The English-language job board for Spain

GRC Specialist

Remote, Balearic Islands·Added 4 months ago

This job was published 4 months ago

Still open when we checked on 28 Sept

Grupo Sermicro

38 open roles

Overview

Job details

  • Fully remote

    Only from certain places, per the ad: “Modalidad 100% remota desde España.”

Requirements

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • University degree

    “Formación universitaria en Ingeniería Informática, Telecomunicaciones o similar.” — per the ad.

Skills

This job was automatically translated to English.

Requirements

What we're looking for

Requirements

Demonstrable experience in Governance, Risk, and Compliance (GRC) functions.

Solid knowledge of standards and regulatory frameworks such as ISO 27001, NIST, PCI-DSS, ENS, NIS2, DORA, or equivalents.

Experience in corporate and technological risk management.

Experience in security, compliance, or management system audits.

Ability to coordinate cross-functional initiatives with technical and business areas.

General knowledge of information security environments, technologies, and controls.

Experience in project management and monitoring

Nice to have

We will especially value

CISA, CISM, CISSP, CRISC, or similar certifications.

Previous experience in companies within the Travel, Hospitality, or Tourism sectors.

Experience in Information Security Management Systems (ISMS).

Knowledge of Agile methodologies.

Education & certifications

University degree in Computer Engineering, Telecommunications, or similar.

Master's degree or specialized training in Cybersecurity.

Pay & benefits

What you'll get

What we offer

Stable project with a direct impact on the business.

Participation in strategic security and compliance initiatives.

Stable contract

Flexible schedule. 100% remote modality from Spain.

Collaborative environment with multidisciplinary teams.

Flexibility and 100% remote modality from Spain.

The role

We are currently looking for a GRC (Governance, Risk & Compliance) Specialist to join a Security & Fraud team within a major company in the tourism sector.

We are looking for a profile with experience in security governance, risk management, regulatory compliance, and auditing, capable of acting as a link between the business, technology, cybersecurity, and data protection areas, ensuring the correct implementation and monitoring of corporate security frameworks.

Important: Although we value cybersecurity knowledge, this position has a focus primarily oriented toward Governance, Risk, and Compliance (GRC). We are looking for professionals with experience in risk management, auditing, regulatory compliance, ISMS, and security governance, rather than operational cybersecurity functions such as SOC, Pentesting, or Incident Response.

What will your mission be?

You will be responsible for driving and maintaining Governance, Risk, and Compliance (GRC) initiatives within the organization, ensuring the alignment of corporate processes with regulatory, normative, and information security requirements.

What you'll do

Main duties

Maintain and evolve the Information Security Management System (ISMS).

Participate in the definition, implementation, and monitoring of security policies, procedures, and controls.

Manage and coordinate internal and external audits related to information security and compliance.

Identify, evaluate, and monitor corporate and technological risks.

Collaborate in the definition and execution of the Security Master Plan. Supervise compliance with regulatory frameworks and security standards.

Coordinate security governance initiatives with IT, Cybersecurity, and Business teams.

Act as a technical interlocutor with the Data Protection area.

Define and monitor indicators, metrics, KPIs, and OKRs related to security and compliance.

Participate in the continuous improvement of governance, risk, and compliance processes.

Verify the correct implementation and effectiveness of established security controls.

Prepare executive reports and documentation for audits, committees, and governing bodies.

About Grupo Sermicro

Industry
IT Services

In their own words

About the company & team

At DIMÁTICA, a company recognized as a Microsoft Partner, we specialize in the design, development, and maintenance of software solutions in multiplatform environments.

All open roles at Grupo Sermicro
WhatsApp

Python/SQL Support

Grupo Sermicro2d ago
Hybrid in Madrid

Coordinator / Supervisor

Grupo Sermicro2d ago
Madrid

Monitoring Technician - Weekends

Grupo Sermicro1d ago
Barcelona

Field Technician

Grupo Sermicro1w ago
Barcelona

Helpdesk Technician

Grupo Sermicro1w ago
Balearic Islands

User Support Technician

Grupo Sermicro1w ago2 locations
València

Telecommunications Technician

Grupo Sermicro1w ago
Barcelona

Project Management

Grupo Sermicro1w ago
Madrid

Remedy Support Technician

Grupo Sermicro1w ago
Madrid

CAU Technician

Grupo Sermicro1w ago2 openings
Salamanca

Microinformatics Technician

Grupo Sermicro1w ago
Madrid

SAP Basis Administrator

Grupo Sermicro2w ago
MadridNo Spanish needed
See all 38 jobs