
Information Security GRC Specialist (m/f/x) at Allianz Direct Spain
- Madrid
- Permanente
- Tiempo completo
We are looking for an Information Security GRC Specialist who is looking to work hands-on to help the security team accelerate and support our business even faster.To thrive in this dynamic role, you'll leverage your exceptional expertise in information security frameworks to drive various GRC initiatives. You would leverage cuttingedge automation tools to streamline and enhance GRC processes,ensuring efficient risk management, regulatory compliance, and governance oversight across the organization.
Join usin shaping a secure future while making a meaningful impact in an exciting and rewarding setting.Key Responsibilities:
- Manage and improve our Governance Framework, in line with regulatory requirements and Allianz group-wide
- standards. We work with ISO 27001, DORA, GDPR, NIS, etc.
- Optimize our Information Security Control Framework to ensure efficiency and transparency for our partners, auditors, and other internal or external stakeholders.
- Support and execute the Information Risk Management process, including risk analytics analysis, mitigation, and preparation of risk reports for Senior Leadership including Board of Management.
- Conduct regular self-assessments against our Control Framework, supporting stakeholders in their role during these assessments and in evidence collection.
- Support with other Governance and Compliance related work, such as technical documentation, following up on vulnerability reports, and third risk management.
- University degree in relevant disciplines preferred.
- At least 5 years of experience in Information Security with significant focus on GRC.
- Experience with Information Security GRC tools.
- Experience with Governance of cloud-native environments and understanding of the implications of cloud-
- native technology on GRC.
- Ability to translate between deep technical experts and business leaders or compliance experts (e.g., Auditors).
- Ability to communicate security issues and coach technical teams on best compliance practices.
- Knowledge of compliance with regulations and standards (e.g., DORA, GDPR, ISO 27001, NIS).
- English proficiency required; additional languages are a plus.