> Markdown version of [/jobs/ext/1602174-grc-analyst](https://www.wearedevelopers.com/jobs/ext/1602174-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst - **Company:** ScaleUp - **Location:** Madrid, Spain (Remote available) - **Contract:** Contract - **Skills:** JIRA, Spreadsheets, Cloud Computing, CompTIA Security+, Cyber Security, Multi-Factor Authentication, Single Sign-On, Backup and Restore - **Published:** July 31, 2026 - **Apply:** https://es.indeed.com/viewjob?jk=587f4c5a7b90a136 ## About the Role * 2-4 years of experience completing vendor security questionnaires, working in GRC/compliance, or in a security-related client-facing role. * Hands-on experience completing SIG, CAIQ, or custom vendor security questionnaires . * Working knowledge of SOC 2 and ISO 27001 . * Understanding of common security concepts, including: + Single Sign-On (SSO) + Multi-Factor Authentication (MFA) + Endpoint Management + Encryption (at rest & in transit) + Cloud infrastructure fundamentals + Backup & Disaster Recovery + Vendor Risk Management * Strong organizational skills with the ability to manage multiple requests simultaneously. * Excellent judgment regarding when to answer independently and when to involve technical SMEs. * Excellent written communication skills. * Professional English (written and spoken). Nice to Have * Experience handling a high volume of vendor security questionnaires. * Experience with: + Conveyor + SafeBase + Vanta + Whistic + Trust Center platforms * Experience maintaining questionnaire knowledge bases. * Experience working alongside Sales or Revenue teams supporting enterprise deals. * Certifications such as: + CompTIA Security+ + ISC2 Certified in Cybersecurity (CC) + Similar cybersecurity certifications ## Description As a Vendor Security Questionnaire Specialist , you'll own the vendor security questionnaire process from end to end across multiple client accounts. You'll work closely with U.S.-based startups, monitoring incoming security requests, coordinating with technical stakeholders, and completing security questionnaires accurately and on time. This role requires a solid understanding of security frameworks, strong organizational skills, and the ability to communicate clearly with both technical and non-technical stakeholders. This is an excellent opportunity for someone with experience in GRC, security compliance, or vendor risk who enjoys supporting multiple clients and playing a key role in helping companies close enterprise deals., * Monitor client Slack channels and respond promptly to incoming security questionnaire requests. * Create and manage tickets in Jira, Linear, or other ticketing systems to track requests through completion. * Complete vendor security questionnaires (SIG, CAIQ, custom questionnaires) through spreadsheets and security platforms such as OneTrust, Whistic, SecurityScorecard, and similar tools. * Develop a deep understanding of each client's security posture, policies, controls, and technical environment. * Maintain and continuously improve client answer libraries and knowledge bases. * Coordinate with security consultants, engineers, and subject matter experts whenever technical clarification is needed. * Escalate recurring gaps or missing controls that impact questionnaire responses. * Ensure all questionnaires are completed accurately and within customer deadlines. ## Related Videos - [Building Security Champions](https://www.wearedevelopers.com/videos/193-building-security-champions) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Launching a marketplace on-time: A lesson in taking shortcuts using spreadsheets!](https://www.wearedevelopers.com/videos/477-launching-a-marketplace-on-time-a-lesson-in-taking-shortcuts-using-spreadsheets) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Spanish Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/353-spanish-business-culture-and-etiquette) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)