Information Security Grc Analyst

OneTrust

Madrid, Spain
Not specified; annual performance bonus opportunit...
On-site (3 days a week)
2-5 years information security experience
Customer security questionnaire completion
Soc 2 iso 27001 nist framework knowledge
OneTrust is seeking an Information Security GRC Analyst to join their Madrid office, focusing on governance, risk, and compliance activities related to customer security assurance. The ideal candidate should have experience in information security, customer security questionnaires, and a strong understanding of security frameworks and compliance

Job Summary

  • OneTrust is seeking a dynamic Information Security GRC Analyst to support IT and InfoSec by performing governance, risk, and compliance activities as part of the team.
  • The role involves owning a high volume of end-to-end completion of customer security questionnaires, RFP security sections, and other assurance artifacts while leveraging internal evidence repositories.
  • Employees receive comprehensive healthcare coverage, flexible PTO, equity RSUs, annual performance bonus opportunities, retirement account support, and 14+ weeks of parental leave.

Matching Summary

Match Score: 85

OneTrust is seeking an Information Security GRC Analyst to join their Madrid office, focusing on governance, risk, and compliance activities related to customer security assurance. The ideal candidate should have experience in information security, customer security questionnaires, and a strong understanding of security frameworks and compliance.

Salary

Not specified; Annual performance bonus opportunities available; Equity RSUs included

Skills & Requirements

Must-have

  • 2-5 years information security experience
  • Customer security questionnaire completion
  • SOC 2 ISO 27001 NIST framework knowledge
  • Security contract and DPA review skills
  • Cross-functional stakeholder collaboration

Nice-to-have

  • CISA or CISM industry certification
  • SaaS cloud security assurance background
  • Experience with enterprise customer support
  • Risk-based thinking and mitigation strategies
  • High-throughput execution in fast-paced environment

Key Requirements

  • 2-5 years relevant experience in GRC or security assurance
  • Familiarity with SOC 2, ISO 27001, NIST, CIS, PCI DSS, HIPAA, GDPR
  • Strong understanding of security fundamentals including access control and encryption
  • Excellent written and verbal communication skills
  • Ability to manage multiple requests with competing deadlines

Work Rights

Not specified

Tailored Resume

Cover Letter