15 sep
|
Verisure
|
Madrid
Overview In this role you help safeguard IT and business processes by identifying, assessing, and mitigating cybersecurity risks. You will collaborate with the Cyber & IT Risk Team to implement risk controls, policies, and standards across the organization. You'll document gaps, guide remediation, and support regulatory compliance (ISO27001, NIST, GDPR).
You contribute to building a robust Audit function within Information Security and partner with cross-functional teams to drive secure, scalable practices. This is a chance to shape security governance in a growth-focused, technology-enabled company.
Responsabilidades Build and maintain the Information Security Audit function Manage and mature the IT risk control framework for effective operation and monitoring Document control gaps, provide remediation guidance, and drive mitigation projects Develop security policies, standards, and procedures for standardization of controls Perform risk assessments across IT and business processes and propose mitigations Ensure risk and remediation plans are addressed by owners Support regulatory compliance activities (ISO27001, NIST, GDPR)
Audit and document processes and prepare management reports Requisitos principales Bachelor's degree in a relevant field 4+ years' experience in Information Security, IT risk and compliance Experience in defining and executing an IT risk control framework for internal and third-party environments Experience performing information security and IT assessments and compliance/maturity assessments Ability to manage risks, vulnerabilities, and non-conformities; document and mitigate KPIs/KRIs definition and reporting for stakeholders Experience in IT controls audits and remediation with internal and third parties Strong planning, problem-solving, and complex technical issue analysis Knowledge of regulatory requirements (SOC 2, NIST, GDPR, COBIT, ITIL) Professional relationship-building and cross-functional collaboration English proficiency; willingness to travel Effective communication Team collaboration Relationship building GRC tool (unspecified) MS Office Information Security controls auditing
📌 Information Security Analyst (RIsk) (Madrid)
🏢 Verisure
📍 Madrid