Description
Job Summary:
We are seeking a professional with experience in governance, risk, and security compliance to ensure adherence to regulations such as GDPR, ENS, and ISO27001.
Key Highlights:
1. Experience in ensuring regulatory compliance (GDPR, ENS, NIS2)
2. Certifications such as ISO27001 Lead Auditor or equivalent
3. Proficiency in Catalan and Spanish, with English at B2 level
MANDATORY REQUIREMENTS:
Applicants must demonstrate experience/knowledge in at least 4 of the following areas:
* Organization and assurance of compliance with applicable regulations (GDPR, ENS, NIS2, ISO, CCN guidelines, etc.).
* Design, monitoring, and implementation of NIS2, ENS, ISO27001, GDPR, or other security compliance alignment plans.
* Internal and external audits for security compliance under ENS, ISO27001, NIS2, GDPR, or other security compliance standards.
* Identification of operational, technological, and legal cybersecurity risks.
* Definition of controls, tests, and evidence.
* Proposal and monitoring of mitigation plans.
* Collaboration in incident response.
Certification in ISO27001 Lead Auditor, ISO22301 Lead Auditor, or equivalent.
Spoken and written Catalan (bilingual with Spanish).
English language level: minimum B2.
Work format: Hybrid, with 60% on-site presence in the Barcelona metropolitan area.
DESIRABLE REQUIREMENTS:
Knowledge/experience in business continuity plans and disaster recovery plans (DRPs).
Knowledge/experience in TPRM (Third-Party Risk Management).
English language certification: B2/C1.
REQUIRED QUALIFICATIONS:
University degree in computer science and telecommunications, law, administration and management, or related fields.
YEARS OF EXPERIENCE IN THE REQUIRED PROFILE:
At least 4 years of documented experience in the field of technological systems, including at least 3 years specifically in governance, risk, and security compliance.