← Back to job listings
PG
GRC Specialist
Papaya Global · Barcelona, Spain
About The Role
Join our Security group as a GRC Specialist. You will lead and manage information security compliance programs, support DORA compliance, respond to customer security questionnaires, conduct risk assessments, and collaborate with cross-functional teams. Enjoy benefits such as gym reimbursement, additional paternity/maternity leave, and a transparent PTO policy.
- Lead and manage information security compliance programs, including SOC 2 Type I/II and ISO 27001 audits.
- Support the implementation and maintenance of DORA (Digital Operational Resilience Act) compliance requirements across the organization.
- Own the end-to-end process of responding to customer security questionnaires, RFPs, and third-party due diligence requests.
- Familiarity with DORA (Digital Operational Resilience Act) requirements and their practical application
- Strong knowledge of information security risk management methodologies and frameworks
- Degree in Information Technology / Information Systems / Computer Science – Advantage
- Highly proficient in spoken and written English
- 4+ years of hands-on experience in GRC, information security compliance, or a related field
- Hands-on experience with ISO 27001 implementation and/or certification audits
- Experience in a SaaS or B2B tech company – Advantage
- Experience working with cross-functional stakeholders and translating compliance requirements into actionable steps
- Proven experience managing SOC 2 Type I/II audits and certification processes
- Experience handling customer security questionnaires and due diligence requests – Must
- Team player, detail-oriented, with strong organizational and communication skills – Must
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring