Назад
Company hidden
6 дней назад

Governance, Risk & Compliance Specialist (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
c1
Страна
Spain
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Governance, Risk & Compliance Specialist (Cybersecurity): Developing and monitoring cybersecurity, compliance, and risk management frameworks for a global employee benefits platform with an accent on regulatory alignment, policy governance, and continuous risk mitigation. Focus on analyzing cybersecurity KPIs and KRIs, supporting audits and control testing, and improving GRC practices across countries and business lines.

Location: Madrid, Spain

Company

hirify.global provides employee benefits and engagement solutions across Meal & Food, Wellbeing, Lifestyle, Reward & Recognition, and Public Benefits in a global B2B2C ecosystem.

What you will do

  • Develop, maintain, and improve cybersecurity and compliance policies, procedures, standards, and GRC frameworks.
  • Align governance practices with ISO 27001, NIST, GDPR, LGPD, DORA, and other regulatory and industry frameworks.
  • Track cybersecurity KPIs and KRIs, prepare risk posture updates, and contribute to internal reporting and audits.
  • Collaborate with IT, Privacy, Legal, Compliance, HR, and business units on governance and risk-related matters.
  • Support cybersecurity awareness campaigns, employee training, risk assessments, control testing, and audits.
  • Research regulatory and technological developments and recommend improvements to controls, tools, and methodologies.

Requirements

  • Bachelor’s degree in Risk Management, Business Administration, Cybersecurity, or a related field.
  • 3–5 years of experience in GRC, cybersecurity compliance, or information risk management in a multinational or regulated environment.
  • Knowledge of ISO 27001, NIST, GDPR, LGPD, DORA, and related regulatory frameworks.
  • Experience with GRC platforms such as OneTrust, Sandas GRC, or GlobalSuite.
  • Strong analytical, documentation, and stakeholder communication skills, including interaction with C-level and cybersecurity committee members.
  • Fluent English and Spanish required. Proficiency in Microsoft 365 is also required.

Nice to have

  • CRISC, ISO 27001 Lead Implementer, CISA, or equivalent certification.
  • Certification in Esquema Nacional de Seguridad (ENS).

Culture & Benefits

  • Inclusive and diverse workplace with experts working across multiple countries.
  • Opportunities to experiment with new ideas and develop digital employee experiences.
  • Work connected to sustainability, diversity, local economies, and employee wellbeing.
  • Support for career development, work-life balance, and learning new skills.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →