04 ago
|
Montarelo Recruiting
|
Madrid
04 ago
Montarelo Recruiting
Madrid
h3Cybersecurity Governance Risk Compliance Lead (Madrid - Hybrid) /h3 pbThe company /b: Our customer is a technology-based startup with solid funding that is in the midst of expansion. /p pThey will hire the selected candidate as an internal and permanent employee, based in Madrid, but providing services to their integral organization. /p pbDescription of the position /b: /p pWe’re looking for a bGovernance Risk Compliance Lead /b for its global operations in Madrid. He/She will be responsible for designing and operationalizing the company’s governance, risk, and compliance framework. Reporting to the Head of Information Security, he/she will play a critical role in enabling company growth by ensuring regulatory readiness, managing risk, and embedding security and compliance into business and product operations. /p pbKey Responsibilities and tasks /b: /p ul liLead the implementation of GDPR, ISO 27001, SOC 2, and NIS 2 compliance programmes, with a roadmap aligned to business priorities and client expectations. /li liDevelop and maintain policies, procedures, and controls that support certification and audit readiness. /li liCoordinate with external auditors, consultants, and vendors to streamline evidence collection and reporting. /li liOperationalize the NIST Cybersecurity Framework across the corporate, product and operational domains /li liConduct regular risk assessments and maintain a centralized risk register. /li liCollaborate with IT, Product and Legal teams to ensure risk mitigation strategies are prioritized correctly. /li libGovernance Policy Enforcement /b:
ul liEstablish governance structures for security and compliance decision-making. /li liRun regular risk committees and track related actions. /li liMaintain and enforce policies such as password management, access control, and vendor risk. /li /ul /li libReporting Communication /b: ul liProvide regular updates to executive leadership on compliance progress, risk posture, and audit outcomes. /li liDevelop dashboards and visualizations to communicate timelines and milestones to stakeholders. /li liAct as the primary liaison for compliance-related queries from clients, partners, and regulators. /li /ul /li /ul pbWorking Experience: /b /p ul li5+ years of proven experience in cybersecurity landscape within cloud-first or SaaS organisations. /li liAt least 2+ years in GRC roles. /li liWorking experience of GDPR, ISO 27001, SOC 2, NIS 2, and NIST CSF. /li liFamiliarity with compliance automation platforms (e.g., Vanta, OneTrust). /li /ul pbNot mandatory but preferred /b: /p ul liLead on ISO 27001, SOC2 or GDPR compliance implementation. /li liIn-depth knowledge of the NIS2 directive. /li liWorking knowledge of Azure cloud environments. /li liWorking knowledge of OT security. /li liExcellent communication and stakeholder management skills.
/li liInternational work experience working with international teams. /li /ul pbEducation and Training: /b /p ul liBachelor's Degree or vocational training qualification: In information technology, or a related field. /li /ul pbCertifications /b: Not mandatory but preferred /p ul liCertified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), or ISO 27001 Lead Implementer. /li /ul pbLanguages: /b /p ul liSpanish: Very good Business Spanish required (excellent communication skills). B2/C1 level. /li liEnglish: Very good Business English required (excellent communication skills). B2/C1 level. /li /ul pbJob Conditions: /b /p pbJob location: /b Tres Cantos (Madrid). EU nationality or valid EU/Spain work permit required. /p pbEmployment Type: /b Permanent Full Time, as internal employee. /p pbSalary: /b Depending on qualification and experience. /p pbWork from home: /b Hybrid working model including the possibility of working from home (70%) but according to the specific needs that may arise from the perspective of project development, department, clients, and/or partners. /p pbHow to apply: /b If you are interested, please apply here or email with the subject Governance Risk Compliance Lead and your English CV. /p h3Seniority level /h3 ul liMid-Senior level /li /ul h3Employment type /h3 ul liFull-time /li /ul h3Job function /h3 ul liInformation Technology /li /ul h3Industries /h3 ul liIT Services and IT Consulting and Space Research and Technology /li /ul #J-18808-Ljbffr
📌 Cybersecurity Governance Risk & Compliance Lead (Madrid - Hybrid)
🏢 Montarelo Recruiting
📍 Madrid