You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Early Window: Be the first to open itNo views yetCloses in
Company hidden

Security GRC Engineer

  • Hybrid
  • 3-6 years

Salary

Not stated

Similar roles pay €85K - 105K a year · our estimate

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

Glovo is seeking a proactive Security GRC Engineer to help strengthen our global security posture and navigate a rapidly evolving regulatory environment. In this multifaceted role, you will support compliance frameworks (PCI DSS, ISO 27001, NIS2), internal and external audits, drive risk assessment and remediation, and pioneer security awareness programs within our organization. Acting as a strategic bridge between technical engineering, legal, and business stakeholders, you will translate complex legal and regulatory demands into robust, actionable security controls. The ideal candidate brings deep cybersecurity risk expertise, hands-on experience with GRC tools, and the collaborative mindset needed to foster a security-first culture across Glovo.

Be a part of a team where you will:

Develop, implement, and maintain security policies and procedures in line with relevant compliance frameworks (e.g., ISO 27001, NIST, PCI DSS, GDPR, NIS2, EU AI Act).

Develop, execute and deliver security awareness programs to educate employees on best practices and compliance requirements.

Conduct security assessment risks, recommending and implementing mitigation strategies, maintaining a risk register and monitoring the status of remediation plans.

Coordinate and respond to customer security inquiries and due diligence questionnaires (e.g., SIG, CAIQ). Review and provide input on contract modifications related to security, data protection, and privacy.

Propose, develop and implement processes and tools for continuous monitoring of security monitoring to ensure ongoing adherence to policies.

Assist with the end-to-end security certification and re-certification process (such as PCI DSS, ISO 27001, NIS2, among others).

Assist with internal assessments to identify gaps, weaknesses, or non-compliance issues within our security controls.

Support external and internal audits by preparing documentation and coordinating with auditors, follow ups and findings remediation.

Serve as a key liaison between technical teams, legal, internal audit, and business units to ensure a unified approach to security and compliance

Requirements

  • BA/BS in Computer Science, Information Systems, or similar field.
  • Professional security certifications (CISSP, CISM, CISA, ISO 27001 Lead Implementer or equivalent).
  • Minimum 5 years of experience in the field or in a related area.
  • Solid understanding and previous experience of security control frameworks (NIST, PCI DSS, GDRP, ISO 27001, NIS2)
  • Hands-on experience with GRC platforms (e.g. RSA Archer, SAP GRC, StandardFusion, ServiceNow, OneTrust, etc).
  • Strong ability to manage and report on multiple projects, prioritizing efforts, managing time effectively, and requiring minimal direction in the execution.
  • Proven problem solving, analytical and investigative skills combined with the ability to develop creative solutions and navigate through ambiguity in a fast-paced, agile environment.
  • Proven team player, collaborating well with others to tackle problems in a team-focused dynamic.
  • Excellent written and communications skills, as well as strong interpersonal and relationship building skills.
  • Experience with compliance in cloud environments (AWS, Azure, GCP) and knowledge of frameworks like the Cloud Controls Matrix (CCM).
  • Experience in risk quantification methodologies (e.g., FAIR) to assess financial and operational impact of security risks.
  • Strong background in designing and delivering effective security awareness programs to foster a security-first culture.
  • Nice-to-haves:
  • Development skills to automate integrations or processes (e.g. python).
  • Experience with developing, documenting, and testing Business Continuity Plans (BCP) and Disaster Recovery (DR) plans.
  • Working knowledge of the EU AI Act, including its risk-based approach and requirements for high-risk and general-purpose AI models. Familiarity with AI security threats and relevant frameworks (NIST AI RMF, MITRE ATLAS).
  • Additional Information
  • At Glovo, your success is defined by both results and behaviors. We hire for excellence in craft and for the Leadership Principles that shape how we think, decide, and collaborate. What you achieve matters and how you achieve it defines us. Together, they move the business forward and deliver great experiences. Learn more about our Leadership Principles here .
  • Here at Glovo, we thrive on diversity, we believe it enhances our teams, products, and culture. We know that the best ideas come from a mashup of brilliant diverse minds. This is why we are committed to providing equal opportunities to talent from all backgrounds – all genders, racial/diverse backgrounds, abilities, ages, sexual orientations and all other unique characteristics that make you YOU. We will encourage you to bring your authentic self to work, fostering an inclusive environment where everyone feels heard.
  • Feel free to note your pronouns in your application (e.g., she/her/hers, he/him/his, they/them/theirs, etc).
  • So, ready to take the wheel and make this the ride of your life?
  • Delve into our culture by taking a peek at our Instagram and check out our LinkedIn and website !
  • Company Description
  • Glovo is part of the the company Group, the world’s pioneering local delivery platform, our mission is to deliver an amazing experience—fast, easy, and to your door.

Where you’d work

Part of the week in the office

About the company

Company hidden

  • Industry: Logistics

Office in Barcelona, Spain

Your chances

Still hiring, not crowded yet, and you'd be among the first.

  • 16 checks run
  • 5 good signs
  • 1 red flag

Still hiring?

11 checks

Actively hiring

In its favour3

  • Still on the company's own careers site, checked 1 h agoModerate evidence
  • Found in the last 48 hours, before the big job boardsModerate evidence
  • The company opened 19 roles and closed 38 in the last 2 weeks: hiring is movingModerate evidence

Against it1

  • Listed again after an earlier listing of the same role closedModerate evidence

How crowded?

5 checks

Low

In its favour2

  • In its Early Window: not on the big job boards yetStrong evidence
  • Hybrid in Barcelona: only people nearby can take itSlight evidence

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details11 facts · Role, Location, Compensation, Employment, Company
Tech stack
  • Python
  • AWS
  • Azure
Type
Full-time
Industry
Logistics
Specialty
Security
Region
Europe
Pay period
Annual
Show 5 more factsShow less

Role

Category
DevOps & Infrastructure
Specialty
Security
Experience
5+ years
Tech stack
  • Python
  • AWS
  • Azure

Location

Work model
Hybrid
Region
Europe
Office
  • Barcelona, Spain

Compensation

Salary
Salary by agreement
Pay period
Annual

Employment

Type
Full-time

Company

Industry
Logistics

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer, New Grad

    Salary by agreement

    • Office · Dublin
    • Junior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Security Operations Analyst

    Salary by agreement

    • Hybrid · Wellington, Auckland
    • Senior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Platform Security Engineer

    £90,000 - 160,000 / year

    • Hybrid · London
    • Mid-Level
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer

    $275,000 - 345,000 / year

    • Office · London

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason