> Markdown version of [/jobs/ext/1939123-cybersecurity-grc-analyst](https://www.wearedevelopers.com/jobs/ext/1939123-cybersecurity-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Grc Analyst - **Company:** Satlantis - **Location:** Álava, Spain - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Audit Trail, Cyber Security, Cloud Services, Software Vulnerability Management, Information Security Management System, Data Classification, Microsoft InTune, Information Technology, Performance Monitor - **Published:** August 5, 2026 - **Apply:** https://www.buscojobs.com.es/cybersecurity-grc-analyst-en-alava-ID-365494203 ## About the Role experience in Cybersecurity, Information Technology, Telecommunications, Computer Science, Risk Management, Law with a technology specialization, or a related field, Experience and knowledge:Basic practical knowledge of security and compliance frameworks such as ENS, ISO *****, NIS2, and GDPR.Experience maintaining structured documentation, control evidence, risk registers, or audit records, together with a general technical understanding of IT infrastructure, networks, identity, endpoints, cloud services, and cybersecurity controls.A working understanding of SOC operations, incident management, vulnerability management, and remediation processes will help you monitor performance, track actions, and challenge deviations when needed.Basic understanding of technology risk assessment and supplier and supply-chain security assessment processes will help you contribute to managing cybersecurity risks across the organization.Autonomy and Teamwork: Ability to work independently and in a team.Communication skills: Native or equivalent Spanish and technical English.Preferred skills:Experience participating in ENS or NIS2 implementation, maintenance, or audit activities.Familiarity with Microsoft 365 security and compliance technologies, including Entra ID, Intune, Defender, or Purview, and AWS.Ready to strengthen cybersecurity in the space industry? If you're excited about turning cybersecurity requirements into practical improvements and contributing to the security and resilience of space technologies, this is your chance. ## Description At SATLANTIS, we design advanced space technologies to tackle global challenges from above.Our satellites are conceived, designed, and built to deliver reliable, high-performance Earth observation data in demanding orbital environments.As a Cybersecurity GRC Analyst, you will help strengthen the governance, risk management, and compliance foundations that protect our technology, information, and business operations.Working closely with IT, Cybersecurity, business stakeholders, suppliers, and external partners, you will contribute to ensuring that security requirements are effectively implemented, monitored, evidenced, and continuously improved.What's in it for youReal impact on cybersecurity governance: Your work will directly contribute to strengthening the security and resilience of a growing space technology organization.Professional growth in a cutting-edge sector: Develop your expertise in cybersecurity governance, risk management, compliance, and information security within the space industry.Flexible working hours: Because balance and trust are part of how we work.Young, dynamic environment: Join a proactive team where autonomy, innovation, and collaboration drive our daily routine.Private health insurance: Your wellbeing comes first, with comprehensive coverage.Campus perks: Discounts at gym and restaurants on the UPV/EHU campus, plus fresh fruit, great coffee, and a motivating work atmosphere.Your missionYour mission will be to support the effective governance, risk management, and compliance of SATLANTIS' cybersecurity and information security environment.Through structured coordination, monitoring, documentation, and continuous improvement, you will help ensure that security requirements are implemented, risks are tracked, audit commitments are addressed, and cybersecurity performance remains visible to decision-makers.Your main responsibilities will be:Support the maintenance and continuous improvement of ENS High compliance and the ISMS, including the statement of applicability, security policies, standards, procedures, records, and control evidence.Support the oversight of the external SOC service and vulnerability management process, monitoring service performance, escalations, asset coverage, risk classification, remediation deadlines, and outstanding actions.Coordinate internal and external audits, managing audit evidence and maintaining the register of findings, observations, and non-conformities, together with their corresponding corrective action plans and closure status.Coordinate the maintenance and testing of IT continuity and disaster recovery plans with the relevant service and business owners.Support supplier security assessments, contractual security reviews, supplier SLA monitoring, remediation activities, and customer cybersecurity questionnaires and evidence requests.Conduct and maintain technology risk assessments, propose treatment actions, and monitor their implementation, while supporting the application and monitoring of the information classification scheme.Support incident notification and regulatory deadline tracking related to ENS, NIS2, and GDPR.Prepare periodic cybersecurity governance, risk, and compliance dashboards and reports for the Head of IT & Cybersecurity.What will set you up for successTechnical foundation: You hold a Higher Vocational Qualification, University Degree, or equivalent professional experience in Cybersecurity, Information Technology, Telecommunications, Computer Science, Risk Management, Law with a technology specialization, or a related field.Experience and knowledge:Basic practical knowledge of security and compliance frameworks such as ENS, ISO *****, NIS2, and GDPR.Experience maintaining structured documentation, control evidence, risk registers, or audit records, together with a general technical understanding of IT infrastructure, networks, identity, endpoints, cloud services, and cybersecurity controls.A working understanding of SOC operations, incident management, vulnerability management, and remediation processes will help you monitor performance, track actions, and challenge deviations when needed.Basic understanding of technology risk assessment and supplier and supply-chain security assessment processes will help you contribute to managing cybersecurity risks across the organization.Autonomy and Teamwork: Ability to work independently and in a team.Communication skills: Native or equivalent Spanish and technical English.Preferred skills:Experience participating in ENS or NIS2 implementation, maintenance, or audit activities.Familiarity with Microsoft 365 security and compliance technologies, including Entra ID, Intune, Defender, or Purview, and AWS.Ready to strengthen cybersecurity in the space industry?If you're excited about turning cybersecurity requirements into practical improvements and contributing to the security and resilience of space technologies, this is your chance.Apply now and join our mission at SATLANTIS.#J-*****-Ljbffr ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)