Skip to main content

Specialist, Risk Management

RemoteSpain, United Kingdom only
Published
Role
Security
Experience
Mid
Salary not disclosed
Check eligibility

Open to ES, GB only. Set where you work from to check your eligibility.

No BS summary

In this role, the Risk Management Specialist III will support and strengthen our risk management and information security programs. You’ll help ensure the organization maintains effective protections across regulatory, contractual, and data privacy requirements while partnering cross-functionally to identify, assess, and mitigate risk.

Core skills

ISO 27001:2022GDPRPCI DSS

Required skills

VantaCCPAPIPEDALGPD

Required languages

English Fluent/Native

What you'll do

  • Supports the deployment and continuous improvement of information security policies, standards, and technical controls
  • Coordinates Prosci’s ISO 27001:2022 certification and audit activities, including audit scheduling, evidence collection, and external auditor coordination
  • Administers compliance tooling (e.g., Vanta) to support the information security program and control monitoring
  • Facilitates ISMS Governance Council activities, including maintaining the enterprise risk register and reporting on risk posture
  • Conducts information security risk assessments for vendors, projects, and business changes

What they require

  • 4 – 7 years’ experience in Risk Management, including knowledge of US/international data privacy regulations, implementation for/maintenance of ISO certification 27001 certification, risk evaluation of new projects and vendors, creation of risk management solutions, review of client DPA and security agreements, and related matters.
  • Bachelor’s degree
  • CIPM Certification
  • Strong communication skills
  • Ability to work independently and prioritize multiple risks and adapt to needed changes
Salary not disclosed