GRC Manager

Adevinta
Spain
4 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Artificial Intelligence Software as a Service Cloud Engineering Phishing Information Security Management System RSA Archer Platform

Job description

You will own the Governance, Risk & Compliance function across Adevinta Information Services and support our marketplaces in maintaining a strong security posture., * Own the Information Security Management System (ISMS)

  • Lead ISO 27001, ENS and other security certifications and audits
  • Coordinate cybersecurity assessments from internal stakeholders, EQT and external auditors
  • Drive Third-Party Risk Management across suppliers and strategic partners
  • Define and maintain security policies, standards and governance processes
  • Lead security awareness and phishing programmes across the company
  • Track security risks and remediation plans with business owners
  • Build executive dashboards and security KPIs for senior leadership
  • Coordinate Business Continuity and security governance activities
  • Partner with Legal, Privacy, Procurement, Engineering and Product teams to embed security into business processes
  • Help scale governance through automation and AI where possible

Requirements

  • Experience leading GRC or Information Security Governance in a technology company
  • Strong understanding of ISO 27001, ENS, NIST or similar frameworks
  • Experience managing external audits
  • Experience with Vendor Risk Management
  • Excellent communication skills with technical and non-technical stakeholders
  • Pragmatic mindset focused on reducing business risk
  • Ability to work autonomously and drive initiatives end-to-end, * Experience in SaaS, cloud-native or digital marketplace environments
  • Experience with GRC platforms
  • Security certifications (CISM, CRISC, ISO Lead Auditor…)

About the company

At Adevinta Information Services, we build and operate some of Spain’s largest digital marketplaces, including InfoJobs, Milanuncios, Coches.net and Motos.net.

We’re building a modern, AI-first cybersecurity organisation from the ground up following our separation from the global organisation. This is a unique opportunity to shape governance, compliance and cyber risk for a fast-moving technology company.

We’re looking for a proactive and pragmatic GRC Manager who enjoys working close to the business and turning governance into an enabler rather than a blocker.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jobleads.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

1:23 min

Closing thoughts and educational resources for edge network engineering

Austin Gil · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:06 min

Developer experience and project variety at scale

Alexandra Petri · WWC 2023

1:29 min

Recommended community resources for cloud engineers

Piet Van Dongen · LIVE

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · WWC Europe 2026

Videos

See all

Related articles

See all