
HR Security and Compliance Analyst
- Barcelona
- Permanente
- Tiempo completo
- As a Cybersecurity and Compliance Analyst, your main role is to support Cyber Security, and Privacy compliance for HR processes and supporting applications.
- To safeguard sensitive HR data and ensure regulatory compliance by proactively identifying risks, implementing robust security controls, and fostering a culture of data protection.
- This role bridges cybersecurity expertise with HR-specific needs, ensuring that employee data, systems, and processes are secure, compliant, and resilient against threats.
- Data Protection & Privacy
- Ensure HR systems comply with data protection regulations (e.g., GDPR, HIPAA, local labor laws).
- Monitor and enforce policies for handling Personally Identifiable Information (PII) and sensitive employee data.
- Risk Assessment & Mitigation
- Support risk assessments on HR applications (e.g., payroll, recruitment platforms, employee portals).
- Identify vulnerabilities and recommend mitigation strategies tailored to HR workflows.
- Collaborate with HR and IT teams to implement secure configurations and access controls.
- Compliance Monitoring
- Track and report on compliance with internal policies and external regulations.
- Maintain documentation for audits and regulatory reviews.
- System & Application Security
- Collaborate with IT to secure HRIS, ATS, LMS, and other HR platforms.
- Ensure encryption, authentication, and role-based access controls are properly implemented.
- Participate in change management processes for HR systems to assess security impact.
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field.
- Solid understanding of cybersecurity principles, data privacy laws, and compliance frameworks (e.g., GDPR, NIS 2, HIPAA, SOC 2).
- Experience securing HR systems such as Workday, SAP SuccessFactors, Oracle HCM, or similar platforms.
- Proficiency with security tools (e.g., SIEM, DLP, IAM, GRC platforms).
- Strong analytical and problem-solving skills.
- Effective communication and stakeholder management, especially with HR and legal teams.
- Ability to translate technical risks into business impact for non-technical audiences.
- Proactive mindset with a focus on continuous improvement and collaboration.
- 3–5 years of experience in cybersecurity, IT audit, or compliance roles.
- Demonstrated experience working with HR or other sensitive data domains.
- Preferred certifications (any of the following):
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Information Privacy Professional (CIPP/US, CIPP/E)
- ISO/IEC 27001 Lead Implementer or similar
+13% organic growth
150 000+ employees in 100+ countries
#1 on the Global 100 World’s most sustainable corporationsYou must submit an online application to be considered for any position with us. This position will be posted until filled.Schneider Electric aspires to be the most inclusive and caring company in the world, by providing equitable opportunities to everyone, everywhere, and ensuring all employees feel uniquely valued and safe to contribute their best. We mirror the diversity of the communities in which we operate, and ‘inclusion’ is one of our core values. We believe our differences make us stronger as a company and as individuals and we are committed to championing inclusivity in everything we do.At Schneider Electric, we uphold the highest standards of ethics and compliance, and we believe that trust is a foundational value. Our Trust Charter is our Code of Conduct and demonstrates our commitment to ethics, safety, sustainability, quality and cybersecurity, underpinning every aspect of our business and our willingness to behave and respond respectfully and in good faith to all our stakeholders. You can find out more about our Trust CharterSchneider Electric is an Equal Opportunity Employer. It is our policy to provide equal employment and advancement opportunities in the areas of recruiting, hiring, training, transferring, and promoting all qualified individuals regardless of race, religion, color, gender, disability, national origin, ancestry, age, military status, sexual orientation, marital status, or any other legally protected characteristic or conduct.