ph3Governance risk and Compliance Technical Specialist - Hybrid Madrid /h3 pGet AI-powered advice on this job and more exclusive features. /p pb? UST is looking for the very Top Talent…and we would be delighted if you were to join our family! /b /p pMore in detail, UST is a multinational company based in North America, certified as a Top Employer and Great Place to Work company with over 35.000 employees all over the world and a presence in more than 35 countries. We are leaders on digital technology services, and we provide large-scale technologic solutions to big companies. /p pb What are we looking for? /b /p pWe are looking for a GRC Specialist contribute for a project with one of our integral customers in the cybersecurity team. /p h3Responsibilities /h3 ul li4 years’ experience in audits and compliance and assessments based on national and international standards (ISO27001, ISO22301, ENS, NIST, DORA, NIS2) /li liKnowledge/certifications in ISO27001 is a must. It is also desirable knowledge in ENS, ISO 27005, ISO22301, ISO 42001, NIST CSF 2.0, NIST, SOC 2, GDPR, DORA, NIS2, CMMC 2.0 /li liProficiency with a variety of instruments for assessing and controlling risk (ex. ISO 31000, Magerit v3, COSO) /li liExperience in implementation of best practices, compliance with information security policies and standards. /li liTechnical experience or applicable knowledge in security architectures for different environments. /li liExperience related to Cybersecurity ecosystem, deployment experience of security technologies. /li liKnowledge of different security solutions/technologies: FW, DLP, IDS/IPS, EDR… /li liExperience in incident response plans and exercises /li liComputer Engineering/Telecommunications and/or Master in Cybersecurity It is also desirable and will be considered to hold certifications such as CISM, CISSP, CISA, ISO/IEC 27001 Lead Auditor / Lead Implementer. /li liHandle the assigned tasks from the allocated domain with minimal guidance from the leads. (Domain Examples: BCMS, ISMS, Risk assessment (AARR BIAs), GAP Analysis, Incident management,
Awareness activities, Data Privacy, etc.) /li liIndependently handle (with very minimal guidance from the supervisors) internal audits or GAP Analysis to ensure compliance with security standards (ex. ISO 27001/ISO 22301/ISO 27701, NIST CSF 2.0, ..) requirement as well as process specific requirements /li liResponsible for the effective documentation of projects individually. /li liPoint out the non-conformance areas and suggest measures to improve the information security individually. /li liEnsure that risk management is effectively conducted across the organization, business processes and information systems. /li liInvolve and contribute to customer assurance activities. /li liCoordinate information security awareness training programs for all the employees, contractors and approved system users. /li liCoordinate and Review the technical assessments of IT systems and processes to identify potential risks. Submit recommendations to mitigate any risks identified and ensure controls that they are implemented. /li liDesign, plan and execute the Cybersecurity activities. /li liDirectly Interact with customer and communicate detailed technical requirement to the team. /li liUse independent judgement and discretion to analyze the system security. /li liPrepare detailed description of user requirements and steps required to perform a compliance project in basis a standard or regulation. /li liLearn and understand existing regulations or standards requirements. /li liIndependently handle the evidence collection from multiple teams as part of any internal audits. /li liPolicy/Procedure creation activities and process improvement ideas to be implemented.
/li liResearch and analytical skills, including the ability to convert complex policy issues into simple briefings and communicate to the audience. /li /ul h3Qualifications /h3 ul li4+ years of experience in audits, compliance, and assessments based on ISO27001, ISO22301, NIS2, DORA, etc. /li liISO27001 certification or equivalent knowledge, plus familiarity with ENS, ISO 27005, ISO 42001, SOC 2, GDPR, CMMC 2.0. /li liStrong understanding of risk assessment frameworks (ISO 31000, Magerit, COSO). /li liExperience with cybersecurity technologies (FW, DLP, IDS/IPS, EDR) and incident response. /li liRelevant degree (Computer Engineering, Telecommunications, or Master in Cybersecurity); optional certifications: CISM, CISSP, CISA, ISO/IEC 27001 Lead Auditor / Lead Implementer. /li /ul h3Benefits /h3 ul li23 days of Annual Leave plus the 24th and 31st of December as discretionary days! /li liNumerous benefits (Health Care Plan, Internet Connectivity, Life and Accident Insurances). /li liFree access to several training platforms. /li liProfessional stability and career plans. /li liReferral program benefits. /li liOption to pick between 12 or 14 payments along the year. /li liReal Work Life Balance measures (flexibility, WFH or remote work policy, compacted hours during summertime…). /li liUST Club Platform discounts and gym Access discounts. /li /ul h3Seniority level /h3 pMid-Senior level /p h3Employment type /h3 pFull-time /p h3Job function /h3 pConsulting /p h3Industries /h3 pIT Services and IT Consulting /p pb If you would like to know more, do not hesitate to apply and we’ll get in touch to fill you in details. UST is waiting for you! /b /p pbIn UST we are committed to equal opportunities in our selection processes and do not discriminate based on race, gender, disability, age, religion, sexual orientation or nationality. We have a special commitment to Disability Inclusion, so we are interested in hiring people with disability certificate. /b /p /p #J-18808-Ljbffr
📌 Governance risk and Compliance Technical Specialist - Hybrid Madrid
🏢 Ust
📍 Madrid