> Markdown version of [/jobs/ext/1368615-information-security-grc-specialist](https://www.wearedevelopers.com/jobs/ext/1368615-information-security-grc-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security GRC Specialist - **Company:** Búsqueda Avanzada - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Agile Methodology, Amazon Web Services, Data Analysis, Command-Line Interface, Cloud Computing, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, JSON, YAML - **Published:** July 21, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role Requirements:Minimum of 5 years in Information Security GRC roles.At least 3 years leading or coordinating internal compliance assessments, audits, or strategic maturity evaluations.Strong knowledge of information security frameworks (ISO/IEC 27000 series, COBIT, NIST SP 800-xx, NIST CSF, CIS).Experience with regulatory and cybersecurity requirements applicable to financial or fintech organizations.Proficiency in scripting, JSON/YAML configurations, command-line tools, and basic automation.Ability to analyze data from logs to identify trends and derive actionable insights.Certified Information Systems Auditor (CISA) or equivalent credentials.Knowledge of AWS Cloud Infrastructure or AWS Certified Cloud Practitioner.Strong communication, collaboration, and stakeholder management skills.Detail-oriented with a proactive and continuous learning mindset.Nice-to-have: ISO 27k Lead Auditor, CISSP, PMP certifications, cloud security best practices, Agile/PMI methodologies, and familiarity ## Description Inscribirse en esta oferta This position is posted by Jobgether on behalf of a partner company. We are currently looking for an Information Security GRC Specialist in Spain.This role provides a pivotal opportunity to shape and maintain an organization's information security governance, risk, and compliance (GRC) program. You will oversee security policies, technical standards, and procedures while coordinating internal and external security assessments. The position demands both strategic oversight and hands-on engagement with cross-functional teams, ensuring alignment with regulatory and industry standards. You will identify, assess, and mitigate security risks while driving continuous improvement in compliance processes. Collaboration with technical, regulatory, and business teams is key, and the role emphasizes proactive, high-quality, and automated approaches to GRC. Ideal candidates are analytical, detail-oriented, and adept at translating technical findings into actionable business insights.Accountabilities: + Maintain, implement, and continuously improve the Information Security GRC program. + Coordinate internal and external audits, compliance assessments, and maturity evaluations. + Ensure adherence to regulatory, contractual, and industry information security standards. + Collaborate with cross-functional teams to embed security controls into technical and business processes. + Conduct risk assessments, monitor control effectiveness, and recommend remediation strategies. + Support adoption and consistent application of security policies, procedures, and technical standards. + Leverage automation and Agile approaches to shift from manual compliance to integrated, continuous practices. + Provide reporting, metrics, and insights to stakeholders and senior management. ## Related Videos - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Data Science in Retail](https://www.wearedevelopers.com/videos/586-data-science-in-retail) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Introducing JSON Structure](https://www.wearedevelopers.com/videos/100219-introducing-json-structure) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)