GRC Consultant

Accenture
Accenture
Madrid, SpainOn-siteCompetitiveAdded 19 days agoMidPermanentRemote: On Site🇪🇸Spanish: Native
🇪🇸 Translated from SpanishMadrid, torre chamartin

This job was originally posted in Spanish and automatically translated to English. You'll most likely need Spanish to apply.

Job Description

Functions and Responsibilities

Risk Management

  • Preparation and maintenance of risk analyses and control frameworks in accordance with ISO/IEC 27001, NIST CSF, ENS, and DORA.
  • Monitoring of treatment plans: status, progress, and effectiveness of defined measures.
  • Tracking of non-conformities and corrective actions until closure, ensuring traceability and evidence.
  • Support in the operation and evolution of GRC tools (Archer, OneTrust, Formalize, or similar).

Third-Party and Supply Chain Management

  • Support in the evaluation and onboarding process of providers from a security and risk perspective.
  • Monitoring the third-party risk lifecycle: periodic evaluations, questionnaires, findings management, and continuous monitoring.
  • Collaboration in the preparation and updating of the critical provider inventory.
  • Support in the automation of evaluation processes through tools.

Dashboards and Reporting

  • Preparation and maintenance of risk and compliance dashboards for Senior Management and the CISO.
  • Consolidation of metrics and key indicators (KRI/KPI) that reflect the security posture in an understandable and actionable way.
  • Support in the preparation of periodic reports for risk committees, internal audit, and regulators.
  • Translation of technical information into executive language, facilitating decision-making.

Knowledge and Experience

  • Experience in information security risk management and regulatory compliance frameworks.
  • Knowledge of standards and regulations: ISO/IEC 27001, NIST CSF, ENS, DORA, NIS2, and GDPR.
  • Ability to interpret regulatory requirements and translate them into practical and verifiable controls.
  • Knowledge of business continuity and crisis management (ISO 22301 or similar, valued).
  • Experience or knowledge in third-party and supply chain risk management.
  • Solid knowledge of cybersecurity technologies and information systems.
  • Proficiency in GRC tools (Archer, OneTrust, Formalize, or similar). Valued: PILAR tool and MAGERIT methodology.
  • Ability to identify and apply efficiencies through process automation and the use of AI tools, contributing to the continuous improvement of GRC operations.
  • B2 English. Reading of international regulations and fluent communication with global teams.

About Accenture

Accenture is a leading global professional services company that helps the world's leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services-creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world's leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities.

Visit us atwww.accenture.com

Equal Employment Opportunity Statement

We believe that no one should be discriminated against for their differences. All employment decisions will be made regardless of age, race, creed, color, religion, sex, national origin, ancestry, disability, military veteran status, sexual orientation, gender identity or expression, genetic information, marital status, citizenship, or any other criteria protected by applicable law. Our rich diversity makes us more innovative, competitive, and creative, which helps us better serve our clients and communities.

View original advert (Spanish)

Funciones y Responsabilidades

Gestión de Riesgos

  • Elaboración y mantenimiento de análisis de riesgos y marcos de control conforme a ISO/IEC 27001, NIST CSF, ENS y DORA.
  • Seguimiento de planes de tratamiento: estado, avance y efectividad de las medidas definidas.
  • Seguimiento de no conformidades y acciones correctivas hasta su cierre, asegurando trazabilidad y evidencia.
  • Apoyo en la operación y evolución de herramientas GRC (Archer, OneTrust, Formalize o similares).

Gestión de Terceros y Cadena de Suministro

  • Soporte en el proceso de evaluación y onboarding de proveedores desde el punto de vista de seguridad y riesgo.
  • Seguimiento del ciclo de vida del riesgo de terceros: evaluaciones periódicas, cuestionarios, gestión de hallazgos y monitorización continua.
  • Colaboración en la elaboración y actualización del inventario de proveedores críticos.
  • Apoyo en la automatización de procesos de evaluación mediante herramientas.

Cuadros de Mando y Reporting

  • Elaboración y mantenimiento de cuadros de mando de riesgo y cumplimiento para la Alta Dirección y el CISO.
  • Consolidación de métricas e indicadores clave (KRI/KPI) que reflejen la postura de seguridad de forma comprensible y accionable.
  • Apoyo en la preparación de informes periódicos para comités de riesgo, auditoría interna y reguladores.
  • Traducción de información técnica en lenguaje ejecutivo, facilitando la toma de decisiones.

Conocimientos y experiencia

  • Experiencia en gestión de riesgos de seguridad de la información y marcos de cumplimiento normativo.
  • Conocimiento de estándares y regulaciones: ISO/IEC 27001, NIST CSF, ENS, DORA, NIS2 y GDPR.
  • Capacidad para interpretar requisitos normativos y trasladarlos a controles prácticos y verificables.
  • Conocimientos en continuidad de negocio y gestión de crisis (ISO 22301 o similar, valorable).
  • Experiencia o conocimiento en gestión de riesgos de terceros y cadena de suministro.
  • Conocimientos sólidos en tecnologías de ciberseguridad y sistemas de información.
  • Manejo de herramientas GRC (Archer, OneTrust, Formalize o similares). Valorable: herramienta PILAR y metodología MAGERIT.
  • Capacidad para identificar y aplicar eficiencias mediante automatización de procesos y manejo de herramientas de IA, contribuyendo a la mejora continua de las operaciones GRC.
  • Inglés B2. Lectura de normativas internacionales y comunicación fluida con equipos globales.

About Accenture

Accenture is a leading global professional services company that helps the world's leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services-creating tangible value at speed and scale. We are a talent- and innovation-led company with approximately 791,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world's leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology and leadership in cloud, data and AI with unmatched industry experience, functional expertise and global delivery capability. Our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Song, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients reinvent and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities.

Visit us atwww.accenture.com

Declaración de igualdad de oportunidades en el empleo

Creemos que nadie debe ser discriminado por sus diferencias. Todas las decisiones de empleo se tomarán sin importar la edad, raza, credo, color, religión, sexo, origen nacional, ascendencia, discapacidad, condición de veterano militar, orientación sexual, identidad o expresión de género, información genética, estado civil, ciudadanía ni ningún otro criterio protegido por la legislación aplicable. Nuestra rica diversidad nos hace más innovadores, competitivos y creativos, lo que nos ayuda a servir mejor a nuestros clientes y comunidades.

Need a visa? No sponsorship mentioned here. Browse visa jobs