Join our cybersecurity team as a GRC Senior Consultant and help organizations navigate today’s evolving security and regulatory landscape.
You will work on cybersecurity assessments, audits, risk and compliance initiatives across leading frameworks and regulations such as ISO 27001, NIST CSF, ENS, PCI DSS, ISO 22301, GDPR, NIS2 and DORA, while advising clients and contributing to the development and continuous improvement of our GRC services.
This is an opportunity to combine your cybersecurity and GRC expertise with consulting, project coordination and client-facing responsibilities, working with different stakeholders and helping organizations strengthen their security and compliance posture.
Your responsibilities
As a GRC Senior Consultant, you will:
- Define and validate the scope of cybersecurity assessments, compliance reviews and audits, ensuring alignment with applicable standards and regulatory requirements.
- Review and assess technical documentation, security policies, procedures, regulations and control frameworks.
- Conduct interviews and working sessions with stakeholders responsible for security measures, processes and controls.
- Collect, review and validate supporting evidence as part of cybersecurity assessments and audits.
- Identify potential compliance gaps and provide guidance on how to address them.
- Advise clients and internal stakeholders on compliance with information security standards, regulations and cybersecurity best practices.
- Participate in GRC projects related to frameworks and regulations such as PCI DSS, NIST CSF, ISO 27001, ENS, ISO 22301, GDPR, NIS2 and DORA, as well as emerging areas related to AI governance and compliance.
- Prepare clear and comprehensive reports, assessments, findings and project deliverables.
- Support the coordination and management of cybersecurity and GRC projects, working with multidisciplinary teams and different stakeholders.
- Contribute to the development, evolution and continuous improvement of GRC products and services.
- Bring a proactive and problem-solving approach to client challenges, identifying opportunities to improve security governance, risk management and compliance processes.
What are we looking for?
We would love to hear from you if you have:
- A higher technical degree in Engineering, IT, Telecommunications or a related field.
- At least 5 years of professional experience in cybersecurity, including a minimum of 3 years of experience in Governance, Risk and Compliance (GRC).
- Solid knowledge of cybersecurity principles, practices and technologies.
- Experience working with security and compliance frameworks and regulations such as: ISO 27001 NIST Cybersecurity Framework (CSF) PCI DSS ENS ISO 22301 GDPR NIS2 DORA AI-related governance and regulatory requirements
- Knowledge of cybersecurity technologies and experience in projects involving the design, implementation or deployment of cybersecurity solutions.
- Experience in project management, team coordination and stakeholder management.
- Professional proficiency in English, both written and spoken.
- Strong analytical skills and the ability to understand, structure and synthesize complex information.
- Excellent interpersonal and communication skills, with the ability to interact effectively with both technical and non-technical stakeholders.
- A proactive and autonomous way of working.
- Critical thinking and problem-solving skills.
- A collaborative mindset and strong teamwork skills.
- Commitment to continuous improvement.
- Creativity and the ability to find practical solutions to complex cybersecurity and compliance challenges.
Nice to have
- Proficiency in Euskera/Basque is highly desirable, although it is not mandatory.
Working model
This position offers a hybrid working model, combining remote work with regular presence at client offices in the area. For this reason, candidates must be based in Bilbao or Vitoria.
Why join us?
If you are passionate about cybersecurity, risk and compliance, enjoy working in a consulting environment and want to contribute to challenging projects across different security and regulatory frameworks, we would love to hear from you.
Join us and help build a safer and more resilient digital future.
YOUR CAREER AT THALES
Future opportunities will allow you to discover other domains or sites. You will be able to evolve and grow your competences in different areas:
Room and attention to personal development
Build your talents in another domain of Thales Group, discovering new products, new customers, new country or go to a more complex Solution
Choose between a technical expertise or a leadership path
Build an international career within a leading Engineering Group
More Information
Application Details
- Organization DetailsTHALES S21 SEC ESPAÑA, S.A.U.


Recommended Comments
There are no comments to display.
Join the conversation
You are posting as a guest. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.