Senior Information Security GRC AnalystFlexibel; Madrid, Spanien; Barcelona, Spanien; Lissabon,[...]
hace 2 meses
ABOUT THE JOB
As a Senior Information Security GRC Analyst, you will have experience in the day-to-day management, delivery and tracking of actions towards our assurance and compliance programmes.
You will have knowledge and practical experience of regulatory compliance activities (e.g. GDPR) and have a view on how delivery and tracking of compliance actions could be accomplished.
This role will also be responsible for filling policy and standards gaps across the company.
The role will deliver regular reporting to senior stakeholders within the organisation to inform decision making and appropriate investment.
This role will directly assist in enabling TUI to meet its strategic goals. Specifically, you will be responsible for delivering the following:
Management and reporting on the status and performance of assurance and compliance programmes.
Owning the day-to-day operation of TUI’s application assurance and cyber resilience programmes.
Prioritising and managing the workload between the GRC Analysts in the team.
Managing the documentation workflow and producing policy, process and guidelines in the appropriate format by liaising with a wide range of stakeholders, driving the approval process and publishing the documents.
Supporting the wider GRC team (including the Information Security Officers and Information Security Managers) on a variety of GRC-related activities.
Managing the roadmap, prioritising and filling gaps in policy, standards, procedures and frameworks working with the wider GRC team and subject matter experts.
Building roadmaps for continued compliance against applicable standards.
Becoming a subject matter expert to IT and the business to support delivery against the standards.
Manage and mature the CMDB of compliance / governance assets.
Our information security team works in collaboration with business and IT teams across our many businesses. You will build strong working relationships and influence others to do the right thing to protect our smile.
ABOUT YOU
Significant experience with managing compliance or assurance activity in a large travel / web / retail organisation.
Strong ability in prioritising a wide breadth of tasks based on both internal and external factors.
Excellent communication skills, both written and oral.
Ability to produce clear documentation in English.
Excellent organisational skills and attention to detail.
Information Security Audit skills and experience.
Strong experience in a large-scale enterprise organisation, preferably a retail or financial organisation.
Strong knowledge of ISO27001, GDPR and associated legislation.
Excellent influencing skills.
Excellent interpersonal skills including persuasiveness and/or assertiveness skills.
Relevant security qualifications (e.g. CISM, CISSP, Security+, PCI P etc.) or equivalent qualifications are a nice to have.
Experience using standards and frameworks such as NIST, OWASP, ITIL and COBIT.
Ability to understand the needs, objectives and constraints of those in other teams.
OUR OFFER
Being a valuable team member of TUI, the No.1 global and socially aware travel company.
Competitive salary and benefits.
Smart working (Flexible hours) and possibility of working remotely up to 100% or Hybrid from one of our offices.
Develop yourself as part of a friendly, richly diverse virtual international team.
If you want to know more about why TUI Group is the world’s leading tourism group, and our continuing work in the diversity & inclusion space, simply visit careers.tuigroup.com.
TUIjobs
#J-18808-Ljbffr
-
Senior GRC Security Engineer
hace 5 días
Centro, España SGS A tiempo completoCompany Description We are SGS – the world's leading testing, inspection and certification company. We are recognized as the global benchmark for sustainability, quality and integrity. Our 99,600 employees operate a network of 2,600 offices and laboratories, working together to enable a better, safer and more interconnected world. Job Description The...
-
Consultor Senior GRC, Madrid
hace 5 días
Centro, España Michael Page A tiempo completoConsultor Senior GRC en Madrid.Perfil buscado (Hombre/Mujer): Gestionar y supervisar la implementación de políticas y procedimientos GRC. Proporcionar asesoramiento estratégico a los clientes en cuestiones de GRC. Desarrollar e implementar programas de formación GRC. Mantenerse al día con las tendencias y regulaciones de la industria de Tecnología y...
-
CISO - Chief Information Security Officer - Madrid
hace 2 meses
Centro, España Asesoresygestores A tiempo completoCISO - Chief Information Security Officer - Madrid Asesores y Gestores International Recruitment Group is looking for a CISO (Chief Information Security Officer) in Madrid. Position to support SMEs worldwide. Head Office and Security Operations Center (SOC) in Madrid. If you value an entrepreneurial project, to be able to access the shareholding and...
-
Information Security, Risk
hace 2 meses
Centro, España Fever España A tiempo completoHi, we’re Fever. We’re excited you are checking out this job offer. We are the leading global live-entertainment discovery tech platform with a clear mission: to democratize access to culture and entertainment. How do we achieve our mission? Fever has developed a proprietary technology that inspires a global community of over 125M people through...
-
Information Security Analyst
hace 3 semanas
Centro, España Firewood Marketing, Inc. A tiempo completoInformation Security Analyst • Madrid Europe This position is intended to be involved in the implementation and improvement of administrative and technical controls of the company's Information Security Management System. This person should understand the risk assessment process to detect new threats, contribute in the action plan development and promote...
-
Information Security Analyst
hace 2 meses
Centro, España Monks Associates Inc A tiempo completoInformation Security Analyst • Madrid Europe This position is intended to be involved in the implementation and improvement of administrative and technical controls of the company's Information Security Management System. This person should understand the risk assessment process to detect new threats, contribute in the action plan development and promote...
-
Information Security Specialist
hace 5 días
Centro, España GMV Spain A tiempo completoIf you are passionate about information security, risk analysis, and compliance, GMV is your place! We are expanding our teams in the defense and security sector to participate in projects related to information security. WHAT CHALLENGE WILL YOU BE TAKING ON? In our defense and security team, you will participate in activities related to the certification...
-
GRC Solutions Senior Analyst
hace 2 meses
Centro, España Amadeus A tiempo completoGRC Solutions Senior Analyst - Archer IRM GRC Solutions Senior Analyst - Archer IRM Job Title Job Title GRC Solutions Senior Analyst - Archer IRMSummary of the role The GRC (Governance, Risk and Compliance) Solutions Senior Analyst is responsible for defining, building, delivering, and maintaining Risk Management applications in...
-
GRC Solutions Senior Analyst
hace 2 meses
Centro, España Amadeus IT Group A tiempo completoGRC Solutions Senior Analyst - Archer IRM Job Title: GRC Solutions Senior Analyst - Archer IRM Summary of the role The GRC (Governance, Risk and Compliance) Solutions Senior Analyst is responsible for defining, building, delivering, and maintaining Risk Management applications in alignment with the Amadeus business strategy. This role will enable...
-
Head Of Technology
hace 2 meses
Centro, España TUI A tiempo completoABOUT THE JOB As a Head Of Technology, you will be responsible for leadership of the IT members of several cross-functional, agile teams, and oversee shaping, development, delivery and operation of business-critical initiatives, products and services. Your key responsibility is to the people you support, ensuring that they are growing within their area of...
-
Consultor/a GRC en Ciberseguridad
hace 5 días
Centro, España Govertis A tiempo completoConsultor/a GRC en Ciberseguridad - Riesgos - Madrid Contrato Indefinido Jornada completa • Consultoría especialista en Ciberseguridad - Análisis de riesgos Conocimientos obligatorios: Experiencia mínima de 3 años en proyectos de seguridad de la información y ciberseguridad relacionada con riesgos. Estar en posesión de una de las siguientes...
-
Information Security Analyst II, Customer Trust
hace 2 meses
Centro, España Datadog A tiempo completoThe Customer Trust team is the face of Datadog’s security organization. Members of the Customer Trust team interact directly with our customers, and translate customer security and compliance requirements into the overall Datadog information security program. You will support the sales organization in the procurement phase and ongoing vendor management...
-
Consultor/a GRC en Ciberseguridad
hace 5 días
Centro, España Govertis A tiempo completoConsultor/a GRC en Ciberseguridad - Madrid Contrato: Contrato Indefinido, Jornada completa Conocimientos obligatorios: Experiencia mínima de 5 años en proyectos relacionados con consultoría en Ciberseguridad. Experiencia en el trabajo con mejores prácticas y normativa en Ciberseguridad (ISO 27001, ENS, RGPD/LOPDGDD, NIST, ENISA, …). Experiencia en...
-
Centro, España TUI A tiempo completoABOUT THE JOB Backend environments: .NET C# experience. Web services development (API REST). Freedom to recommend and implement new technologies into the stack. Participation in code reviews and other peer-based development activities. Provide technical support. ABOUT YOU Experience with .NET Core. Experience with .NET framework and C#. Web Development (MVC...
-
System Engineer
hace 2 meses
Centro, España TUI A tiempo completoABOUT THE JOB As a System Engineer, you will be part of a cross-functional team that enables networking engineering skills and capabilities across TUI. You will provide technical leadership within your team, shape engineering processes and practices, coach and develop other team members, promote a quality-first ethos, and champion continuous improvement and...
-
Senior Networking
hace 2 meses
Centro, España ING A tiempo completoAt ING we are looking for Senior Networking & Security Infrastructure Engineer Your role and work environment: We are looking for a talented and enthusiastic Senior Networking & Security Infrastructure Engineer to join our Networking & Security Infrastructure Team of Cloud & Tech Foundation Tribe. The responsibility of this team is to manage IT-network &...
-
Senior Security Specialist Remediation
hace 5 días
Centro, España BASF SE A tiempo completoSenior Security Specialist Remediation (m/f/d) At BASF Digital Hub Madrid we develop innovative digital solutions for BASF, create new exciting customer experiences and business growth, and drive efficiencies in processes, helping to strengthen BASF´s position as the digital leader in the chemical industry. We believe the right path is through creativity,...
-
Corporate Security Manager, Madrid
hace 2 meses
Centro, España Michael Page A tiempo completoCorporate Security Manager en Madrid.Perfil buscado (Hombre/Mujer) Diseñar implementar y mantener las políticas y procedimientos de seguridad de la empresa. Supervisar el cumplimiento de las políticas y regulaciones de seguridad de la información. Gestionar la respuesta a incidentes de seguridad y realizar investigaciones cuando sea necesario. Evaluar y...
-
IT Security Analyst
hace 1 mes
Centro, España BOARD Deutschland GmbH A tiempo completoAt Board, we power financial and operational planning solutions for the world’s best brands. Thousands of enterprises use our technology to optimize resources, drive growth, and ensure profitability. With advanced analytics and forecasting, plus AI-driven insights, customers transform complex, real-time data into actionable intelligence. What’s been key...
-
Global IT Security Regional Head
hace 2 meses
Centro, España DUFRYS A tiempo completoRole Profile Key Accountabilities Policy, Compliance and Audit: Develop and implement effective and reasonable policies and practices to secure protected and sensitive data and ensure information security and compliance with relevant legislation and security frameworks. Internally assess and evaluate the risk. Report to Global CISO on security project...