GRC Security Expert

Job not on LinkedIn

🔥 0 minutes ago

🇪🇸 Spain – Remote

⏰ Full Time

🟢 Junior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 12%

infoinfo

🗣️🇪🇸 Spanish Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of LEADtech

LEADtech

2 - 10 employees

Founded 2017

🛍️ eCommerce

🛒 Retail

🔧 Hardware

eCommerce • Retail • Hardware

LEADtech is an online Romanian retailer and e‑commerce store that offers a broad catalogue of consumer electronics, IT and computer components, mobile phones, home electronics, gaming gear, appliances, tools, garden equipment, baby products and smart home/security devices. The site content (Romanian language, references to "lei" and sections like "Contul Meu") indicates a web storefront selling products from stock with delivery, account/returns support, and extensive category-based merchandising for consumers and small businesses.

📋 Description

• Develop cybersecurity policies, procedures, and methodologies • Implement applicable standards and regulations • Manage ISO 27001 projects, vulnerability follow-up, and vendor reviews • Align security work with ISO 27001, GDPR, and NIS2 requirements • Develop data protection and privacy initiatives • Identify, troubleshoot, and resolve issues affecting internal and external processes • Manage multiple projects while maintaining quality and regulatory alignment • Engage product, engineering, marketing, and other stakeholders to gather requirements and evaluate options • Develop tools and processes supporting organizational goals

🎯 Requirements

• Degree in Computer Science, Telecommunications, Law or equivalent practical experience • 1 or 2 years of experience in GRC, compliance, IT auditor, or a related role • Working knowledge of ISO 27001:2022, including clause structure, Annex A controls, and SoA • Experience as an auditor, consultant, or implementation specialist • Working knowledge of data protection concepts, including data retention, PIAs, and RATs • Basic familiarity with AWS, GCP, or Azure and IAM concepts such as least privilege, MFA, key rotation, and orphaned accounts • Strong written communication in English and Spanish • Excellent organizational skills for tracking findings, tickets, and evidence requests across teams • Proactive ability to follow up with teams, gather evidence, identify overdue deadlines, and drive tasks to completion with minimal supervision • Ability to independently identify gaps or deviations and escalate them in a timely manner • ISO 27001 Lead Implementer/Auditor, CompTIA Security+, CISA, or CISM certification in progress or completed viewed favorably • Exposure to NIS2 or other EU cybersecurity regulation • Familiarity with GRC platforms such as CISO Assistant or vulnerability management tooling • Prior experience supporting vendor/third-party security assessments

🏖️ Benefits

• Competitive compensation package • Flexible hours and flextime • Health insurance • Training • Personalized internal training • Annual budget for external learning opportunities • Option to work fully remote or from the Barcelona office • Free Friday afternoons with a 7-hour workday • 35-hour workweek in July and August • Top-tier private health insurance including dental and psychological services • 25 days of vacation • Birthday off • Flexible vacation options with no blackout days • Free coffee, fresh fruit, snacks, game room, and rooftop terrace at the Barcelona office • Ticket restaurant vouchers • Nursery vouchers • Full-time permanent contract

Apply Now

Similar Jobs

🕒 July 29

EverAI

51 - 200

🤖 Artificial Intelligence

🎮 Gaming

Security Engineer managing application security for fast-growing AI companionship platform. Working across application security, risk & compliance, and security awareness.

🕒 June 16

Prima

1001 - 5000

💼 Consulting

📦 Logistics

🛡️ Insurance

Cyber Security Governance Specialist strengthening governance, resilience, and AI security for Prima’s data-driven motor insurance business. Supporting audits, risk assessments, continuity planning, and regulatory compliance.

Cyber Security

RTOS