4 дня назад
Senior Information Security GRC Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Information Security GRC Analyst (Cybersecurity): Managing customer security questionnaires, assurance artifacts, contract reviews, and security discussions for an AI-ready governance platform with an accent on evidence-based responses, risk assessment, and cross-functional collaboration. Focus on handling high-volume assurance requests, translating security controls for technical and non-technical audiences, negotiating security obligations, and improving response processes.
Location: Madrid, Spain; office-first culture with three days per week in the office for most roles
Company
provides an AI-ready governance platform that unifies regulatory intelligence, automation, and connected governance workflows for responsible data use.
What you will do
- Complete high volumes of customer security questionnaires, RFP security sections, SIG, CAIQ, and other assurance artifacts.
- Prepare accurate, consistent, and defensible responses using SOC reports, ISO certificates, policies, standards, diagrams, and penetration test summaries.
- Collaborate with Sales, Marketing, Customer Success, Security, Engineering, Privacy, Legal, Compliance, and Product teams to validate responses and resolve gaps.
- Meet customers and prospects to explain security controls, risk posture, and compliance commitments to technical and non-technical audiences.
- Review contracts, DPAs, security addenda, and customer security terms; identify risks, propose mitigations, and track contractual commitments.
- Improve efficiency through standardization, playbooks, reusable response libraries, current evidence, and process improvements.
Requirements
- 2–5 years of experience in information security, security compliance, GRC, security assurance, third-party risk, or customer trust.
- Experience responding to customer security questionnaires and security due diligence requests.
- Familiarity with SOC 2, ISO 27001, NIST, CIS, PCI DSS, HIPAA, and GDPR.
- Strong understanding of access control, encryption, vulnerability management, secure SDLC, incident response, logging and monitoring, and vendor risk.
- Experience collaborating across Security, Legal, Privacy, Engineering, and Sales, with strong written and verbal communication skills.
- Ability to prioritize and execute a high volume of concurrent requests while meeting SLAs and maintaining accuracy.
Nice to have
- CISA, CISM, or an equivalent industry certification.
- Experience reviewing or negotiating security contract terms, security addenda, and customer assurance language.
- Background in SaaS or cloud security assurance and enterprise customer support.
Culture & Benefits
- Office-first working environment with meaningful opportunities for in-person collaboration.
- Healthcare coverage, flexible paid time off, equity RSUs, and annual performance bonus opportunities.
- Retirement account support and 14+ weeks of paid parental leave.
- Career development opportunities and company-paid privacy certification exam fees.
- Physical, mental, and emotional wellbeing support, with benefits varying by country.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
Security GRC Engineer
6 дней назад
Governance, Risk & Compliance Specialist (Cybersecurity)
9 дней назад
Third-Party Cyber Assurance Supervisor (Cybersecurity)
5 дней назад
Senior Security Engineer (Cloud Security)
110 000 - 130 000€
6 дней назад
Global Chief Information Security Officer (CISO) (Fintech)
10 дней назад