5 дней назад
Security GRC Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security GRC Engineer (Cybersecurity/GRC): Strengthening security governance through compliance frameworks, risk assessments, audits, remediation plans, and security awareness programs with an accent on ISO 27001, PCI DSS, NIS2, cloud compliance, and GRC platforms. Focus on translating regulatory requirements into actionable controls, quantifying security risks, coordinating audits, and connecting technical, legal, and business stakeholders.
Location: Barcelona, Spain
Company
Glovo is part of , a global local delivery platform operating in around 65 countries and headquartered in Berlin, Germany.
What you will do
- Develop and maintain security policies and procedures aligned with ISO 27001, NIST, PCI DSS, GDPR, NIS2, and the EU AI Act.
- Design and deliver security awareness programs that promote secure working practices and compliance.
- Assess security risks, maintain the risk register, define mitigation strategies, and monitor remediation plans.
- Coordinate customer security inquiries, due diligence questionnaires, and security-related contract reviews.
- Support continuous security control monitoring, certification and recertification activities, and internal and external audits.
- Act as a liaison between technical teams, legal, internal audit, and business stakeholders.
Requirements
- BA/BS in Computer Science, Information Systems, or a related field.
- At least 5 years of experience in security, GRC, or a related area.
- Professional security certification such as CISSP, CISM, CISA, or ISO 27001 Lead Implementer.
- Experience with security control frameworks including NIST, PCI DSS, GDPR, ISO 27001, and NIS2.
- Hands-on experience with GRC platforms such as RSA Archer, SAP GRC, StandardFusion, ServiceNow, or OneTrust.
- Experience with cloud compliance across AWS, Azure, or GCP, risk quantification methods such as FAIR, and security awareness programs.
Nice to have
- Python development skills for automating integrations or processes.
- Experience with Business Continuity Plans and Disaster Recovery plans.
- Knowledge of the EU AI Act, NIST AI RMF, MITRE ATLAS, and AI security threats.
Culture & Benefits
- Work within a diverse and inclusive environment focused on equal opportunities.
- Leadership Principles guide decision-making, collaboration, and professional conduct.
- Additional compensation may include benefits, equity, and variable bonuses for predefined roles.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
Governance, Risk & Compliance Specialist (Cybersecurity)
8 дней назад
Vice President & Chief Information Security Officer (Cybersecurity)
228 700 - 285 900$
11 дней назад
Head of Security & Risk (Fintech)
5 дней назад
Senior Security Engineer (Cloud Security)
110 000 - 130 000€
9 дней назад
Security GRC Specialist (Fintech)
9 дней назад