Назад
Company hidden
4 дня назад

Senior Information Security GRC Analyst (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Spain
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Information Security GRC Analyst (Cybersecurity): Managing customer security questionnaires, assurance artifacts, contract reviews, and security discussions for an AI-ready governance platform with an accent on evidence-based responses, risk assessment, and cross-functional collaboration. Focus on handling high-volume assurance requests, translating security controls for technical and non-technical audiences, negotiating security obligations, and improving response processes.

Location: Madrid, Spain; office-first culture with three days per week in the office for most roles

Company

hirify.global provides an AI-ready governance platform that unifies regulatory intelligence, automation, and connected governance workflows for responsible data use.

What you will do

  • Complete high volumes of customer security questionnaires, RFP security sections, SIG, CAIQ, and other assurance artifacts.
  • Prepare accurate, consistent, and defensible responses using SOC reports, ISO certificates, policies, standards, diagrams, and penetration test summaries.
  • Collaborate with Sales, Marketing, Customer Success, Security, Engineering, Privacy, Legal, Compliance, and Product teams to validate responses and resolve gaps.
  • Meet customers and prospects to explain security controls, risk posture, and compliance commitments to technical and non-technical audiences.
  • Review contracts, DPAs, security addenda, and customer security terms; identify risks, propose mitigations, and track contractual commitments.
  • Improve efficiency through standardization, playbooks, reusable response libraries, current evidence, and process improvements.

Requirements

  • 2–5 years of experience in information security, security compliance, GRC, security assurance, third-party risk, or customer trust.
  • Experience responding to customer security questionnaires and security due diligence requests.
  • Familiarity with SOC 2, ISO 27001, NIST, CIS, PCI DSS, HIPAA, and GDPR.
  • Strong understanding of access control, encryption, vulnerability management, secure SDLC, incident response, logging and monitoring, and vendor risk.
  • Experience collaborating across Security, Legal, Privacy, Engineering, and Sales, with strong written and verbal communication skills.
  • Ability to prioritize and execute a high volume of concurrent requests while meeting SLAs and maintaining accuracy.

Nice to have

  • CISA, CISM, or an equivalent industry certification.
  • Experience reviewing or negotiating security contract terms, security addenda, and customer assurance language.
  • Background in SaaS or cloud security assurance and enterprise customer support.

Culture & Benefits

  • Office-first working environment with meaningful opportunities for in-person collaboration.
  • Healthcare coverage, flexible paid time off, equity RSUs, and annual performance bonus opportunities.
  • Retirement account support and 14+ weeks of paid parental leave.
  • Career development opportunities and company-paid privacy certification exam fees.
  • Physical, mental, and emotional wellbeing support, with benefits varying by country.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →