GRC Consultant & Cybersecurity Strategy

GRC Consultant & Cybersecurity Strategy

Excelia
Excelia
Madrid, SpainCompetitiveHybridAdded 2 days agoSenior · 2+ yearsPermanent🇬🇧English: Required

Need a visa? No sponsorship mentioned here. Browse visa jobs.

About the role

At Excelia, a multinational Consulting, Technology, and Professional Services firm with over 25 years of experience and a presence in more than 50 countries across Europe, Latin America, and the United States through our 9 own offices, we continue to grow and want to bring talent into our Cybersecurity and Risk team.

We are looking for a Senior GRC and Cybersecurity Strategy Consultant with experience in defining Cybersecurity Master Plans, assessing maturity, and security governance, who wants to take part in strategic transformation and risk management projects.

What you'll do

  • Lead end-to-end one or more workstreams of Cybersecurity Master Plan projects, being responsible for the quality and delivery of results.

  • Design and execute cybersecurity maturity assessments based on reference frameworks such as NIST CSF, ISO/IEC 27001, ENS, and CIS Controls.

  • Conduct interviews and working sessions with stakeholders from different areas to identify gaps and improvement opportunities.

  • Define cybersecurity dashboards (KPI/KRI) aligned with business objectives and prepare prioritized recommendations based on risk analysis.

  • Prepare executive reports on the state of cybersecurity to support strategic decision-making.

  • Participate in defining and evolving cybersecurity governance models, including roles, responsibilities, committees, and reporting processes.

  • Align the cybersecurity strategy with governance and management frameworks such as COBIT, ISO 38500, and NIST AI RMF.

  • Facilitate workshops and working sessions with technical and business teams.

  • Coordinate and supervise the work of junior profiles, reviewing deliverables and providing mentoring.

  • Manage the planning, tracking, and evolution of assigned activities within the project.

What you'll get

  • 📝 Stable position within a growing international company.

  • 💰 Salary band based on experience and seniority.

  • 📊 Flexible compensation plan.

  • 📚 Ongoing training and professional development plan.

  • 🌍 Participation in strategic national and international projects.

  • ⏰ Flexible working hours and work-life balance.

How you'll work

Hybrid, in Madrid (2 days on-site)

full-time

Permanent

Hiring process

If you want to join a team specialized in cybersecurity strategy, governance, and risk management, working on high-impact projects for large organizations, we would love to meet you!

📌 Requirements

  • University degree in Computer Engineering, Telecommunications, or a related field.

  • More than 2 years of experience in cybersecurity consulting, GRC, or technology risk management.

  • At least 2 years of experience in Cybersecurity Master Plan projects, maturity analysis, or security strategy definition.

  • Experience working with frameworks and standards such as ISO/IEC 27001, NIST CSF, ENS, CIS Controls, COBIT, or ISO 38500.

  • Ability to interact with technical and executive profiles, adapting the message to the audience.

  • English level C1 or high B2 with experience participating in international meetings.

  • Certifications such as CISM, CRISC, or equivalent will be valued.

This job was automatically translated to English, .

Apply at Excelia