GRC Consultant
Altia·A Coruña, Spain
What they offer
Full-time hours
Per the ad.
Hybrid
Office and home days — the ad has the split.
What they ask for
Have the right to work in Spain
No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.
Speak native-level Spanish
Listed as a requirement in the ad.
Be near A Coruña for hybrid days
No relocation package mentioned.
Have 3+ years of experience
Per the ad.
Pulled from the advert automatically — the full ad is what counts.
About the role
At Altia, we are looking for a Cybersecurity Consultant with a hybrid profile that combines a strategic vision of Governance, Risk, and Compliance (GRC) with operational technical capabilities in SOC / Incident Response environments.
This person will be key to helping our clients design security plans, ensure regulatory compliance (including emerging regulations such as the EU AI Act and NIS2), deploy advanced monitoring tools, and automate analytical and executive reporting processes.
What you'll do
Main Responsibilities:
📋 Governance, Risk, and Compliance (GRC)
- Security Master Plans: Design and implementation of Security Master Plans aligned with regulations and reference frameworks (ISO 27001, NIS2, ENS).
- Artificial Intelligence Governance: Risk analysis and benchmarking of AI tools and providers (evaluating data residency, retention, certifications, SSO/SCIM, DLP, and log auditing).
- EU AI Act Compliance Assessment: Gap analysis and alignment with the EU AI Regulation (Regulation (EU) 2024/1689), covering deployer obligations and accessibility.
- IAM and Access Audits: Risk audits of IAM architectures (SSO, MFA, encryption in transit / at rest), privilege reviews under the principle of least privilege, and Segregation of Duties (SoD).
🔍 Security Operations (SOC) & Incident Response
- Tier 3 Operations and Analysis: Advanced management and response to complex security incidents, including digital forensics analysis.
- SIEM Deployment and Integration: Configuration, data ingestion, use case modeling, and alert generation in Splunk, tailored to the business.
- Automation and Development: Creating Python scripts to automate incident response workflows.
- Security Technology Deployment: Configuration and operation of EDR, NDR, Firewalls, and Advanced Email Protection solutions.
📊 Reporting & Business Intelligence
- Executive Dashboards: Development of cybersecurity KPI dashboards using BI tools.
- Report Automation: Integration of service data, resolution KPIs, and multi-technology metrics for the monthly SOC report.
What we're looking for
🎯 Minimum Requirements (Must-Have)
- Degree in Computer Science
- ISO 27001 Certification
- Previous experience: Minimum of 3 years in cybersecurity consulting roles, covering GRC projects and technical support in SOC/Incident Response environments.
- Regulatory Knowledge: Mastery and demonstrable experience in ISO 27001, NIS2, ENS, and risk management frameworks.
- EU AI Act Knowledge: Understanding of the regulatory obligations of the European Artificial Intelligence Regulation.
- SIEM / Splunk: Hands-on experience with deployment, data ingestion, use case modeling, and alerting in Splunk.
- Programming / Scripting: Fluent-level Python skills focused on task automation and incident response.
- Incident Response: Experience in Tier 3 incident escalation/resolution and knowledge of digital forensics.
- Identity and Access Management (IAM): Experience in security audits of SSO, MFA, access matrices, and data encryption.
Nice to have
🌟 Desirable Requirements
- Valuable certifications: CISM, CRISC, ISO 27001 Lead Auditor/Implementer, Splunk Core Certified Power User/Admin, or other related technology/security certifications.
- Previous experience with Business Intelligence tools (Power BI, Tableau, etc.) for developing dashboards.
- Practical knowledge of managing EDR / NDR / Next-Generation Firewall tools.
About the role
En Altia buscamos un/a Consultor/a de Ciberseguridad con un perfil híbrido que combine una visión estratégica de Gobierno, Riesgo y Cumplimiento (GRC) con capacidades técnicas operativas en entornos de SOC / Respuesta ante Incidentes.
La persona será clave para ayudar a nuestros clientes a diseñar planes de seguridad, garantizar el cumplimiento normativo (incluyendo regulaciones emergentes como la EU AI Act y NIS2), desplegar herramientas de monitorización avanzadas y automatizar procesos analíticos y de reporte ejecutivo.
What you'll do
Responsabilidades Principales:
📋 Gobierno, Riesgo y Cumplimiento (GRC)
- Planes Directores de Seguridad: Diseño e implantación de Planes Directores alineados con normativas y marcos de referencia (ISO 27001, NIS2, ENS).
- Gobernanza de Inteligencia Artificial: Análisis de riesgos y benchmarking de herramientas y proveedores de IA (evaluando residencia de datos, retención, certificaciones, SSO/SCIM, DLP y auditoría de logs).
- Evaluación de Cumplimiento EU AI Act: Análisis de brechas (gap analysis) y adecuación al Reglamento de IA de la UE (Reglamento (UE) 2024/1689), cubriendo obligaciones de desplegadores y accesibilidad.
- Auditorías IAM y Accesos: Auditorías de riesgos en arquitecturas IAM (SSO, MFA, cifrado en tránsito / en reposo), revisiones de privilegios bajo principio de mínimo privilegio y separación de funciones (Segregation of Duties).
🔍 Operaciones de Seguridad (SOC) & Respuesta ante Incidentes
- Operación y Análisis N3 (Tier 3): Gestión y respuesta avanzada ante incidentes de seguridad complejos y análisis forense digital.
- Despliegue e Integración de SIEM: Configuración, ingesta de datos, modelado y generación de alertas en Splunk adaptadas al negocio.
- Automatización y Desarrollo: Creación de scripts en Python para la automatización de flujos de respuesta ante incidentes (Incident Response).
- Despliegue de Tecnologías de Seguridad: Configuración y operación de soluciones EDR, NDR, Firewalls y Protección Avanzada de Email.
📊 Reporting & Business Intelligence
- Cuadros de Mando Ejecutivos: Desarrollo de dashboards de KPIs de ciberseguridad con herramientas de BI.
- Automatización de Informes: Integración de datos de servicio, KPIs de resolución y métricas multitecnología para el reporte mensual del SOC.
What we're looking for
🎯 Requisitos Mínimos (Must-Have)
- Grado en Informática
- Certificación ISO 27001
- Experiencia previa: Mínimo de 3 años en funciones de consultoría de ciberseguridad, abarcando proyectos de GRC y soporte técnico en entornos SOC/Incident Response.
- Conocimiento Normativo: Dominio y experiencia demostrable en ISO 27001, NIS2, ENS y marcos de gestión de riesgos.
- Conocimientos en EU AI Act: Comprensión de las obligaciones regulatorias de la normativa europea de Inteligencia Artificial.
- SIEM / Splunk: Experiencia práctica en el despliegue, ingesta, modelado de datos y alertas con Splunk.
- Programación / Scripting: Nivel fluido de Python orientado a la automatización de tareas y respuesta ante incidentes.
- Respuesta a Incidentes: Experiencia en escalado/resolución de incidentes N3 (Tier 3) y nociones de análisis forense digital.
- Identidad y Accesos (IAM): Experiencia en auditorías de seguridad sobre SSO, MFA, matrices de accesos y cifrado de datos.
Nice to have
🌟 Requisitos Deseables
- Certificaciones valorables: CISM, CRISC, ISO 27001 Lead Auditor/Implementer, Splunk Core Certified Power User/Admin, o certificaciones afines en tecnología/seguridad.
- Experiencia previa con herramientas de Business Intelligence (Power BI, Tableau, etc.) para la elaboración de cuadros de mando.
- Conocimiento práctico en gestión de herramientas EDR / NDR / Firewalls de última generación.
You'll most likely need Spanish to apply.This job was automatically translated to English, .