Governance Technician

Telefónica·Spain

What they ask for

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Speak native-level Spanish

    Listed as a requirement in the ad.

  • Work in English

    English is required, per the ad.

  • Work on-site in Spain

    No relocation package mentioned.

  • Have 3+ years of experience

    Mid-level role.

Pulled from the advert automatically — the full ad is what counts.

Added 1 month ago
Read the full advert

About the role

We connect the present. We transform the future.

Have you ever wondered what makes it possible for millions of people to be connected at the same time, from anywhere in the world, without anything failing?

At Telefónica, we make it possible.

We are a global telecommunications and technology company that connects people, businesses, and communities through next-generation networks and advanced digital solutions such as cloud, artificial intelligence, IoT, and cybersecurity.

With over 100 years of history, we work every day to ensure that innovation serves society, driving a digital transformation that is responsible, sustainable, and has real impact.

Here, we don't just design infrastructure—we design the future. We are looking for people who are curious, enthusiastic, and passionate about what they do, who never settle, and who want to build the Telefónica of tomorrow.

If you are passionate about technology that transforms lives, this is your place.

What you'll do

  • Drafting, review, and management of the approval cycle for regulations and global security documents, in coordination with subject matter expert areas, security areas, and global Telefónica areas. Definition of global digital security controls, including information security and cybersecurity (access control and identity management, hardening, security patching, backup, security event monitoring, incident management, vulnerability management, cyber intelligence, etc.), both at the infrastructure and application layers, as well as organizational and management requirements (establishment of responsibilities, risk management, monitoring and measurement, continuous review and improvement, training and awareness, etc.). Coordination with the rest of the areas under the global Security and Intelligence Management for the review of global regulations associated with physical and personnel security, operational resilience, and supply chain security. Alignment with international best practices and standards.
  • Monitoring and evaluation of digital security measures, through a framework of indicators (KPIs) for monitoring compliance with regulatory requirements and digital security performance across the different units and companies of the Telefónica group (OBs/GBUs), both in on-premise and Cloud environments. Evolution of the framework, consolidation of data received from the different units, analysis, and reporting.
  • Risk management and Information Security Management Systems (GRC/ISMS) in global environments aligned with Telefónica's corporate risk management policies, with pragmatic criteria to support the business in making informed decisions regarding existing digital security risks, alignment of risk management dynamics across business units providing consolidated views to management, and management of global strategic security plans.
  • Liaison with global areas, business units, and interested parties, regarding digital security matters, including cybersecurity, providing the necessary information and contributing to the activities and documents required by interested parties and ensuring compliance with security requirements derived from legislation, regulation (mainly within the European Union and Brazil) or best practices led by other Telefónica areas (Compliance, Internal Audit, Sustainability, Insurance, Technology, Privacy/DPO, Markets, Legal/Regulation, etc.). Communication to the operational security area of requirements associated with physical security, resilience, and supply chain security.
  • Global awareness on digital security, aimed at employees with different profiles and determining the key topics to address based on the analysis of available digital security governance information. Includes content generation, launch coordination, and monitoring and analysis of the effectiveness of training courses, awareness capsules, phishing campaigns, surveys, recognition programs, etc.
  • Coordination and dissemination of information to the local digital security areas of the Telefónica group, including monitoring of budgets and strategic projects, management of content and users on intranets based on Office365 environments, preparation of periodic newsletters, and management and coordination of in-person and virtual events with the parameters set by the global Digital Security Management.
  • Generation of content for digital security awareness courses and capsules, coordination of launch and monitoring.
  • Creation of phishing campaigns, coordination of launch and monitoring.
  • Consolidation of information, composition, and sending of the monthly digital security newsletter.
  • Request to OBs/GBUs, collection and consolidation of digital security indicator data.
  • Support in the management, monitoring, support, and evolution of the digital security indicator framework, including the preparation of specific reports to management, committees, OBs/GBUs, and other areas.
  • Content management on security intranets.
  • Access management on digital security intranets.
  • Collaboration in the rest of the activities of the global Digital Security Governance unit as required.
  • Reporting to the Heads of the global Digital Security Governance unit and to the Manager in charge.

What other aspects are relevant?📚

What we're looking for

  • The development of the work will require the application of knowledge in the implementation of digital security controls and information security management systems (ISMS) following ISO27001 regulations, ENS, and risk management methodologies such as ISO 27005, ISO 31000, as well as IT Governance, Compliance, and IT Audit.
  • Knowledge of regulations such as NIS/NIS2, GDPR, SOX, PCI-DSS, DORA, CRA, CER, etc., and aspects related to Cybersecurity (vulnerability management, incident management and notification, ethical hacking - Red Team, etc.) is required.
  • Advanced proficiency in Word, Excel, and PowerPoint, messaging and collaboration tools in M365 environments, and use of AI tools such as Copilot.
  • Perseverance and tenacity in pursuing results delivery in projects with multiple axes of complexity (technical, organizational, political,...) are required.
  • Analytical capacity,
  • Internal stakeholder management,
  • Excellent oral and written communication,
  • Organizational and planning skills,
  • Results orientation,
  • Communication skills,
  • Interpersonal relationships and teamwork,
  • Ability to document, model, and synthesize in the drafting of deliverables,
  • Prioritization and presentation of results,
  • Autonomy and proactivity.
  • 3 years of demonstrable experience in digital security process governance, strategic security project management, risk management and ISMS, regulatory development and compliance, security audits, or in environments regulated under ENS, SOX, NIS/NIS2, CRA, etc., are required.

Nice to have

  • Knowledge of programming and data management using PowerBI will be valued.
  • Experience in the development and maintenance of best practices and standards in physical security, business continuity, supply chain security, and fraud management will be valued.
  • Experience in the implementation of specific architectures and/or technical tools for the Digital Security domain, as well as practical experience in physical security management, resilience, and supply chain security, will be valued.
  • Knowledge of the Telefónica group's organization and/or experience in the Telecommunications and mobile networks field will be valued.

What advantages will you have by being part of our team?💙

Education & certifications

  • Education in Telecommunications Engineering, Computer Science, or similar.
  • It is necessary to have courses in some of the following areas:
  • Cybersecurity (hacking, technical protection tools)
  • International reference regulations (ISO 27001 and NIST),
  • Legislation and regulation with security requirements (NIS/NIS2, GDPR, ENS, PCI-DSS, SOX, DORA, CRA, CER).
  • Having any of the following certifications will be valued: CISM, CISA, CRISC, ISO27001 Implementer/Auditor, ISO22301 Implementer/Auditor, ENS Implementer/Auditor, etc.

Languages

  • Spanish and English (native in one of them and very high level in the other). Basic level of Portuguese will be valued.

How will you contribute to the purpose of the role with your skills? 💼

What you'll get

  • Transformative projects. At Telefónica, you will be part of high-impact projects that set trends and address the connectivity and digital transformation challenges of our society.
  • Professional development. You will have a long career path and learning opportunities on a global scale, thanks to our presence in different geographies. We will share with you opportunities for development, training and mobility options. We want to grow and build a future with you!
  • Flexibility. We are committed to the balance between professional and personal life. At Telefónica, we care about flexibility, positioning ourselves as a benchmark in new ways of working and work-life balance measures.
  • 27 working days of vacation to enjoy.
  • Social benefits. You will be able to enjoy a comprehensive package of social benefits, including:
    • Life and accident insurance
    • Medical insurance for you and your family unit (spouse and children)
    • Meal voucher card
    • Flexible compensation plan with numerous options to choose from.
    • Pension plan

And much more!

About the company & team

The Digital Security Governance Management reports to the global Governance and Architecture Management, under the global Digital Security Management and the global Security and Intelligence Management of Telefónica.

What skills are we looking for in you? 🔎

Additional information

At Telefónica, we are committed to building a diverse, inclusive, and sustainable work environment where every person feels valued, respected, and free. Our culture is based on equal opportunity and inclusion because we have the responsibility to transform society and make the world a better place.

If you want to be part of an innovative team and contribute to a better future, we are waiting for you!

This job was automatically translated to English, .

About the company

Telefónica

Telefónica

Telecom

View company profile
Spanish company
100000 employees