Governance Security Specialist

Governance Security Specialist

Excelia
Excelia
Madrid, Spain (Remote)CompetitiveRemoteAdded yesterdayMid · 2+ yearsPermanent

Need a visa? No sponsorship mentioned, and this kind of work is rarely sponsored in Spain. See which routes exist.

About the role

At Excelia, a multinational Consulting, Technology and Professional Services firm, we have more than 25 years of experience and a presence in more than 50 countries across Europe, Latin America and the United States, through our 9 own offices.

We are currently looking for an IT Audit & Compliance Specialist to join a stable project in the payments sector, taking part in managing controls, audits, and regulatory compliance in cloud environments.

What you'll do

  • Maintain and oversee IT controls aligned with the main applicable standards and regulatory frameworks.

  • Monitor compliance with PCI DSS v4.0, ISO/IEC 27001, DORA, and SOC 2 Type II.

  • Collaborate with the different business and technology areas to ensure compliance with corporate policies and procedures.

  • Participate in the development, implementation, and continuous improvement of the organization's Information Security framework.

  • Identify, assess, and manage technology risks associated with non-compliance, exceptions, or control weaknesses.

  • Prepare and coordinate internal reviews to facilitate the execution of external audits.

  • Proactively detect and communicate risks, deviations, or potential regulatory non-compliance.

  • Develop improvement recommendations and monitor the associated remediation plans.

  • Participate in governance, risk, and compliance (GRC) initiatives related to cloud environments and payment services.

Nice to have

  • Experience in business continuity and operational resilience projects.

  • Participation in certification or recertification processes for security standards.

  • Knowledge of governance, risk, and compliance (GRC) frameworks.

  • Certifications related to auditing, information security, or risk management.

  • Previous experience in financial institutions, fintech, or payment companies.

What you'll get

📝 Stable contract with an international company.

💻 Company-provided computer equipment.

📈 Participation in strategic audit, compliance, and technology risk management projects.

📖 Ongoing training and professional development.

🌍 Collaborative environment with multidisciplinary teams.

🚀 Career path and growth opportunities within Excelia.

🏠 100% remote model and flexibility.

📩 If you want to continue developing your career in technology auditing, compliance, and risk management within cloud environments and the payments sector, we would love to meet you!

How you'll work

📍 100% remote.

📍 Opportunity to collaborate with national and international teams.

full-time

Permanent

remote

Remote work

Requirements

  • At least 2 years of experience in IT auditing, regulatory compliance, or technology risk management.

  • Experience in auditing and reviewing controls in AWS environments.

  • Solid knowledge of:

    • PCI DSS v4.0 (including Gap Analysis processes, audit preparation, and evidence management).

    • DORA.

    • ISO/IEC 27001.

    • ISO/IEC 27017.

    • ISO/IEC 27018.

    • SOC 2 Type II.

  • Experience in technology risk modeling and management.

  • Knowledge of the payments industry and card-present and card-not-present ecosystems.

  • Ability to coordinate audits, manage evidence, and prepare compliance documentation.

  • Analytical skills, attention to detail, and the ability to engage with multidisciplinary teams.

You'll most likely need Spanish to apply.This job was automatically translated to English, .

Apply at Excelia