Description
Job Summary:
We are seeking a GRC professional to participate in strategic projects for assessing, defining, and improving cybersecurity compliance and risk management.
Key Highlights:
1. Participation in strategic projects for risk assessment and management
2. Continuous training in cybersecurity, GRC, and compliance frameworks
3. Participation in high-impact international projects
At Excelia, a multinational consulting, technology, and professional services firm with over 25 years of experience and presence in more than 50 countries across Europe, Latin America, and the United States through our 9 owned offices, we continue to grow and seek to incorporate talent into our Cybersecurity and Risk team.
We are looking for a generic GRC profile with experience in technological risks and information security reference frameworks, who wishes to participate in strategic projects for assessing, defining, and improving compliance and risk management.
**Responsibilities**
---------------------
* Assessment and management of technological risks in corporate environments.
* Definition and implementation of security controls aligned with international standards.
* Participation in regulatory compliance and security audit projects.
* Application of reference frameworks such as ISO/IEC 27001, NIST, and cybersecurity best practices.
* Gap analysis and definition of remediation plans.
* Advisory support to technical and business teams on security and compliance matters.
* Support in defining and improving information security policies and procedures.
**Requirements**
--------------
* Technical education (Computer Engineering, Telecommunications, or similar).
* Minimum 1 year of experience in GRC, technological risk, or information security roles.
* Knowledge of frameworks and standards: ISO 27001, NIST, or equivalents.
* Ability to analyze risks and define security controls.
* Profile with a global view of security (not necessarily deep technical implementation expertise).
* Prior experience in security auditing or consulting is desirable.
**What We Offer?**
-------------------
* Stable employment with an international company.
* Salary band commensurate with experience.
* Flexible compensation.
* Continuous training in cybersecurity, GRC, and compliance frameworks.
* Hybrid work model and flexible working hours.
* Participation in high-impact international projects.
**Location**
-------------
Bilbao (hybrid model).
**Are You Interested?**
-----------------
If you are motivated to work in technological risk management, compliance, and international security frameworks, we would love to meet you!