TL;DR
Security Governance Specialist (Cybersecurity): Developing and maintaining the governance framework and information security policies, ensuring alignment with business objectives and compliance with regulations. Focus on risk management, continuous improvement, and bridging communication between security and engineering teams.
Location: 100% remote-friendly within Spain or hybrid work model with hub in Barcelona.
Company
hirify.global is the largest digital healthcare platform in the world, present in 15 countries and currently connecting over 30 million patients to more than 2 million healthcare professionals.
What you will do
- Develop and maintain information security policies, procedures, and standards.
- Establish and manage the security governance framework.
- Assist in identifying and understanding regulatory requirements and standards.
- Contribute to the development of security awareness programs and training materials.
- Maintain a repository of security policies, procedures, and standards.
- Integrate risk management principles across the business.
Requirements
- 5+ years of experience in information security governance.
- Knowledge of relevant security standards and frameworks (e.g., ISO 27001, NIST, SOC 2).
- Experience of continuous compliance tooling (eg Vanta or Drata).
- Strong understanding of regulatory requirements, such as GDPR.
- Excellent communication and collaboration skills.
- Ability to adapt to a dynamic and fast-paced environment.
Nice to have
- ISO 27001 Lead Auditor or Implementer certification.
- Experience leading or taking part in internal and or external audits.
Culture & Benefits
- Remote or hybrid work model with hub in Barcelona and flexible working hours.
- Summer intensive schedule during July and August (work 7 hours, finish earlier).
- 23 paid holidays, with exchangeable local bank holidays.
- Private healthcare plan for you and subsidized for your family.
- Access to hundreds of gyms for a symbolic fee in partnership for you and your family.
- Free English and Spanish classes.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →