IT Risk & Compliance Specialist
Tasks
- Assess EU AI Act applicability for vendor AI services
- Conduct vendor security due diligence
- Develop and deliver security awareness training
- Draft review approve and publish ISMS policies
- Identify assess and treat security risks
- Lead gap assessments for ISO 27001 and SOC 2
- Maintain information security risk management plan
- Maintain risk register and manage risk acceptance
- Maintain version control and documentation accuracy
- Manage ISMS documentation lifecycle
- Manage audit nonconformity remediation
- Manage vendor rescreening
- Monitor ISMS compliance requirements
- Oversee internal external ISMS audits
- Perform ongoing vendor security monitoring
- Prepare compliance reporting materials
- Produce DDQ analysis reports
- Respond to client due diligence questionnaires
- Support SOC 2 Type II audit cycle
- Support security awareness vendor management and quality monitoring
- Track security metrics and ISMS performance
- Triage compliance service requests
Perks/Benefits
- N/A
Skills/Tech-stack
AI Act | Confluence | Conformity Management | Cybersecurity Framework | Documentation Management | EU AI | EU AI Act | GDPR | GRC | ISMS | ISO 27001 | ISO 27005 | Information Security Governance | Information security | Jira | Jira Service | Jira Service Management | Jira Work Management | MAGERIT | NIST Cybersecurity | NIST Cybersecurity Framework | Policy writing | Python | Risk Assessment | Risk Management | SOC 2 | Security Governance | Security Policy | Security Policy Writing | Service Management | Third Party | Third Party Risk Assessment | Third-Party Risk | Vanta | Vendor Risk | Vendor risk management | Work Management
Education
N/A
Related jobs
-
IT Support / Sysadmin & Cybersecurity Intern EUR 18K-27KAccess Management | Bash | CIS Benchmarks | DNS | Device ManagementFlexible working hours | Mentorship | Remote work opportunityEntry-level InternshipSales Layer Valencia1d ago
-
AWS | Audit | Cloud Security | Compliance | Information securityFlexible working hours | Inclusion and diversity focus | Mentorship and career growth | Work-life balanceSenior-level Full TimeMadrid, Community of Madrid, ESP5d ago
-
AWS | Audit | Cloud Security | Compliance | Continuous ImprovementCareer growth | Flexible working hours | Mentorship | Work-life balanceSenior-level Full TimeMadrid, Community of Madrid, ESP5d ago
-
Consultor GRC Tech EUR 40K-50KAPI Integration | Business Intelligence | Continuous integration | Databases | DatalakesMid-level Full TimeMadrid, ES, 280466d ago
-
Account Management | Active Directory | Ansible | Automation | Automation monitoringCollective transport service | Development prospects | Employee stock options | Flexible working arrangements | Free canteenMid-level Full TimeAlbacete, Spain R6d ago
-
Governance Risk and Compliance (GRC) Specialist EUR 46K-61K800-37 | 800-53 | COBIT | CSF 2.0 | Compliance AutomationSenior-level Full TimeSant Just Desvern, B, ES, 0896012d ago
-
Senior-level Full TimeSant Just Desvern, B, ES, 0896012d ago
-
ArcSight | Connector configuration | Information security | Linux | Logging standardsAutonomous work | Career growth | Health insurance | Hybrid work | Team cultureSenior-level Full TimeMadrid; Barcelona14d ago
-
HQ - GRC Lead EUR 60K-75KAWS | Audit Readiness | Audit management | Cloud Security | Cloud platformSenior-level Full TimeMadrid HQ, ES14d ago
-
Cyber Security Specialist EUR 30K-33KBy Design | Control Systems | IEC 62443 | ISO 27001 | ISO 27002Mid-level Full TimeMadrid, M, ES, 2803319d ago
-
Head of Security Operations & Corporate IT EUR 85K-103KAccess Management | Audit Readiness | Budget Management | CI/CD | Call ManagementIn person meetings quarterly | Remote-first cultureExecutive-level Full TimeMadrid, Spain R21d ago
-
Regional Information Security Officer EUR 65K-65KCOBIT 2019 | Cloud Security | Compliance reporting | Contractual Security Provisions | GovernanceDigital learning | Employee discounts | Employee shares | Flexible working | Health and wellbeing programsSenior-level Full TimeBARCELONA, B, ES, 0800526d ago
-
Access Control | Access Management | Active Directory | Azure Active Directory | Cloud IAMMid-level Full TimeMADRID, M, ES, 2804327d ago
-
AWS | Attack surface | Attack surface management | Azure | Cloud SecurityEmployee discounts | Employee stock program | Flexible working | Healthcare | Hybrid work modelMid-level Full TimeBARCELONA, B, ES, 0800528d ago
-
Especialista en DFIR EUR 35K-40KBash | Digital forensics | EDR | Forensic Investigation | IDS/IPSChildcare | Flexible benefits | Hybrid work | Meal vouchers | Medical insuranceMid-level Full TimeMadrid, MD, Spain30d ago
-
Assurance - Consultor Senior GRC IT EUR 40K-45KArcher | Cibersecurity | Cloud Governance | Coso | Data analyticsCareer development | Collaborative work environment | Continuous trainingSenior-level Full TimeMadrid - Paseo de la Castellana …30d ago
-
GRC Compliance Analyst EUR 40K-55KAccess Management | Audit Coordination | CI/CD | Cloud logs | EncryptionMid-level Full TimeSpain1mo ago
-
Web Application Firewall Specialist (m/f/d) EUR 39K-66KAkamai | Allow List | Application Firewall | Automation | BashCompany bonus scheme | Digital learning programs | Employee discounts | Employee shares program | Flexible workingMid-level Full TimeBARCELONA, B, ES, 080051mo ago
-
Senior Security Assurance Specialist EUR 60K-89KAccess Control | Agile | Audit management | Cloud Security | CryptographySenior-level Full TimeMadrid Office - Spain1mo ago
-
API | Bash | Jira | Kenna | PowershellContinuous training | Flexible working hours | Hybrid work model | Social benefits package | Volunteering programsEntry-level Full TimeMADRID, ES R1mo ago
-
Experto/a en Seguridad IT (GRC & Compliance) EUR 36K-43KCompliance Management | ENS | GRC | ISO 27001 | Information securityContinuous training | Flexible work hours | Full-time employment | Permanent contractSenior-level Full TimeBarcelona, Spain1mo ago
-
Especialista De Red Team Y Ciberinteligencia EUR 25K-30KAfter-action reporting | Artificial Intelligence | Attack Surface Analysis | Attack surface | Cyber ThreatChildcare vouchers | Employee discounts | Flexible working hours | Health insurance | Life insuranceMid-level Full TimeMadrid, MD, ES R1mo ago
-
Cyber Security Engineer SSC EUR 27K-48KAutomation | Business Continuity | Cloud Security | Cyber Security | Disaster RecoveryCareer growth | Comprehensive benefits package | International work environment | Training opportunities | Travel opportunitiesMid-level Full TimeSpain1mo ago