This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Security Governance Specialist is a critical member of the Information Security team responsible for developing and maintaining the governance framework, policies, procedures, and standards that guide the organization's information security practices. This role plays a pivotal role in ensuring that security efforts align with business objectives and comply with relevant regulations and industry standards.
Job Responsibility:
Develop and maintain information security policies, procedures, and standards in alignment with industry best practices, regulatory requirements, and organizational goals
Collaborate with stakeholders across the organization to ensure policies meet business needs while maintaining security standards
Establish and manage the security governance framework, ensuring consistency and accountability in security practices
Define and communicate governance-related roles and responsibilities within the organization
Assist in identifying and understanding regulatory requirements and standards relevant to the organization (e.g., SOC 2, ISO 27001)
Ensure that security practices and policies align with compliance requirements and facilitate compliance assessments and audits
Contribute to the development of security awareness programs and training materials
Collaborate with the Security Awareness and Training Specialist to educate employees about security policies and best practices
Maintain a repository of security policies, procedures, and standards
Prepare and distribute reports on compliance status, governance efforts, and security metrics to management
Integrate risk management principles across the business
Ensure that security governance efforts address identified risks appropriately
Stay informed about emerging security threats, regulations, and best practices
Propose and implement improvements to the security governance framework based on industry trends and organizational needs
Integrate with Tech and Product teams to identify and assess new development initiatives or projects
Bridge communication between the security and engineering teams ensuring needs and expectations are understood and managed
Requirements:
ISO 27001 Lead Auditor or Implementer certification is highly desirable (but not essential)
Experience leading or taking part in internal and or external audits
5+ years of experience in information security governance
Knowledge of relevant security standards and frameworks (e.g., ISO 27001, NIST, SOC 2)
Experience of continuous compliance tooling (eg Vanta or Drata)
Strong understanding of regulatory requirements, such as GDPR
Excellent communication and collaboration skills, with the ability to work across various departments
Strong analytical and problem-solving skills
Detail-oriented with a commitment to maintaining accuracy in documentation
Ability to adapt to a dynamic and fast-paced environment
Self-starter and free thinker
What we offer:
True flexibility and work-life balance
Remote or hybrid work model with our hub in Barcelona
Flexible working hours
Summer intensive schedule during July and August (work 7 hours, finish earlier)
23 paid holidays, with exchangeable local bank holidays
Additional paid holiday on your birthday or work anniversary (you choose what you want to celebrate)
Private healthcare plan with Adeslas for you and subsidized for your family (medical and dental)
Access to hundreds of gyms for a symbolic fee in partnership for you and your family
Access to iFeel, a technological platform for mental wellness offering online psychological support and counseling