New

Manager, Information Security GRC

Madrid, Spain

Strength in Trust 

OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™, unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society. 

 

The Challenge

This role leads one or more GRC (Governance, Risk and Compliance) program functions for OneTrust. This role is also responsible for customer security and third-party risk.

This is a critical role at OneTrust because it helps ensure we have the right processes, oversight, and support in place to protect the company, support our customers, and scale our security and compliance efforts effectively.

Your Mission

Lead and mature the Security GRC team and its programs, ensuring the team is working effectively and is adequate for the size and scope of the company.

This person will, on a daily and weekly basis:

  • lead a team of Security GRC analysts
  • mature program processes and procedures
  • measure quality of work and performance indicators to ensure resources are applied to the right places
  • manage the customer security team, which handles customer contract reviews, questionnaires, assessments, RFPs, and customer calls
  • manage third-party risk for the company
  • manage key vendor relationships

Primary Responsibilities / Expected Results

  • manage and mature the Security GRC team, ensuring monitoring so the team is working effectively and is adequate for the size and scope of the company
  • create and maintain a scalable process for compliance and continuous assurance
  • collaborate with IT, InfoSec, and within the GRC team to mature the compliance process and become a trust advisor to IT, InfoSec, R&D, and the business
  • transform our ongoing risk and control self-assessment, audit management, security risk assessment, and third-party assessment processes
  • execute risk assessments of third-party vendors
  • provide front-line support to customer meetings and audit requests to ensure that OneTrust’s customers understand the security program and controls and how it meets their requirements
  • support requests from the audit team, risk team, security awareness team, and other internal stakeholders

Success in This Role

Success in this role is defined by:

  • a well-managed and scalable Security GRC team
  • strong and repeatable compliance and continuous assurance processes
  • improved risk and assessment processes across the business
  • effective support for customer security needs and audit requests
  • strong collaboration and trusted partnership across IT, InfoSec, R&D, and the business

You Are

  • qualified with a College BS/BA degree, progressive educational certificate, or equivalent
  • experienced, with 5+ years of experience in Information Security
  • knowledgeable, with 3+ years of experience in a GRC analyst or information security support role
  • a people leader, with 2+ years as a people leader, team lead, or in a senior analyst/engineer capacity on the team
  • experienced managing teams and technologies in a multi-cloud environment

 

Where we Work

We are embracing an office-first culture, encouraging three days a week in office for most roles, with meaningful opportunities to collaborate and celebrate in person.

Each role may have specific requirements or flexibility depending on the scope of the position, so we encourage you to verify this with your recruiter during your first interview.

Benefits

As an employee at OneTrust, you will be part of the OneTeam. That means you’ll receive support physically, mentally, and emotionally so that you can do your best work both in and out of the office. This includes comprehensive healthcare coverage, flexible PTO, equity RSUs, annual performance bonus opportunities, retirement account support, 14+ weeks of paid parental leave, career development opportunities, company-paid privacy certification exam fees, and much more. Specific benefits differ by country. For more information, talk to your recruiter or visit onetrust.com/careers.

Resources  

Check out the following to learn more about OneTrust and its people: 

Your Data

You have the right to have your personal data updated or removed. You also have the right to have a copy of the information OneTrust holds about you. Further details about these rights are available on the website in our Privacy OverviewYou can change your mind at any time and have your personal data removed from our database. In order to do this you must contact us and let us know you wish to be removed. The request should be made on the Data Subject Request Form.

Recruitment fraud warning: OneTrust is aware of scams involving false offers of employment with our company. The fraudulent jobs, interviews and job offers use fake websites, email addresses, group chat and text messages. Be aware that we never ask candidates for personal information, IDs or bank information during the interview process. We do not interview prospective candidates via instant message or group chat, and do not require candidates to purchase products or services, or process payments on our behalf as a condition of any employment offer. Please note that any legitimate interview availability requests will come directly from a OneTrust recruiter with an "@onetrust.com" email address. You may also receive legitimate emails from "@us.greenhouse-mail.io". Recruiters will only reach out to candidates who have applied for a role through our ATS (Greenhouse) or prospects via LinkedIn InMail. Job offers will come from a recruiter and may have a "@docusign.net" email address. For more information or if you have been targeted please reach out to askrecruiting@onetrust.com.

Our Commitment to You 

When you join OneTrust you are stepping onto a launching pad — the countdown has begun. The destination? A career without boundaries working alongside a diverse and inclusive crew who is passionate about doing meaningful work. As a pioneer, your voice and expertise will help chart the direction of an entirely new category. Our commitment to putting people first starts with you. Your growth is part of the mission. Our goal is to give you the power to embark on the next phase of your uniquely, unique career. 

OneTrust provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by local laws.

Create a Job Alert

Interested in building your career at OneTrust? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...
Select...
Select...

Before you submit your application, please confirm that you have read and understood our Candidate Privacy Notice available here. In order to exercise your rights with respect to any Personal Information submitted as part of your application, please contact us using our Data Subject Request Form.