Consultor/a GRC
Core
Cybersecurity consultant specializing in Governance, Risk, and Compliance (GRC) to support the Information Security Unit in Madrid.
Role type
GRC Cybersecurity Consultant
Builds
Security management frameworks and compliance documentation for clients
Domain
Cybersecurity / Information Security Management
Deliverable
client delivery
Required skills
Risk analysis, Asset inventory management, Regulatory compliance knowledge (ISO 27001, ISO 22301, ENS), Gap analysis, Third-party security evaluation, KPI definition, Policy and procedure management
Preferred skills
Experience in Security Risk Assessments (SRA), Knowledge of ENS framework
Technologies
GRC tools
Responsibilities
Conduct security risk assessments aligned with ISO 27001, Manage and update asset inventories, Support implementation and maintenance of ISMS, Evaluate third-party security, Prepare security reports and support governance committees
Seniority
Junior to Senior