> Markdown version of [/jobs/ext/2799340-it-security-compliance-manager](https://www.wearedevelopers.com/jobs/ext/2799340-it-security-compliance-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security & Compliance Manager - **Company:** Sinclair - **Location:** Madrid, Spain (Remote available) - **Salary:** €75,000.0 - €95,000.0 - **Contract:** Permanent contract - **Skills:** Audit Trail, Cyber Security, Information Security Management, Information Technology Audit, SAP (Applications), System Testing, Backup and Restore, IT General Controls (ITGC), GXP - **Published:** September 8, 2026 - **Apply:** https://www.adzuna.es/contact-us.html ## About the Role English to full professional standard, written and spoken; right to work in the Netherlands or Spain. Able to work as the only person in the discipline: sets own priorities and writes own material. Desirable: CISA, CRISC, or ISO/IEC 27001 Lead Auditor. Pharmaceutical, medical device or medical aesthetics experience, including GxP and CSV /computerized system validation. SAP authorisation concept and segregation-of-duties design. UK and EU data protection as it applies to systems and vendors. ## Description Own It! Be Accountable for your decisions, actions and consequences; Be Reliable to your customers and colleagues What You'll Be Doing: Audit response and readiness - primary * Act as the single point of contact for external audit, group internal audit and finance control reviews: scope agreement, evidence, walkthroughs, management responses. * Maintain one register of IT-related findings from every source, each with a named owner and a date. * Report remediation status monthly to the Global IT Director, and at each audit cycle to Finance and to Legal & Compliance. * Assemble the evidence base before it is asked for: application inventory, system owner matrix, access records, change records, backup and restore records. Internal controls, built from audit requirements * Turn each agreed finding into a documented, repeatable control: control objective, control owner, frequency, evidence retained. * Start with what is already known to be required - periodic user access review; segregation of duties in ERP and procure-to-pay; a named System Owner for every application. * Design controls that can be operated at current headcount. Where one cannot be, record the compensating control and the accepted risk rather than writing a control that will fail its next test. * Re-test what has been remediated, and close findings on evidence rather than assertion. Standing compliance duties * Keep the IT policy set current - access, information security and acceptable use, continuity - and aligned to what is actually done. * Review new and renewed software and services before any commitment is made: data location, processing terms, security, GxP impact, exit terms. Conclusion within five working days. * Support Legal & Compliance on UK and EU data protection where systems are involved: hosting location, transfers, processing agreements, retention. * Represent controls in the SAP and workflow programmes - authorisation model, segregation-of-duties rules, approval matrix, audit logging - and sign off before configuration freeze. Your skills and experience Essential: Five or more years in IT audit, IT compliance or IT risk, within or facing a multi-entity international group. Has personally run the company side of an IT audit - scope, evidence, management response, remediation through to closure. Has built and operated IT general controls off the back of findings, not only tested them. Has owned a user access review and segregation-of-duties cycle across an ERP. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [How One Developer Built the Back Office for 10 Million Companies](https://www.wearedevelopers.com/videos/100082-how-one-developer-built-the-back-office-for-10-million-companies) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Spanish Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/353-spanish-business-culture-and-etiquette) - [How to land a developer job in Amsterdam](https://www.wearedevelopers.com/magazine/36-how-to-land-a-developer-job-in-amsterdam) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [How to Find Tech Jobs in Amsterdam](https://www.wearedevelopers.com/magazine/279-how-to-find-tech-jobs-in-amsterdam)