Senior GRC Consultant
3 days ago
Madrid
We’re hiring a Senior GRC Consultant Location: Madrid / Castillo y León - Hybrid Salary: 40-45k€ We are looking to hire a Senior GRC Consultant with a strong track record in projects involving the implementation, adaptation, and auditing of information security management frameworks, business continuity, and regulatory compliance. The selected candidate will lead client projects from start to finish, acting as the client's technical lead, with a direct reporting line to the GRC Manager. What you'll do • Lead the implementation and maintenance of ISMS projects in accordance with ISO/IEC 27001:2022 and ISO/IEC 27002 controls. Similarly, lead projects related to ISO 27701 and/or GDPR., • Manage adaptation processes to the National Security Framework (Royal Decree 311/2022 and CCN-STIC 800, specifically sections 803, 804, 808, and 817), including the statement of applicability, risk analysis, and adaptation plan., • Design and implement Business Continuity Management Systems (BCMS) according to ISO 22301, including BIA, continuity risk analysis, continuity and recovery plans, and testing., • Conduct risk analyses and assessments using recognized methodologies for ENS and ISO 27001., • Assist clients in internal audit and certification processes with accredited bodies, as well as in compliance audits with ENS, ISO 27001, etc., • Support projects adapting to NIS2, DORA, CIS, ENS, and ISO/IEC 27001 according to client needs., • Develop high-quality policies, procedures, regulations, and technical reports, adhering to rigorous regulatory criteria. Attend coordination meetings with the client's CIO/CISO., • Serve as the primary point of contact for CISOs, compliance officers, and client management. Education Requirements • Bachelor's degree in Computer Engineering, Telecommunications, Mathematics, or equivalent., • ISACA CISA and/or ISO 27001 Lead Auditor certifications. Experience requirements • Minimum of 3 years of demonstrable experience in cybersecurity consulting within GRC., • Participation, as a lead consultant, in several ISO 27001 and ENS implementation projects., • Practical experience in projects adapting to the National Security Scheme (ENS) (medium and high categories) and ISO 27001. Technical and regulatory knowledge requirements • Solid command of ISO/IEC 27001:2022, ISO/IEC 27002:2022, and ISO/IEC 27005., • In-depth knowledge of the National Security Scheme and the CCN-STIC 800 series of guidelines., • Knowledge of NIS2, DORA, GDPR/LOPDGDD, ISO 27701, and the European cybersecurity regulatory ecosystem., • Familiarity with ISO 22301 and best practices in Business Continuity. Other • Native or bilingual Spanish speaker., • Minimum B2 level English (fluent technical reading and working in meetings)., • Availability for occasional travel to clients within Spain. The following will be considered an asset: • Professional certifications: CISM, CRISC, CISSP, Lead Auditor / Lead Implementer ISO 22301, ISO 42001, etc., • Master's degree in Information Security, ICT Auditing, or equivalent., • Experience with ISO/IEC 42001, EU AI Act, and/or Cyber Resilience Regulation (CRA)., • Previous experience in consulting for public administrations as well as for technology providers to public administrations., • Experience with GRC tools. Competencies and soft skills • Ability to lead projects and multidisciplinary teams., • Excellent oral and written communication skills, with the ability to write high-quality technical documents., • Customer-focused and detail-oriented., • Autonomy, proactivity, and the ability to organize one's own work., • Analytical thinking and sound normative judgment. What we offer • Join a cybersecurity consulting firm in its established and growing GRC unit., • High-value projects with leading clients in regulated sectors., • Hybrid work model (office in Madrid)., • 40-45k€ compensation commensurate with experience, with performance-based bonuses., • Career development plan and ongoing training, including professional certifications., • Top-tier technical team and participation in forums