Senior GRC Specialist

hace 4 semanas


Madrid, España UST A tiempo completo

Senior GRC Specialist (Cybersecurity)
Role description

We are still looking for the very Top Talent...and we would be delighted if you were to join our team

More in details, UST is a multinational company based in North America, certified as a Top Employer and Great Place to Work company with over 35.000 employees all over the world and presence in more than 35 countries. We are leaders on digital technology services, and we provide large-scale technologic solutions to big companies.

What we look for?

We are looking for a GRC Specialist contribute for a project with one of our global customers in the cybersecurity team.

Skills:

- 4 years experience in audits and compliance and assessments based on national and international standards (ISO27001, ISO22301, ENS, NIST, DORA, NIS2)

- Knowledge/certifications in ISO27001 is a must. It is also desirable knowledge in ENS, ISO 27005, ISO22301, ISO 42001, NIST CSF 2.0, NIST, SOC 2, GDPR, DORA, NIS2, CMMC 2.0

- Proficiency with a variety of instruments for assessing and controlling risk (ex. ISO 31000, Magerit v3, COSO)

- Experience in implementation of best practices, compliance with information security policies and standards.

- Technical experience or applicable knowledge in security architectures for different environments.

- Experience related to Cybersecurity ecosystem, deployment experience of security technologies.

- Knowledge of different security solutions/technologies: FW, DLP, IDS/IPS, EDR...

- Experience in incident response plans and exercises

- Fluent in English

- Computer Engineering/Telecommunications and/or Master in Cybersecurity It is also desirable and will be considered to hold certifications such as CISM, CISSP, CISA, ISO/IEC 27001 Lead Auditor / Lead Implementer. We will also consider knowledge of HIPAA, ARC-AMPE or OT Cybersecurity (ISO 27019 / IEC 62443) for the more senior role

Tasks:

- Handle the assigned tasks from the allocated domain with minimal guidance from the leads. (Domain Examples: BCMS, ISMS, Risk assessment (AARR BIAs), GAP Analysis, Incident management, Awareness activities, Data Privacy, etc.)

- Independently handle (with very minimal guidance from the supervisors) internal audits or GAP Analysis to ensure compliance with security standards (ex. ISO 27001/ISO 22301/ISO 27701, NIST CSF 2.0, ..) requirement as well as process specific requirements

- Responsible for the effective documentation of projects individually.

- Point out the non-conformance areas and suggest measures to improve the information security individually.

- Ensure that risk management is effectively conducted across the organization, business processes and information systems.

- Involve and contribute to customer assurance activities.

- Coordinate information security awareness training programs for all the employees, contractors and approved system users.

- Coordinate and Review the technical assessments of IT systems and processes to identify potential risks. Submit recommendations to mitigate any risks identified and ensure controls that they are implemented.

- Design, plan and execute the Cybersecurity activities.

- Directly Interact with customer and communicate detailed technical requirement to the team.

- Use independent judgement and discretion to analyze the system security.

- Prepare detailed description of user requirements and steps required to perform a compliance project in basis a standard or regulation.

- Learn and understand existing regulations or standards requirements.

- Independently handle the evidence collection from multiple teams as part of any internal audits.

- Policy/Procedure creation activities and process improvement ideas to be implemented.

- Research and analytical skills, including the ability to convert complex policy issues into simple briefings and communicate to the audience.

Location: 4 days remote 1 day at the office.

Schedule: Office working hours

What can we offer?
- 23 days of Annual Leave plus the 24th and 31st of December as discretionary days
- Numerous benefits (Heath Care Plan, Internet Connectivity, Life and Accident Insurances).
- Retribución Flexible Program: (Meals, Kinder Garden, Transport, online English lessons, Heath Care Plan...)
- Free access to several training platforms
- Professional stability and career plans
- UST also, compensates referrals from which you could benefit when you refer professionals.
- The option to pick between 12 or 14 payments along the year.
- Real Work Life Balance measures (flexibility, WFH or remote work policy, compacted hours during summertime...)
- UST Club Platform discounts and gym Access discounts

In UST we are committed to equal opportunities in our selection processes and do not discriminate based on race, gender, disability, age, religion, sexual orientation or nationality. We have a special commitment to Disability Inclusion, so we are interested in hiring people with disability certificate.

Ciberseguridad, NIST, ENS, DORA



  • Madrid, Madrid, España Minsait A tiempo completo

    Ubicación:Madrid, ESPerfil profesional: Medios de PagoExperiencia requerida: Más de 2 años de experienciaModalidad del puesto:Este es el retoEn Minsait, creemos en el talento que impulsa el cambio. Únete a nuestro equipo de Nuek como Senior Cybersecurity GRC Specialist y sé parte de esta transformación.Sobre el equipo y su impactoSer parte de nuestro...

  • Consultor/a Senior Grc

    hace 4 días


    Madrid, España BSD Enterprise A tiempo completo

    **Rol**: - Consultor/a Senior GRC (Gestión Riesgo Y Cumplimiento) **Requisitos**: - Para aproyecto estable se requere Consultor/a Senior GRC Inmpresindible Conocimiento de **estándares y frameworks de seguridad (ENS, NIST CSF, UNE-ISO/IEC 27001, etc.).**: - Titulación Ingeniero en informática. - **Gestión de riesgos de seguridad.**: - Al menos una...


  • Madrid, España Tuyú Technology A tiempo completo

    Especialista Cyber GRC¡Impulsa tu carrera con TUYÚ Technology!¿Te interesa la Gobernanza, Riesgo y Cumplimiento en Ciberseguridad y quieres trabajar en un entorno bancario exigente y regulado? En TUYÚ Technology buscamos incorporar un/a Cyber GRC Specialist para un proyecto estable y de alto impacto.¿Qué te ofrecemos?Proyectos innovadores y de larga...


  • Madrid, España Experis A tiempo completo

    A leading cybersecurity consultancy in Madrid seeks a Cyber GRC Specialist to ensure cybersecurity governance and compliance. Responsibilities include analyzing controls, monitoring compliance, and managing remediation processes. Candidates should have a degree in Computer Engineering or similar, at least 2 years of relevant experience, and strong English...


  • Madrid, España Tuyú Technology A tiempo completo

    Especialista Cyber GRC ¡Impulsa tu carrera con TUYÚ Technology! ¿Te interesa la Gobernanza, Riesgo y Cumplimiento en Ciberseguridad y quieres trabajar en un entorno bancario exigente y regulado? En TUYÚ Technology buscamos incorporar un/a Cyber GRC Specialist para un proyecto estable y de alto impacto. ¿Qué te ofrecemos? Proyectos innovadores y de...


  • Madrid, España Tuyú Technology A tiempo completo

    Especialista Cyber GRC ¡Impulsa tu carrera con TUYÚ Technology! ¿Te interesa la Gobernanza, Riesgo y Cumplimiento en Ciberseguridad y quieres trabajar en un entorno bancario exigente y regulado? En TUYÚ Technology buscamos incorporar un/a Cyber GRC Specialist para un proyecto estable y de alto impacto. ¿Qué te ofrecemos? Proyectos...


  • Madrid, España Tuyú Technology A tiempo completo

    Especialista Cyber GRC ¡Impulsa tu carrera con TUYÚ Technology! ¿Te interesa la Gobernanza, Riesgo y Cumplimiento en Ciberseguridad y quieres trabajar en un entorno bancario exigente y regulado? En TUYÚ Technology buscamos incorporar un/a Cyber GRC Specialist para un proyecto estable y de alto impacto. ¿Qué te ofrecemos? Proyectos...


  • Madrid, España Tuyú Technology A tiempo completo

    Especialista Cyber GRC ¡Impulsa tu carrera con TUYÚ Technology! ¿Te interesa la Gobernanza, Riesgo y Cumplimiento en Ciberseguridad y quieres trabajar en un entorno bancario exigente y regulado? En TUYÚ Technology buscamos incorporar un/a Cyber GRC Specialist para un proyecto estable y de alto impacto. ¿Qué te ofrecemos? Proyectos...


  • Madrid, España Inetum A tiempo completo

    Una empresa de servicios digitales en Madrid busca un Consultor/a senior SAP GRC con al menos 5 años de experiencia en la implementación y soporte de soluciones GRC dentro de SAP. Se requieren conocimientos en Access Control, Process Control, Risk Management y habilidades para gestionar múltiples proyectos y relaciones con clientes. Ofrecemos contrato...

  • Senior Grc Analyst

    hace 6 días


    Madrid, España Enverus A tiempo completo

    **Senior GRC Analyst in Spain** **Why YOU want this position** Enverus is the leading energy SaaS company delivering highly technical insights and predictive/prescriptive analytics that empower customers to make decisions that increase profit. Enverus’ innovative technologies drive production and investment strategies, enable best practices for energy...