> Markdown version of [/jobs/ext/3430296-it-security-compliance-manager-madrid-office](https://www.wearedevelopers.com/jobs/ext/3430296-it-security-compliance-manager-madrid-office). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security & Compliance Manager - Madrid Office - **Company:** Sinclair - **Location:** San Fernando de Henares, Spain (Remote available) - **Contract:** Permanent contract - **Skills:** Audit Trail, Cyber Security, Information Security Management, Information Technology Audit, SAP (Applications), System Testing, Backup and Restore, IT General Controls (ITGC), GXP - **Published:** September 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=9eff5e8ed22f14f9 ## About the Role The ideal candidate will have experience in: * ITGC * SoD * ERP Controls, English to full professional standard, written and spoken; right to work in the Netherlands or Spain. Able to work as the only person in the discipline: sets own priorities and writes own material. Desirable: CISA, CRISC, or ISO/IEC 27001 Lead Auditor. Pharmaceutical, medical device or medical aesthetics experience, including GxP and CSV /computerized system validation. SAP authorisation concept and segregation-of-duties design. UK and EU data protection as it applies to systems and vendors. ## Description * Act as the single point of contact for external audit, group internal audit and finance control reviews: scope agreement, evidence, walkthroughs, management responses. * Maintain one register of IT-related findings from every source, each with a named owner and a date. * Report remediation status monthly to the Global IT Director, and at each audit cycle to Finance and to Legal & Compliance. * Assemble the evidence base before it is asked for: application inventory, system owner matrix, access records, change records, backup and restore records. Internal controls, built from audit requirements * Turn each agreed finding into a documented, repeatable control: control objective, control owner, frequency, evidence retained. * Start with what is already known to be required - periodic user access review; segregation of duties in ERP and procure-to-pay; a named System Owner for every application. * Design controls that can be operated at current headcount. Where one cannot be, record the compensating control and the accepted risk rather than writing a control that will fail its next test. * Re-test what has been remediated, and close findings on evidence rather than assertion. Standing compliance duties * Keep the IT policy set current - access, information security and acceptable use, continuity - and aligned to what is actually done. * Review new and renewed software and services before any commitment is made: data location, processing terms, security, GxP impact, exit terms. Conclusion within five working days. * Support Legal & Compliance on UK and EU data protection where systems are involved: hosting location, transfers, processing agreements, retention. * Represent controls in the SAP and workflow programmes - authorisation model, segregation-of-duties rules, approval matrix, audit logging - and sign off before configuration freeze. Your skills and experience Essential: Five or more years in IT audit, IT compliance or IT risk, within or facing a multi-entity international group. Has personally run the company side of an IT audit - scope, evidence, management response, remediation through to closure. Has built and operated IT general controls off the back of findings, not only tested them. Has owned a user access review and segregation-of-duties cycle across an ERP.