Logo for Jobandtalent

HQ - GRC Senior Analyst

Role overview

Qualifications

  • 8+ years of experience in GRC, Risk, Compliance, or IT Audit roles
  • 5+ years of strong hands-on experience with ISO 27001
  • 3+ years of practical experience with GDPR data mapping
  • 5+ years of experience from a product tech company with global client reach

Responsibilities

  • Own and lead the company’s GRC implementation across ISO 27001 and GDPR
  • Build and manage the Information Security Management System (ISMS) aligned with ISO 27001
  • Ensure GDPR compliance across all data processing activities
  • Act as the primary point of contact for auditors and prepare the company for ISO audits

Key facts

  • Remote from: Spain
  • Full time
  • Senior (5-10 years)
  • English

Other skills

  • Communication

About the company

Jobandtalent logo

Jobandtalent

Human Resources Services

Jobandtalent is the world-leading temporary job platform that connects great people with a steady stream of work. We are reshaping temporary work and creating the conditions for people to truly thrive. We harness the power of technology and data to provide our people back-to-back opportunities, in order to provide the stability and perks associated with long-term employment. Jobandtalent was founded in 2009 in Madrid with the goal of fundamentally tearing down the barriers of job searching and hiring, and is one of the most successful and fastest growing companies in the industry today. Having placed simplicity and fairness at the core of our platform, we have matched 2,000 international clients with over 200,000 people in 2021. Jobandtalent is currently valued at $2.4 billion and is backed by leading investors including SoftBank, Kinnevik, Atomico and BlackRock. For more information, visit jobandtalent.com. Headquartered in Madrid, but home to the world, the remote-first company is operating in 9+ markets across Europe and the Americas and has ambitious plans for further expansion.

Company details

Company typeLarge
IndustryHuman Resources Services
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

We are looking for a GRC Senior Analyst to own and scale our Governance, Risk, and Compliance function within a fast-growing product company. This is a key role responsible for ensuring compliance with SOX, ISO 27001, and GDPR, while enabling the business to move fast in a secure and controlled way.

You will act as the main driver of our compliance strategy, working cross-functionally with Engineering, Security, Legal, Finance, and Product teams.


What you will do
  • Own and lead the company’s GRC implementation across ISO 27001 and GDPR.
  • Build and manage the Information Security Management System (ISMS) aligned with ISO 27001.
  • Ensure GDPR compliance across all data processing activities, including data mapping, data leaks, and encryptions.
  • Act as the primary point of contact for auditors and prepare the company for ISO audits.
  • Identify compliance gaps and drive remediation plans with technical and non-technical teams.
  • Develop governance policies, procedures, and risk management frameworks.
  • Partner closely with Engineering and Security teams to embed controls into systems and SDLC processes.
  • Monitor regulatory and compliance changes and translate them into actionable requirements.

  • Mandatory Requirements
  • 8+ years of experience in GRC, Risk, Compliance, or IT Audit roles
  • 5+ years of strong hands-on experience with ISO 27001 and experience managing or supporting ISMS implementation.
  • 3+ years of practical experience with GDPR data mapping, reviewing systems from the tech side.
  • 5+ years of experience from a product tech company with global client reach in the US & EU (companies above 100 people).
  • Experience working with internal and external auditors
  • Very strong stakeholder management and communication skills across technical and non-technical teams.
  • Fluent English

  • Nice to have
  • Familiarity with cloud environments (AWS, GCP, Azure).
  • Security certifications (CISA, CISM, ISO 27001 Lead Implementer/Auditor). 
  • Other security experience.
  • #LI-OK1

    Apply once. Then go straight to the hiring manager.

    After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

    MR

    Marcus Rivera

    Chief Revenue Officer

    m.rivera@company.com
    linkedin.com/in/marcusrivera
    Unlocked after you apply
    Β·

    Related jobs

    Other jobs at Jobandtalent

    Premium

    Reach out to the hiring manager directly.

    Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

    • Full match report with fit score and gaps
    • Career diagnostics on how recruiters read you
    • Curated company matches and warm intros
    • 48h early access to new roles

    Cancel anytime.