GRC Consultant - Cybersecurity (Bilbao)

GRC Consultant - Cybersecurity (Bilbao)

Excelia
Excelia
Madrid, SpainCompetitiveHybridAdded 2 days agoMid · 2+ yearsPermanent

Need a visa? No sponsorship mentioned, and this kind of work is rarely sponsored in Spain. See which routes exist.

About the role

We are looking for a cybersecurity GRC profile with experience in technology risks and information security frameworks, who wants to participate in strategic projects for assessing, defining, and improving compliance and risk management.

What you'll do

  • Assessment and management of technology risks in corporate environments.

  • Definition and implementation of security controls aligned with international standards.

  • Participation in regulatory compliance and security audit projects.

  • Application of frameworks such as ISO/IEC 27001, NIST, and cybersecurity best practices.

  • Gap analysis and definition of remediation plans.

  • Advisory support to technical and business teams on security and compliance matters.

  • Support in defining and improving information security policies and procedures.

What you'll get

  • 📝 Stable employment at an international company.

  • 💰 Salary package aligned with experience.

  • 📊 Flexible compensation.

  • 📚 Ongoing training in cybersecurity, GRC, and compliance frameworks.

  • ⏰ Hybrid work model and flexible hours.

  • 🌍 Participation in high-impact international projects.

How you'll work

Bilbao (hybrid model).

full-time

Permanent

About the company & team

At Excelia, a multinational consulting, technology, and professional services firm with over 25 years of experience and a presence in more than 50 countries across Europe, Latin America, and the United States through our 9 own offices, we continue to grow and want to bring talent into our Cybersecurity and Risk team.

Hiring process

If you are motivated to work in technology risk management, compliance, and international security frameworks, we would love to meet you!

📌 Requirements

  • Technical education (Computer Engineering, Telecommunications, or similar).

  • Minimum 2 years of experience in GRC, technology risk, or information security roles.

  • Knowledge of frameworks and standards: ISO 27001, NIST, or equivalent.

  • Ability to analyze risks and define security controls.

  • Profile with a holistic security vision (not necessarily deep technical implementation).

  • Experience in security auditing or consulting is a plus.

You'll most likely need Spanish to apply.This job was automatically translated to English, .

Apply at Excelia