The English-language job board for Spain

GRC Consultant

Hybrid in Bilbao·Full-time·Added 9 days ago

Advens

1 open role

Overview

Job details

  • Full-time hours

    Per the ad.

  • Hybrid

    Office and home days — the ad has the split.

Requirements

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Be near Bilbao, Spain (Hybrid) for hybrid days

    No relocation package mentioned.

  • Have 3+ years of experience

    Mid-level role.

  • University degree

    “Titulación universitaria en Ingeniería Informática, Telecomunicaciones o similar.” — per the ad.

This job was automatically translated to English.

Pay & benefits

What you'll get

  • Working in an international company with more than 600 employees and 25 years of experience in the cybersecurity sector.
  • Opportunity to learn and develop in a booming sector such as cybersecurity.
  • A hybrid and flexible working model, where you decide when to come to the office and when to work from home.
  • Be part of a company with a young atmosphere and values of camaraderie, teamwork, and commitment to society and the environment.
  • Training and professional development plans.
  • Company-funded medical insurance.
  • Flexible compensation plan that includes meal vouchers, public transport, childcare, training, among other benefits.
  • Mobile phone bill reimbursement.

Requirements

What we're looking for

  • Approximately 3-5 years of experience in GRC consulting, technological risk, audit, or regulatory compliance.
  • Participation in projects for financial entities, insurance companies, or payment service companies.
  • Experience in preparing reports, procedures, and compliance documentation.

Nice to have

Experience or knowledge in any of the following regulations and frameworks:

  • ISO 27001
  • ISO 22301
  • NIST
  • DORA (Digital Operational Resilience Act)
  • NIS2
  • General Data Protection Regulation (GDPR)
  • EBA Guidelines on ICT and Security Risk Management
  • EBA Guidelines on Outsourcing Arrangements
  • ECB Cyber Resilience Oversight Expectations (CROE)
  • PSD2 / PSD3
  • MiFID II
  • Solvency II
  • European Banking Authority (EBA) Guidelines
  • CRA
  • IA Act
  • ...
  • SWIFT Customer Security Programme (CSP)
  • PCI DSS
  • Payment scheme (Visa, Mastercard)
  • Financial market infrastructures
  • Electronic and digital banking services
  • Payment platforms and fintech
  • ISO 27001 Lead Auditor
  • ISO 27001 Lead Implementer
  • CRISC
  • CISM
  • CISSP
  • ISO 22301 Lead Auditor

Education & certifications

  • University degree in Computer Engineering, Telecommunications, or a related field.

Languages

  • English valued

The role

We are looking for a GRC Consultant located in the Bilbao area with around 3-5 years of experience to join our specialized team in governance, risk, regulatory compliance, and resilience.

You will participate in regulatory transformation, risk management, and cybersecurity projects for different sectors, including organizations subject to high regulatory requirements.

You will work with some of the main European and international regulations and standards, helping our clients strengthen their operational resilience and risk management capabilities.

What you'll do

  • Participate in regulatory compliance and regulatory adequacy projects.
  • Perform technological, cybersecurity, and third-party risk analyses.
  • Execute GAP analyses against regulatory frameworks and international standards.
  • Develop policies, procedures, methodologies, and control frameworks.
  • Design and implement ICT risk management processes.
  • Collaborate on operational resilience and business continuity programs.
  • Participate in critical vendor assessments and supply chain risks.
  • Prepare documentation for audits, regulators, and risk committees.
  • Develop dashboards and executive reports for Risk, Compliance, Security, and Internal Audit areas.
  • Collaborate in crisis simulation exercises and operational resilience tests.

About Advens

Advens is a European, independent cybersecurity services company with around 600 experts across France and Europe. It helps organisations prevent and neutralise cyberattacks through services spanning risk and strategy, cyber compliance (including ISO 27001), offensive security auditing, SOC-as-a-Service and MDR via its mySOC platform, CERT incident response, and security technology integration, serving sectors such as healthcare, public services and industry 4.0. The company holds B Corp™ certification and channels part of its financial performance into its 'Advens for People and Planet' endowment fund.

Industry
Cybersecurity
Employees
600
Website
advens.com

Good to know if you are moving

  • Current open roles in Spain include GRC consulting (Bilbao), Cybersecurity Engineer, DFIR specialist and FullStack DevOps Engineer (AWS/CDK/Python).
  • The company is labelled Great Place To Work® and highlights autonomy, trust and initiative-taking, with the option to work remotely or from the office.
  • Advens is B Corp™ certified and describes itself as an independent European cybersecurity company with 600 experts across France and Europe.
  • Its job families span Governance, Risk & Compliance, offensive security, CERT, security technology, project management, cyber defence, DevOps and data science.

In their own words

About the company & team

📢 Joining Advens means joining a European leader in Cybersecurity, but, above all, it means being part of a team of passionate specialists who protect increasingly exposed organizations, helping them fulfill their missions, which are often essential.

It also means being part of a collective that puts its performance at the service of high-impact projects.

🌎 We have 600 experts distributed across France, Spain, Germany, as well as Montreal and Tahiti.

Our mission of protection guides and drives us every day, but it is not enough. If cybersecurity can make the world work, our performance must also contribute to changing it.

Together and always forward: from our very first steps, we have relied on three fundamental values. More than a brand, they are our driving force to act today and improve tomorrow: #Audacity #Collective #Impact.

🚀 Training, growth opportunities, mobility... we support every project according to the desires and ambitions of each person.

We believe in a work-life balance as a way for individual development, so we commit to autonomy: freedom in the workplace, but also in the way we organize ourselves day to day.

And to maintain our valuable team spirit, our weeks are full of moments of togetherness and sharing... always with a touch of humor.

As you can see, we look for more than cybersecurity experts: we look for committed and passionate people.

All open roles at Advens
WhatsApp