Senior Grc Consultant
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We’re hiring a Senior GRC ConsultantLocation: Madrid / Castilla y León - HybridSalary: **k€We are looking to hire a Senior GRC Consultant with a strong track record in projects involving the implementation, adaptation, and auditing of information security management frameworks, business continuity, and regulatory compliance.The selected candidate will lead client projects from start to finish, acting as the clients technical lead, with a direct reporting line to the GRC Manager.What youll do- Lead the implementation and maintenance of ISMS projects in accordance with ISO/IEC **:** and ISO/IEC *** controls.Similarly, lead projects related to ISO *** and/or GDPR.- Manage adaptation processes to the National Security Framework (Royal Decree **** and CCN-STIC 800, specifically sections 803, 804, 808, and 817), including the statement of applicability, risk analysis, and adaptation plan.- Design and implement Business Continuity Management Systems (BCMS) according to ISO **, including BIA, continuity risk analysis, continuity and recovery plans, and testing.- Conduct risk analyses and assessments using recognized methodologies for ENS and ISO ***.- Assist clients in internal audit and certification processes with accredited bodies, as well as in compliance audits with ENS, ISO **, etc.- Support projects adapting to NIS2, DORA, CIS, ENS, and ISO/IEC *** according to client needs.- Develop high-quality policies, procedures, regulations, and technical reports, adhering to rigorous regulatory criteria.Attend coordination meetings with the clients CIO/CISO.- Serve as the primary point of contact for CISOs, compliance officers, and client management.Education Requirements- Bachelors degree in Computer Engineering, Telecommunications, Mathematics, or equivalent.- ISACA CISA and/or ISO *** Lead Auditor certifications.Experience requirements- Minimum of 3 years of demonstrable experience in cybersecurity consulting within GRC.- Participation, as a lead consultant, in several ISO *** and ENS implementation projects.- Practical experience in projects adapting to the National Security Scheme (ENS) (medium and high categories) and ISO **.Technical and regulatory knowledge requirements- Solid command of ISO/IEC ***:, ISO/IEC **:**, and ISO/IEC **.- In-depth knowledge of the National Security Scheme and the CCN-STIC 800 series of guidelines.- Knowledge of NIS2, DORA, GDPR/LOPDGDD, ISO ***, and the European cybersecurity regulatory ecosystem.- Familiarity with ISO ** and best practices in Business Continuity.Other- Native or bilingual Spanish speaker.- Minimum B2 level English (fluent technical reading and working in meetings).- Availability for occasional travel to clients within Spain.The following will be considered an asset:- Professional certifications: CISM, CRISC, CISSP, Lead Auditor / Lead Implementer ISO **, ISO **, etc.- Masters degree in Information Security, ICT Auditing, or equivalent.- Experience with ISO/IEC **, EU AI Act, and/or Cyber Resilience Regulation (CRA).- Previous experience in consulting for public administrations as well as for technology providers to public administrations.- Experience with GRC tools.Competencies and soft skills- Ability to lead projects and multidisciplinary teams.- Excellent oral and written communication skills, with the ability to write high-quality technical documents.- Customer-focused and detail-oriented.- Autonomy, proactivity, and the ability to organize ones own work.- Analytical thinking and sound normative judgment.What we offer- Join a cybersecurity consulting firm in its established and growing GRC unit.- High-value projects with leading clients in regulated sectors.- Hybrid work model (office in Madrid).- **k€ compensation commensurate with experience, with performance-based bonuses.- Career development plan and ongoing training, including professional certifications.- Top-tier technical team and participation in forumsHiring processFully online:A filter from Hack In Hire.An interview with clients HR.A technical interview with the team.Interested?Apply via LinkedIn or submit your CV via hackinhire.Com
Requirements
Bachelors degree in Computer Engineering, Telecommunications, Mathematics, or equivalent.
- ISACA CISA and/or ISO ***** Lead Auditor certifications.Experience requirements
- Minimum of 3 years of demonstrable experience in cybersecurity consulting within GRC.
- Participation, as a lead consultant, in several ISO ***** and ENS implementation projects.
- Practical experience in projects adapting to the National Security Scheme (ENS) (medium and high categories) and ISO *****.Technical and regulatory knowledge requirements
- Solid command of ISO/IEC **:, ISO/IEC ***:, and ISO/IEC **.
- In-depth knowledge of the National Security Scheme and the CCN-STIC 800 series of guidelines.
- Knowledge of NIS2, DORA, GDPR/LOPDGDD, ISO *****, and the European cybersecurity regulatory ecosystem.
- Familiarity with ISO ***** and best practices in Business Continuity.Other
- Native or bilingual Spanish speaker.
- Minimum B2 level English (fluent technical reading and working in meetings).
- Availability for occasional travel to clients within Spain.The following will be considered an asset:
- Professional certifications: CISM, CRISC, CISSP, Lead Auditor / Lead Implementer ISO **, ISO **, etc.
- Masters degree in Information Security, ICT Auditing, or equivalent.
- Experience with ISO/IEC *****, EU AI Act, and/or Cyber Resilience Regulation (CRA).
- Previous experience in consulting for public administrations as well as for technology providers to public administrations.
- Experience with GRC tools.Competencies and soft skills
- Ability to lead projects and multidisciplinary teams.
- Excellent oral and written communication skills, with the ability to write high-quality technical documents.
- Customer-focused and detail-oriented.
- Autonomy, proactivity, and the ability to organize ones own work.
- Analytical thinking and sound normative judgment.What we offer
Benefits & conditions
Join a cybersecurity consulting firm in its established and growing GRC unit.
- High-value projects with leading clients in regulated sectors.
- Hybrid work model (office in Madrid).
- *****k€ compensation commensurate with experience, with performance-based bonuses.
- Career development plan and ongoing training, including professional certifications.
- Top-tier technical team and participation in forumsHiring processFully online:A filter from Hack In Hire.An interview with clients HR.A technical interview with the team.Interested? Apply via LinkedIn or submit your CV via hackinhire.Com
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What’s the Difference between a Junior, Mid, and Senior Developer?
The 12 Best Jobs for Software Engineers
Top-Paying Tech Jobs (with Salaries)
9 Ways to Make Money Hacking