Назад
Company hidden
4 часа назад

HQ - GRC Senior Analyst (Cybersecurity)

Формат работы
remote (только Spain)
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
Spain
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
HQ - GRC Senior Analyst (ISO 27001/GDPR): Owning and scaling governance, risk, and compliance across a fast-growing product company with an accent on ISMS implementation, GDPR data mapping, and audit readiness. Focus on identifying compliance gaps, driving remediation with technical and non-technical teams, and embedding security controls into systems and SDLC processes.

Location: Remote, Madrid HQ, Spain

Company

hirify.global is a fast-growing product technology company with global client reach across the US and EU.

What you will do

  • Own and scale the Governance, Risk, and Compliance function across ISO 27001 and GDPR.
  • Build and manage the Information Security Management System aligned with ISO 27001.
  • Ensure GDPR compliance across data processing activities, including data mapping, data leak reviews, and encryption controls.
  • Act as the primary contact for internal and external auditors and prepare for ISO audits.
  • Identify compliance gaps, develop remediation plans, and drive implementation with technical and non-technical teams.
  • Develop governance policies, procedures, and risk management frameworks while embedding controls into systems and SDLC processes.

Requirements

  • 8+ years of experience in GRC, risk, compliance, or IT audit roles.
  • 5+ years of hands-on experience with ISO 27001, including managing or supporting ISMS implementation.
  • 3+ years of practical GDPR data mapping experience and technical systems review.
  • 5+ years of experience in a product technology company with more than 100 employees and global US/EU client reach.
  • Experience working with internal and external auditors.
  • Very strong stakeholder management and communication skills across technical and non-technical teams.
  • Fluent English required.

Nice to have

  • Familiarity with AWS, GCP, or Azure environments.
  • Security certifications such as CISA, CISM, or ISO 27001 Lead Implementer/Auditor.
  • Additional security experience.

Culture & Benefits

  • Permanent employment.
  • Remote workplace arrangement.
  • Collaboration with Engineering and Security teams.
  • Work in a product technology environment with global US and EU reach.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →