Governance, Risk & Compliance Manager
AdevintaRegularPosted Aug 3, 2026
At Adevinta Information Services, we build and operate some of Spain's largest digital marketplaces, including InfoJobs, Milanuncios, Coches.net and Motos.net.
We're building a modern, AI-first cybersecurity organisation from the ground up following our separation from the global organisation. This is a unique opportunity to shape governance, compliance and cyber risk for a fast-moving technology company.
We're looking for a proactive and pragmatic GRC Manager who enjoys working close to the business and turning governance into an enabler rather than a blocker.
Responsibilities include:
We're building a modern, AI-first cybersecurity organisation from the ground up following our separation from the global organisation. This is a unique opportunity to shape governance, compliance and cyber risk for a fast-moving technology company.
We're looking for a proactive and pragmatic GRC Manager who enjoys working close to the business and turning governance into an enabler rather than a blocker.
Requirements
- Experience leading GRC or Information Security Governance in a technology company
- Strong understanding of ISO 27001, ENS, NIST or similar frameworks
- Experience managing external audits
- Experience with Vendor Risk Management
- Excellent communication skills with technical and non-technical stakeholders
- Pragmatic mindset focused on reducing business risk
- Ability to work autonomously and drive initiatives end-to-end
- Experience in SaaS, cloud-native or digital marketplace environments
- Experience with GRC platforms
- Security certifications (CISM, CRISC, ISO Lead Auditor...)
Responsibilities
You will own the Governance, Risk & Compliance function across Adevinta Information Services and support our marketplaces in maintaining a strong security posture.Responsibilities include:
- Own the Information Security Management System (ISMS)
- Lead ISO 27001, ENS and other security certifications and audits
- Coordinate cybersecurity assessments from internal stakeholders, EQT and external auditors
- Drive Third-Party Risk Management across suppliers and strategic partners
- Define and maintain security policies, standards and governance processes
- Lead security awareness and phishing programmes across the company
- Track security risks and remediation plans with business owners
- Build executive dashboards and security KPIs for senior leadership
- Coordinate Business Continuity and security governance activities
- Partner with Legal, Privacy, Procurement, Engineering and Product teams to embed security into business processes
- Help scale governance through automation and AI where possible
Benefits
- Build a cybersecurity organisation from scratch
- High ownership and impact
- Work with modern cloud technologies
- AI-first security strategy
- Flexible hybrid environment
- International technology company
- Competitive salary and benefits