GRC Security Expert
Leadtech · Barcelona, Spain · Remote
Posted Sep 18, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
At Leadtech, we’ve been redefining digital businesses since 2009, creating innovative online solutions that reach millions of users every month. With a diverse team of over 700 members from 23+ nationalities, we’re united by a passion for creativity and collaboration.
We specialize in delivering user-centric experiences across web and mobile platforms, where people can connect with our products like never before.
We’re proud of our global reach and committed to fostering an inclusive workplace where every individual contributes to our shared vision of bringing cutting-edge projects to life. Learn more about our journey and mission on our About Us page!
About The Role
To support our continuous growth, the Security team is expanding to navigate evolving security frameworks, drive data protection audits, and lead strategic data privacy initiatives.
If you’re passionate about information security, governance, solving complex problems, collaborating across departments, and driving results, this role is perfect for you!
Key responsibilities:
As a GRC Expert at Leadtech, You Will
Develop cybersecurity policies, procedures, and methodologies to maintain an optimal level of security within the company and implement various standards and regulations.
Juggle several projects at once (ISO 27001, vulnerability follow-up, vendor reviews) without letting quality slip, keeping everything aligned with our security policies and the regulations that apply to us (ISO 27001, GDPR, NIS2).
Develop Data Protection & Privacy initiatives
Proactively identify, troubleshoot, and resolve issues to optimize both internal and external processes.
Balance multiple projects without sacrificing quality, aligning your work with brand standards, cultural nuances, and regulatory requirements.
Engage with diverse stakeholders (e.g., product, engineering, and marketing teams) to gather requirements, evaluate options, and develop tools and processes to support our organization’s goals.
Required skills:
We’re looking for someone with a balance of hard and soft skills who can thrive in a dynamic, cross-functional environment. Here’s what we’d love to see:
Degree in Computer Science, Telecommunications, Law or equivalent practical experience.
1 or 2 years of experience in GRC, compliance, IT auditor, or a related role.
Working knowledge of ISO 27001:2022 (clause structure, Annex A controls, SoA). We are looking for someone with experience as an auditor, consultant, or implementation specialist.
Working knowledge of core data protection concepts (data retention, PIAs, RATs)
Basic familiarity with cloud platforms (AWS, GCP, Azure), enough to understand IAM concepts like least privilege, MFA, key rotation, and orphaned accounts, without needing admin-level expertise
Strong written communication in both English and Spanish (policies and audit deliverables are produced in English, day to day coordination is in Spanish)
Excellent organizational skills, able…