IT Compliance and GRC Manager, hibrido

Michael Page
Barcelona, Spain
20 days ago
Apply on www.empleate.gob.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Data Integrity Identity and Access Management Information Technology Audit SAP (Applications) SAP GRC SAP Security System Testing Enterprise Software Applications SAPBasis Information Technology GXP User Administration

Job description

IT Compliance and GRC Manager Lead and enhance the organizations access governance framework across enterprise applications, identity platforms, and SAP environments. Ensure effective management of the full access lifecycle, including requests, approvals, provisioning, reviews, privileged access, and segregation of duties controls. Oversee security and authorization governance across complex SAP landscapes, including access risk management and compliance processes. Evaluate access-related risks and support remediation activities to ensure compliance with internal controls, security standards, and audit requirements. Partner with stakeholders across IT, Security, Risk, Compliance, Audit, and business functions to strengthen governance practices and improve control effectiveness. Support internal and external audits through clear documentation, reporting, and control evidence. Drive continuous improvement and automation initiatives to increase efficiency, reduce access risks, and enhance

Requirements

transparency through meaningful governance metrics and reporting. International end client company Perm position, long time project Masters degree or equivalent qualification in Information Technology, Computer Science, Business Administration, or a related field. Proven experience in Access Governance, Identity Access Management (IAM), IT Risk Compliance, IT Audit, Internal Controls, SAP Security, SAP Authorizations, or SAP GRC within complex enterprise environments. Professional certifications such as CISA, CISM, CISSP, CRISC, SAP Security/GRC, or Identity Access Management certifications. Experience within highly regulated industries, including healthcare, life sciences, pharmaceuticals, manufacturing, or other environments with strong compliance requirements. Familiarity with regulatory and compliance frameworks such as GxP, GDPR, data integrity standards, system validation practices, and IT control frameworks. Strong understanding of user access management, role-based access controls

Benefits & conditions

(RBAC), segregation of duties (SoD), privileged access management, access reviews, and identity lifecycle processes. Solid expertise in SAP Security and Authorizations, SAP GRC Access Control, and large-scale SAP landscapes. Good knowledge of information security principles, IT General Controls (ITGCs), risk management, compliance frameworks, and audit requirements. Experience working in regulated environments and supporting internal and external audit activities. Ability to assess access-related risks, translate regulatory and governance requirements into practical controls, and drive remediation initiatives. Strong stakeholder management, communication, and influencing skills, with the ability to engage effectively across technical, business, and compliance functions. Demonstrated leadership capabilities, analytical thinking, sound judgment, and a proactive, ownership-driven mindset. International end client company based in Barcelona. Global role within an international environment, working alongside highly skilled professionals. Permanent position with direct employment by the hiring organization. Competitive compensation package aligned with the experience and expertise you bring. Hybrid working model (3 days per week in the office). Comprehensive benefits package. Strong opportunities for long-term career growth and professional development. Location: Barcelona SAP, SAP GRC, IAM

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.empleate.gob.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:13 min

Core components of the internal Optimize ecosystem

Dominik Schneider Dominik Schneider · World Congress 2025

2:08 min

Managing complex structures and corporate guidelines

Alexandra Petri · World Congress 2023

2:03 min

Platform compliance and security certifications for sensitive data

Chad Carlson · World Congress 2021

1:44 min

Background and career journey in regulated software systems

Martin Hynie · Coffee With Developers

Videos

See all

Related articles

See all