Description
Job Summary:
We are seeking a Technical Account Manager specialized in GRC to serve as the technical-strategic point of contact for clients, ensuring adoption of cybersecurity programs.
Key Highlights:
1. Key role in translating regulatory and risk requirements into actionable plans.
2. You will work in complex environments with multiple stakeholders.
3. Participation in strategic cybersecurity and resilience programs.
DESCRIPTION
We are looking for a **Technical Account Manager with strong expertise in Governance, Risk, and Compliance (GRC)** to act as the **technical-strategic client-facing advisor**, ensuring proper adoption of cybersecurity programs, regulatory frameworks, and risk management capabilities.
This role combines **technical vision, regulatory understanding, and influence capability**, playing a critical part in translating regulatory and risk requirements into **actionable security plans**, guiding organizations through their cybersecurity maturity journey.
You will operate in complex environments involving multiple stakeholders (CISO, IT, Legal, Audit, Business, etc.), driving initiatives that directly impact organizational resilience.
### **Technical and Strategic Responsibilities**
* Serve as the **trusted technical point of contact** for clients on GRC matters.
* Design and support the **implementation of security governance programs**, control frameworks, and operational models.
* Lead maturity assessments, gap analyses, and remediation plans.
* Translate regulatory requirements into **technical and organizational roadmaps**.
* Oversee execution of projects related to:
* Cyber risk management
* Regulatory compliance
* Third-party risk
* Business continuity and resilience
* Organizational security and policies
* Define metrics and executive reporting models.
* Facilitate risk workshops, steering committee sessions, and C-level presentations.
* Ensure effective adoption of security controls and tracking of action plans.
* Coordinate technical teams (architecture, SOC, pentesting, cloud security, etc.) to ensure alignment with GRC objectives.
### **Requirements:**
* Practical experience with frameworks such as:
* ISO 27001 / ISO 27002
* NIST CSF / NIST RMF
* CIS Controls
* COBIT
* FAIR or quantitative risk methodologies
* Experience in regulatory environments such as:
* NIS / NIS2
* DORA
* GDPR
* ENS (highly valued in Spain)
* Sector-specific regulations (financial, energy, healthcare, etc.)
### **Functional and Technical Stack**
* GRC tools (ServiceNow GRC, RSA Archer, OneTrust, MetricStream, etc.).
* Risk registers, control libraries, control testing workflows.
* Integration of security metrics (vulnerabilities, incidents, posture) into risk reporting.
* Practical knowledge of cloud architectures, IAM, SOC operations, and defensive security to contextualize risk.
* Ability to interpret pentesting, red teaming, or technical audit results and translate them into business impact.
### **Ideal Profile**
* Hybrid professional combining **technical + consulting + strategic** skills.
* Strong communication ability with executive stakeholders.
* Value-driven mindset focused on continuous improvement of maturity.
* Experience managing complex accounts or multi-project programs.
* Risk-based prioritization capability.
* Autonomy and ownership over client success.
### **What We Offer**
* Participation in strategic cybersecurity and resilience programs.
* Direct and ongoing engagement with CISOs, Risk Committees, and executive stakeholders.
* A high-level technical environment with continuous learning opportunities.