Senior GRC Partner – Governance, Assurance & Third-Party Risk (Madrid)

Senior GRC Partner – Governance, Assurance & Third-Party Risk (Madrid)

30 jul
|
dLocal
|
Madrid

30 jul

dLocal

Madrid

About Us & The Role dLocal enables the biggest companies in the world to collect payments in 40 countries in emerging markets. Global brands rely on us to increase conversion rates and simplify payment expansion effortlessly. As both a payments processor and a merchant of record where we operate, we make it possible for our merchants to make inroads into the world’s fastest-growing, emerging markets.

We do not do "check-box" compliance, and we don't do corporate fluff. Within the Security Department, under the guidance of GRC and security leadership, our GRC and Assurance team operates with a street‑smart, pragmatic approach.

Senior GRC Partner We are looking for a versatile, self‑driven

Senior GRC Partner to take direct ownership across our Governance, Security Awareness, Third‑Party Risk Management, and Compliance programs across a complex, fast‑moving global business. This is not a single‑track specialist role. You will work across all GRC and Assurance domains, rolling your sleeves up wherever the team needs you most.

What You’ll Do

Own Third‑Party Risk & Payment Processor Assessments: Take direct operational ownership of our global Third‑Party Risk Management program, including the Payment Processor Assessment Framework, which is one of the team's most critical and complex programs.

Design the Machine: Implement a tiered, risk‑based review system: fast‑tracks for low‑risk vendors, and deep technical scrutiny for critical processors in emerging markets. Work with our security engineers to define and build automated workflows and AI agents that handle the administrative lifting of TPRM.

Enable the Business Safely: Analyze technical findings from external assessment vendors and translate them into clear, actionable risk positions.

Operationalize Governance: Renegotiate existing policies to make them practical, risk‑calibrated, and enforceable. Run the stakeholder process across security, engineering, and the business to land on controls that reduce risk without grinding operations to a halt.





Drive Security Awareness & Champions: Build targeted, high‑ROI awareness interventions using modern tools that actually change behavior. Build and run the Security Champions program.

Run Compliance & the Risk Register: Map and maintain controls across PCI DSS, SOX, DORA, ISO 27001, and SOC 2. When audit season hits, pull evidence, coordinate with stakeholders, and ensure nothing falls through the cracks.

Shift Left & Protect Business Velocity: Provide business leaders with transparent data, tools, and rules to explicitly accept or reject vendor risk, and draft acceptance paperwork.

What You Bring

Track record of driving governance, assurance, or TPRM programs in fast‑paced, complex environments.

Pragmatic operator mentality: move fast, optimize workflows, deliver results.

Hands‑on grit: willing to do manual work while building automation.

Disruptive vision for TPRM: enable the business, not block it.

Disciplined multi‑threading to manage multiple initiatives simultaneously.

AI fluency: comfortable using LLMs to automate governance work while ensuring data accuracy.

Regulatory knowledge of PCI DSS, SOX, DORA, ISO 27001, SOC 2.

High EQ and stakeholder navigation: negotiate with VP‑level leaders and vendors.

Exceptional communication: clear language for non‑technical audiences.

Nice to Have

Experience in fintech, payments, or tech scale‑up environment.

Experience assessing or securing payment processors and financial institutions in emerging markets.

Experience building or integrating with modern GRC, risk management, or procurement platforms.

Familiarity with the unique cybersecurity challenges of emerging markets.

How You’ll Work High autonomy, high accountability. You take direction from security leadership, figure out the "how," and execute. This role is for someone who wants to build practical, scalable programs trusted by the business.

Benefits Flexibility: versátil schedules driven by performance. Fintech industry: dynamic environment. Referral bonus program. Social budget for team gatherings. Housing support for coworking.

📌 Senior GRC Partner – Governance, Assurance & Third-Party Risk (Madrid)
🏢 dLocal
📍 Madrid

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: senior grc partner – governance, assurance & third-party risk (madrid) / madrid

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: senior grc partner – governance, assurance & third-party risk (madrid) / madrid