The English-language job board for Spain

Information Security GRC Manager

Remote, Europe·Added 21 days ago

Still open when we checked on 3 Oct

JustMarkets

70 open roles

Overview

Job details

  • Fully remote

    Per the ad.

Requirements

  • Have the right to work in Spain

    JustMarkets doesn't mention sponsorship, but this role may fit the Digital nomad visa.

Benefits

  • Gym access

    Free or discounted, per the ad.

Skills

Pay & benefits

What you'll get

  • 20 paid vacation days per year
  • 10 paid sick leave days per year
  • Public holidays according to company policy
  • Medical budget
  • Remote work opportunity
  • Professional education budget
  • Language learning budget
  • Wellness budget (gym membership, sports gear, etc.)

The role

We are looking for an experienced Information Security GRC Manager to lead and develop our Information Security Governance, Risk & Compliance function.

This is a hands-on leadership role with the opportunity to shape the GRC operating model, roadmap, team, and core processes in a growing international FinTech environment.

You will work directly with the CISO and collaborate closely with Security, Legal, Risk, Procurement, IT, Engineering, Product, Platform, HR, and business teams.

The role combines security governance, cyber risk, regulatory assurance, third-party risk, policy management, and security awareness, with a strong focus on building practical controls and processes that support business growth.

What you'll do

  • Own and develop the Information Security GRC strategy, roadmap, operating model, and governance cadence
  • Lead security governance, regulatory assurance, cyber risk, third-party security risk, policy lifecycle, and security-awareness oversight
  • Establish clear ownership for security controls, risks, exceptions, evidence, and remediation actions
  • Coordinate SOC 2, DORA/CySEC-related assurance, internal and external audits, and regulatory requests
  • Maintain cyber-risk and exception registers and ensure material risks are treated, accepted, or escalated
  • Lead security aspects of ICT supplier tiering, due diligence, reassessment, and high-risk supplier decisions
  • Develop practical security policies, standards, controls, and guidance
  • Ensure audit and assurance evidence is reliable, traceable, and reusable
  • Track control gaps, findings, and remediation commitments and escalate material risks
  • Partner with Security, IT, Engineering, Product, Platform, Legal, and business teams on control design and risk-based decisions
  • Prepare concise GRC and risk reporting for the CISO and executive stakeholders
  • Build, develop, and manage the GRC team, including responsibilities, goals, and performance expectations
  • Improve GRC efficiency through automation, reusable evidence, better data quality, and responsible AI-assisted workflows

Requirements

  • Strong practical experience in Information Security GRC, cyber/technology risk, security compliance, or assurance
  • Hands-on experience with recognized frameworks such as SOC 2, ISO 27001, DORA, PCI DSS, NIST CSF, COBIT, or similar
  • Experience establishing or operating security controls, risk registers, exception processes, and assurance programs
  • Strong understanding of control design, operating effectiveness, evidence quality, findings, and remediation
  • Experience coordinating internal or external audits and regulatory or assurance activities
  • Practical experience with cyber risk assessment, risk treatment, risk acceptance, and escalation
  • Understanding of third-party and ICT supplier security risk
  • Ability to translate regulatory and security requirements into practical controls and processes
  • Strong stakeholder management skills and ability to work effectively with technical, business, and executive audiences
  • Sufficient technical understanding of cloud, infrastructure, identity, IT operations, and product development to work effectively with technical teams
  • Experience leading a team, function, program, or complex cross-functional initiatives
  • Strong ownership, prioritization, and decision-making skills

Hiring process

Application review, one or more interviews, then an offer; described as fast and easy 1 interview

  • Applications are reviewed quickly and candidates are kept informed at every step.

About JustMarkets

JustMarkets is a global fintech company operating in the multi-asset brokerage space, providing retail and institutional clients with access to trading in forex, commodities, indices, and shares. The company has grown into an international brand with a significant presence across multiple regions, including Europe, Asia, and Latin America, and is known for its proprietary trading platforms and customer-centric approach.

In Spain, JustMarkets has established a dedicated hub to support its growing client base and expand its European footprint. The company's Spain office is a key part of its global operations, offering roles in engineering, product, design, marketing, and finance. For international professionals, JustMarkets presents opportunities to work in a fast-paced, multicultural environment, with a strong emphasis on technology and data-driven decision-making, making it an attractive option for those looking to build a career in the fintech sector in Spain.

Industry
Fintech
Founded
2012
Employees
500–1,000
Headquarters
Limassol, Cyprus
In Spain
Madrid

Good to know if you are moving

  • The company's global HQ is in Limassol, Cyprus, but its Spain office in Madrid is a key hub for European operations, offering a range of roles in tech, product, and marketing.
  • JustMarkets is a global fintech company, so English is likely the working language, making it accessible for international professionals.
  • The company offers a modern tech stack and data-driven approach, which can be appealing for engineers and data specialists.
  • Roles in Spain span a wide range of functions, from engineering and design to finance and HR, indicating a multi-disciplinary environment.
  • As a regulated broker, the company offers a stable and compliance-focused work environment, which is a plus for professionals from the financial sector.
All open roles at JustMarkets
WhatsApp

Product Designer (Growth)

JustMarkets1d ago
Remote, EuropeNo Spanish needed

Endpoint Security Engineer

JustMarkets1d ago
Remote, EuropeNo Spanish needed
Remote, EuropeNo Spanish needed

Data Analyst

JustMarkets1w ago
Remote, EuropeNo Spanish needed

.NET Engineer

JustMarkets1w ago2 openings
Remote, EuropeNo Spanish needed

Lead Engineering Manager

JustMarkets1w ago
Remote, EuropeNo Spanish needed

Senior Web Designer

JustMarkets1w ago
Remote, EuropeNo Spanish needed
Remote, EuropeNo Spanish needed
Remote, EuropeNo Spanish needed

SMM & UGC Specialist

JustMarkets1w ago
Remote, EuropeNo Spanish needed
Remote, EuropeNo Spanish needed

SMM & Content Producer

JustMarkets1w ago
Remote, EuropeNo Spanish needed
See all 70 jobs