Skip to content
← Back to job listings

GRC Specialist

Papaya Global · Barcelona, Spain

External listingfull-time2 months ago

About The Role

Join our Security group as a GRC Specialist. You will lead and manage information security compliance programs, support DORA compliance, respond to customer security questionnaires, conduct risk assessments, and collaborate with cross-functional teams. Enjoy benefits such as gym reimbursement, additional paternity/maternity leave, and a transparent PTO policy.

  • Lead and manage information security compliance programs, including SOC 2 Type I/II and ISO 27001 audits.
  • Support the implementation and maintenance of DORA (Digital Operational Resilience Act) compliance requirements across the organization.
  • Own the end-to-end process of responding to customer security questionnaires, RFPs, and third-party due diligence requests.
  • Familiarity with DORA (Digital Operational Resilience Act) requirements and their practical application
  • Strong knowledge of information security risk management methodologies and frameworks
  • Degree in Information Technology / Information Systems / Computer Science – Advantage
  • Highly proficient in spoken and written English
  • 4+ years of hands-on experience in GRC, information security compliance, or a related field
  • Hands-on experience with ISO 27001 implementation and/or certification audits
  • Experience in a SaaS or B2B tech company – Advantage
  • Experience working with cross-functional stakeholders and translating compliance requirements into actionable steps
  • Proven experience managing SOC 2 Type I/II audits and certification processes
  • Experience handling customer security questionnaires and due diligence requests – Must
  • Team player, detail-oriented, with strong organizational and communication skills – Must

This is an external listing. JobSpring does not represent or verify the employer. Report this listing