Job Description About Adevinta Information Services At Adevinta Information Services, we build and operate some of Spain's largest digital marketplaces, including InfoJobs, Milanuncios, Coches.net and Motos.net. We're building a modern, AI-first cybersecurity organisation from the ground up following our separation from the general organisation. This is a unique opportunity to shape governance, compliance and cyber risk for a fast-moving technology company. We're looking for a proactive and pragmatic GRC Manager who enjoys working close to the business and turning governance into an enabler rather than a blocker. What you'll do You will own the Governance, Risk & Compliance function across Adevinta Information Services and support our marketplaces in maintaining a strong security posture. Responsibilities Include * Own the Information Security Management System (ISMS) * Lead ISO 27001, ENS and other security certifications and audits * Coordinate cybersecurity assessments from internal stakeholders,
EQT and external auditors * Drive Third-Party Risk Management across suppliers and strategic partners * Define and maintain security policies, standards and governance processes * Lead security awareness and phishing programmes across the company * Track security risks and remediation plans with business owners * Build executive dashboards and security KPIs for senior leadership * Coordinate Business Continuity and security governance activities * Partner with Legal, Privacy, Procurement, Engineering and Product teams to embed security into business processes * Help scale governance through automation and AI where possible What we're looking for * Experience leading GRC or Information Security Governance in a technology company * Strong understanding of ISO 27001, ENS, NIST or similar frameworks * Experience managing external audits * Experience with Vendor Risk Management * Excellent communication skills with technical and non-technical stakeholders * Pragmatic mindset f