What they offer
Full-time hours
Per the ad.
Hybrid
Office and home days — the ad has the split.
What they ask for
Have the right to work in Spain
No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.
Work in English
English is required, per the ad.
Be near Barcelona, Spain (Hybrid) for hybrid days
No relocation package mentioned.
Have 5+ years of experience
Mid-level role.
The role
Glovo is seeking a proactive Security GRC Engineer to help strengthen our global security posture and navigate a rapidly evolving regulatory environment. In this multifaceted role, you will support compliance frameworks (PCI DSS, ISO 27001, NIS2), internal and external audits, drive risk assessment and remediation, and pioneer security awareness programs within our organization. Acting as a strategic bridge between technical engineering, legal, and business stakeholders, you will translate complex legal and regulatory demands into robust, actionable security controls. The ideal candidate brings deep cybersecurity risk expertise, hands-on experience with GRC tools, and the collaborative mindset needed to foster a security-first culture across Glovo.
What you'll do
Develop, implement, and maintain security policies and procedures in line with relevant compliance frameworks (e.g., ISO 27001, NIST, PCI DSS, GDPR, NIS2, EU AI Act).
Develop, execute and deliver security awareness programs to educate employees on best practices and compliance requirements.
Conduct security assessment risks, recommending and implementing mitigation strategies, maintaining a risk register and monitoring the status of remediation plans.
Coordinate and respond to customer security inquiries and due diligence questionnaires (e.g., SIG, CAIQ). Review and provide input on contract modifications related to security, data protection, and privacy.
Propose, develop and implement processes and tools for continuous monitoring of security monitoring to ensure ongoing adherence to policies.
Assist with the end-to-end security certification and re-certification process (such as PCI DSS, ISO 27001, NIS2, among others).
Assist with internal assessments to identify gaps, weaknesses, or non-compliance issues within our security controls.
Support external and internal audits by preparing documentation and coordinating with auditors, follow ups and findings remediation.
Serve as a key liaison between technical teams, legal, internal audit, and business units to ensure a unified approach to security and compliance
Requirements
What we're looking for
BA/BS in Computer Science, Information Systems, or similar field.
Professional security certifications (CISSP, CISM, CISA, ISO 27001 Lead Implementer or equivalent).
Minimum 5 years of experience in the field or in a related area.
Solid understanding and previous experience of security control frameworks (NIST, PCI DSS, GDRP, ISO 27001, NIS2)
Hands-on experience with GRC platforms (e.g. RSA Archer, SAP GRC, StandardFusion, ServiceNow, OneTrust, etc).
Strong ability to manage and report on multiple projects, prioritizing efforts, managing time effectively, and requiring minimal direction in the execution.
Proven problem solving, analytical and investigative skills combined with the ability to develop creative solutions and navigate through ambiguity in a fast-paced, agile environment.
Proven team player, collaborating well with others to tackle problems in a team-focused dynamic.
Excellent written and communications skills, as well as strong interpersonal and relationship building skills.
Experience with compliance in cloud environments (AWS, Azure, GCP) and knowledge of frameworks like the Cloud Controls Matrix (CCM).
Experience in risk quantification methodologies (e.g., FAIR) to assess financial and operational impact of security risks.
Strong background in designing and delivering effective security awareness programs to foster a security-first culture.
Nice to have
Development skills to automate integrations or processes (e.g. python).
Experience with developing, documenting, and testing Business Continuity Plans (BCP) and Disaster Recovery (DR) plans.
Working knowledge of the EU AI Act, including its risk-based approach and requirements for high-risk and general-purpose AI models. Familiarity with AI security threats and relevant frameworks (NIST AI RMF, MITRE ATLAS).
How they hire
Recruiter conversation
With a recruiter
You'll meet one of our recruiters to talk about your motivation, your background, and why you think Glovo could be your next move. We'll also cover cultural alignment and help you understand what the next steps will look like.
Technical problem interview
In this interview, you'll work through a specific technical problem. We want to understand how you think, how you structure your solution, and how you write clean, efficient, and easy-to-follow code. We'll look at your grasp of data structures, performance, and overall problem-solving approach.
Whiteboard interview
In this interview you will use a whiteboard to solve a specific high-level problem and communicate it clearly to your interviewers. We assess how simple, maintainable, and flexible-to-change your solution is.
Stakeholder meeting
With a stakeholders you'd potentially work with
You'll meet with other relevant stakeholders you'd potentially work with. This step is all about making sure we're a strong mutual match — in values, in energy, and in how we work together.
Offer · With a recruiter
- Glovo publishes this tech process alongside a separate one for business roles.
About Glovo
Glovo is a Barcelona-based on-demand delivery platform that connects users with local couriers and partner stores to deliver food, groceries, and other products in minutes. Operating across more than 25 countries in Europe, Africa, Asia, and Latin America, the company has become one of Europe's leading multi-category delivery apps, processing millions of orders annually and employing thousands of people globally.
Glovo was founded in Barcelona in 2015 and maintains its global headquarters there, with a significant presence in Spain. The company is known for its fast-paced, startup-like culture, flexible working arrangements, and a strong focus on technology, data, and product innovation, making it an attractive option for international professionals looking to work in a dynamic, multicultural environment in Spain.
- Industry
- Delivery
- Founded
- 2015
- Employees
- 1,000–5,000
- Headquarters
- Barcelona, Spain
- In Spain
- Barcelona, Madrid, Valencia and 7 more
- Website
- glovoapp.com
Good to know if you are moving
- Glovo's official working language is English, making it accessible for international hires who do not speak Spanish.
- The company offers a flexible remote-work policy, with many roles open to fully remote candidates from anywhere in Spain or abroad.
- Barcelona, where Glovo is headquartered, is a major European tech hub with a large international community and excellent connectivity.
- Glovo provides relocation support and visa sponsorship for senior and specialized roles, easing the move to Spain.
- The company's culture is described as fast-paced and autonomous, with a strong emphasis on ownership and impact, appealing to professionals from high-growth startup backgrounds.
In their own words
About the company & team
Glovo is part of the Delivery Hero Group, the world's pioneering local delivery platform, our mission is to deliver an amazing experience-fast, easy, and to your door. We operate in around 65 countries worldwide. Headquartered in Berlin, Germany. Delivery Hero has been listed on the Frankfurt Stock Exchange since 2017 and is part of the MDAX stock market index.
Additional information
At Glovo, your success is defined by both results and behaviors. We hire for excellence in craft and for the Leadership Principles that shape how we think, decide, and collaborate. What you achieve matters and how you achieve it defines us. Together, they move the business forward and deliver great experiences. Learn more about our Leadership Principles here.
Here at Glovo, we thrive on diversity, we believe it enhances our teams, products, and culture. We know that the best ideas come from a mashup of brilliant diverse minds. This is why we are committed to providing equal opportunities to talent from all backgrounds – all genders, racial/diverse backgrounds, abilities, ages, sexual orientations and all other unique characteristics that make you YOU. We will encourage you to bring your authentic self to work, fostering an inclusive environment where everyone feels heard.
Feel free to note your pronouns in your application (e.g., she/her/hers, he/him/his, they/them/theirs, etc).
So, ready to take the wheel and make this the ride of your life?
Delve into our culture by taking a peek at our Instagram and check out our LinkedIn and website!









