Information Security Analyst, Grc & Isms

GMV
Madrid, Spain
4 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Shift work
Languages
English

Tech stack

Cyber Security Working Model 2D Information Security Management System

Job description

If you wanted to be Anonymous, but the pandemic made you realize that wearing a mask is not your cup of tea…Your place is with us!We are expanding our Corporate Cybersecurity Compliance team to help manage risks, ensure regulatory compliance, and strengthen our security framework.We’ll get to the point; we’ll tell you what’s not on the web.If you want to know more about us go to GMV website.WHAT CHALLENGE WILL YOU BE TAKING ON?In collaboration with the team, you will be responsible for maintaining and evolving the corporate Information Security Management System (ISMS).You will also contribute to all the processes required to ensure and enhance information protection, resilience, and compliance with established requirements.Activities related to regulations, standards, and frameworks applicable in the countries where GMV operates (ISO/IEC **, ENS, NIS2, etc.), including both internal and external audits.Defining and monitoring metrics, indicators (KPIs/KRIs), and management dashboards.Analyzing, assessing, and managing internal and third?party risks, while promoting initiatives to prevent and mitigate them.Developing and reviewing security and compliance policies, methodologies, and documentation.Supporting the preparation of security committees, management reviews, and ISMS governance activities.WHAT DO WE NEED IN OUR TEAM?For this position, we are looking for a Compliance Cybersecurity Engineer with experience in Governance, Risk & Compliance (GRC), Information Security Management Systems (ISMS), audit processes, information security controls and risk treatment plans.You should also have knowledge of:Security regulations and standards such as ISO/IEC **, ENS, NIS2, etc.Risk assessment and risk management methodologies.Security requirements for suppliers and third parties.Additionally, the following will be considered a plus:Certifications such as CISM, CRISC, CISSP, CISA, ISO/IEC *** Lead Auditor, or similar.Knowledge of operational resilience and business continuity frameworks.Experience working in regulated environments or critical infrastructure sectors.A high level of English proficiency is required.WHAT DO WE OFFER?Hybrid working model and 4 weeks per year of teleworking outside your usual geographical area.Flexible start and finish times, and intensive working hours Fridays and in summer.Personalized career plan development, training and language learning support.National and international mobility.If you come from another country, we can offer you a relocation package.Competitive compensation with ongoing reviews, flexible compensation and discounts on brands.Wellbeing program: health, dental and accident insurance, free fruit and coffee, physical, mental and financial health training, and much more.In our recruitment processes you will always have telephone and personal contact, face?to?face or online, with our talent acquisition team.In addition, bank transfers and bank cards will never be requested.If you are contacted through any other process, please write to our team at **We promote equal opportunities in recruitment, and we are committed to inclusion and diversity.WHAT ARE YOU WAITING FOR?JOIN USIf you have any questions please do not hesitate to contact Pablo Durán Álvarez, in charge of this vacancy.Pablo Durán Álvarez#J-***-Ljbffr

Requirements

For this position, we are looking for a Compliance Cybersecurity Engineer with experience in Governance, Risk & Compliance (GRC), Information Security Management Systems (ISMS), audit processes, information security controls and risk treatment plans. You should also have knowledge of: Security regulations and standards such as ISO/IEC **, ENS, NIS2, etc. Risk assessment and risk management methodologies. Security requirements for suppliers and third parties. Additionally, the following will be considered a plus: Certifications such as CISM, CRISC, CISSP, CISA, ISO/IEC ** Lead Auditor, or similar. Knowledge of operational resilience and business continuity frameworks. Experience working in regulated environments or critical infrastructure sectors. A high level of English proficiency is required.

Benefits & conditions

Hybrid working model and 4 weeks per year of teleworking outside your usual geographical area. Flexible start and finish times, and intensive working hours Fridays and in summer. Personalized career plan development, training and language learning support. National and international mobility. If you come from another country, we can offer you a relocation package. Competitive compensation with ongoing reviews, flexible compensation and discounts on brands. Wellbeing program: health, dental and accident insurance, free fruit and coffee, physical, mental and financial health training, and much more. In our recruitment processes you will always have telephone and personal contact, face?to?face or online, with our talent acquisition team. In addition, bank transfers and bank cards will never be requested. If you are contacted through any other process, please write to our team at ** We promote equal opportunities in recruitment, and we are committed to inclusion and diversity. WHAT ARE YOU WAITING FOR? JOIN US If you have any questions please do not hesitate to contact Pablo Durán Álvarez, in charge of this vacancy. Pablo Durán Álvarez #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · World Congress 2023

Videos

See all

Related articles

See all