GRC Engineer (España)

GRC Engineer (España)

04 ago
|
Salmon Group
|
España

04 ago

Salmon Group

España

ph3Overview /h3pYou will own PCI-DSS end to end: certification as a service provider, passing audits, and maintaining status year over year. This includes leading scoping, defining the cardholder data environment, driving remediation, and managing the relationship with the QSA. You translate compliance requirements into concrete technical or process changes with evidence that they work, collaborating with engineering and infrastructure to ensure lasting outcomes. You will also lead the broader GRC program, including risk, audits, and frameworks, reporting to the Group CISO with autonomy to run compliance as your own area. /ph3Responsibilities /h3ullibPCI-DSS certification and maintenance /bulliOwn the PCI-DSS program end to end for a service provider: scoping, gap assessment, remediation, certification, and annual maintenance /liliDefine and minimize the cardholder data environment; drive segmentation and scope reduction with engineering and infrastructure /liliManage the QSA relationship: scoping workshops, evidence packages, assessments, and findings /liliKeep the certification live between audits: quarterly requirements and ongoing evidence and control monitoring /li /ul /lilibTranslating compliance into reality /bulliTurn PCI and other framework requirements into concrete technical and organizational solutions, working directly with engineering and infrastructure teams /liliDistinguish between controls that exist on paper and those that actually work,



and insist on the latter /liliDesign processes and evidence flows that keep controls satisfied without constant manual effort /li /ul /lilibAudit and assurance /bulliLead internal and external audits: scope, evidence, finding responses, and closure /liliBuild and maintain an evidence base that supports continuous readiness across PCI, ISO 27001, and BSP /liliCoordinate the ISO 27001 surveillance cycle /li /ul /lilibGRC leadership /bulliBring structure and ownership to the wider compliance and risk program /liliMaintain the risk register as a working document and drive treatment with system owners /liliRun vendor security assessments and track third-party compliance obligations /liliReport compliance posture clearly to leadership and governance committees /li /ul /li /ulh3Requirements /h3ullibExperience /bulli6+ years in security GRC, compliance, or audit with real ownership of a compliance program /liliHas led a PCI-DSS certification end to end, ideally as a service provider, and maintained status across cycles /liliHas managed a QSA relationship and run a real audit, not just supported one /liliHas led cardholder data environment scoping and segmentation decisions with technical teams /liliComfortable across at least PCI-DSS and one of ISO 27001 or a banking framework (BSP MORB or equivalent)



/liliExperience in a regulated environment where compliance was enforced, not aspirational /li /ul /li /ulh3What Sets The Right Person Apart /h3ullibAbility to translate a compliance requirement into a specific technical or process change and explain it to engineers /b /liliUnderstands technology well enough to know whether a proposed control satisfies the requirement /liliTreats certification as an ongoing state to maintain, not a one-time project /liliBuilds evidence and monitoring into how controls run, rather than collecting it under deadline pressure /li /ulh3Technical understanding /h3ulliSolid grasp of network segmentation, access control, encryption, logging, and other PCI-relevant technical domains /liliFamiliarity with cloud (AWS), identity, and infrastructure to discuss control implementations with engineering /liliComfortable working in Jira and Confluence, and open to building automation around evidence and reviews /li /ulh3Nice to have /h3ulliExperience with a GRC platform (Vanta, Thoropass, ServiceNow GRC, or similar) /liliFamiliarity with BSP examination processes or Philippine financial services regulation /liliCertifications: PCI-DSS ISA, CISA, CRISC, CISSP, ISO 27001 Lead Auditor or Implementer /li /ulh3Communication /h3ulliStrong written and verbal English; most work is async and documentation quality matters /liliCan lead a working session with engineering and a reporting conversation with leadership /li /ul /p #J-18808-Ljbffr

📌 GRC Engineer (España)
🏢 Salmon Group
📍 España

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: grc engineer (españa) / españa

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: grc engineer (españa) / españa