Hiring.Camp

Information Security Governance Specialist

Alsglobal

·

Today

Location
ESP - Madrid (Executive Office), Spain
Department
Security
Source
Workday

Description

At ALS, we encourage you to dream big.

When you join us, you’ll be part of a global team harnessing the power of scientific testing and data-driven insights to build a healthier future. 

The Information Security Governance Specialist owns the governance backbone of the security programme: policy, control framework design, compliance, and audit assurance. This role translates security strategy into structured, auditable, and operationally realistic governance artefacts (e.g.: exception registers, policy suites, control frameworks, audit programmes) and works across the business to embed them into everyday operation. 

 

Key responsibilities 

  • Develop, maintain, and periodically review information security policies, standards, and procedures aligned to ISO 27001 and other recognised cybersecurity frameworks. 

  • Maintain the security governance calendar (policy reviews, management reviews). 

  • Support design and evolution of the organisation's security strategy and multi-year security programme roadmap. 

  • Administer the security exception/waiver process end-to-end: intake, documentation, approval routing, and tracking of time-bound remediation commitments through to closure. 

  • Maintain the control framework catalogue, mapping controls to ISO 27001 Annex A, NIST CSF, and CIS Controls, and flag control gaps for risk assessment by the Information Security Risk Specialist. 

  • Partner with the Information Security Risk Specialist to ensure exceptions and control gaps are risk-assessed and formally risk-accepted by the appropriate owner before a waiver is granted. 

  • Coordinate internal and external audits and certification cycles (e.g. ISO 27001), including evidence collection and remediation tracking. 

  • Map controls to regulatory and contractual obligations (GDPR, PCI-DSS, HIPAA, sector-specific requirements as applicable). 

  • Maintain a defensible audit trail for control operation and governance decisions. 

  • Produce executive-ready reporting: governance and compliance dashboards, programme status updates, board and committee papers. 

  • Act as a trusted point of contact for business units seeking governance guidance on new initiatives. 

  • Contribute governance input to post-incident reviews and remediation programmes, ensuring lessons learned convert into control or policy change. 

  • Support the broader team on cross-functional initiatives (e.g. data protection projects, security awareness) as priorities require. 

Working at ALS

The ALS team is a diverse and dedicated community united by our passion to make a difference in the world.

Our values are important to us, and shape how we work, how we treat each other and how we recognise excellence. 

At ALS, you’ll be supported to develop new skills and reach your full potential. We invest in our people with programs and opportunities that help you build a diverse career with us. 

We want everyone to have a safe, flexible and rewarding career that makes a positive impact on our people, the planet and our communities.

Everyone Matters

ALS is proud to be an equal opportunity employer and is committed to fostering an inclusive work environment where the strengths and perspectives of each employee are both recognised and valued.

ALS also welcomes applications from people with all levels of ability. Reasonable adjustments to support candidates throughout the recruitment process are available upon request.

Eligibility
To be eligible to work at ALS you must be a Citizen or Permanent Resident of the country you are applying for, or either hold or be able to obtain, a valid working visa.

How to apply
Please apply on-line and provide a resume & cover letter that best demonstrate your motivation and ability to meet the requirements of this role.

Skills

CybersecurityComplianceHIPAAGDPRISO 27001

Similar Jobs

30

Lead, Business Intelligence, Information Security Governance

Pru · Wash, 213 Washington St., Newark, NJ, United States of America · Remote, Hybrid, Onsite

1 week ago

Information Security Governance Specialist

Frontify · Sankt Gallen Metropolitan Area · Hybrid

4 weeks ago

Information Security Governance Specialist

Frontify · London Area · Hybrid

4 weeks ago

Information Security Governance Expert

Roche · Madrid Osiris, Spain

1 month ago

Working Student Information Security Governance & Culture

Puma · PUMA Way Headquarters, Germany

1 month ago

Information Security Governance Expert

Roche · Madrid Osiris, Spain

1 month ago

AI and Automation Engineer-Information Security Governance

Roche · Madrid Osiris, Spain

1 month ago

Information Security Governance Manager

Ebanx · Curitiba | On-site · Onsite

2 months ago

Information Security Governance, Risk and Compliance Specialist

Globalwebindex · Athens, GR +1 · Hybrid

2 months ago

Information Security Governance Analyst

Default Brand · Kansas City, MO

2 months ago

Information Security Governance, Risk and Compliance Specialist

Globalwebindex · London, UK · Hybrid

2 months ago

Director of Information Security Governance & Compliance

Sobi · Stockholm, Stockholm County, Sweden · Hybrid

2 months ago

Associate - Information Security Governance - IT

HKEX Career · HK-TKO 5/F, Hong Kong

3 months ago

Senior Information Security Governance Consultant

Thales · Zaventem_EXC, Belgium · Remote

3 months ago

Information Security Governance Consultant

AIA Careers · PH-MPI-Makati City, TWC, Philippines

4 months ago

Information Security Governance Specialist - Information Security Enablement Section, Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

4 months ago

Information Security Governance Risk & Compliance Assoc. Mgr.

Morae · Bangalore, India

1+ year ago

Vice President, Information Security - Identity, Governance, and Cyber Risk

Pg · CINCINNATI GENERAL OFFICES, United States of America

3 days ago

Information Security Specialist - Global ISMS Operation & Support Group, Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

1 week ago

AI Risk Management Specialist - AI Governance Management Section, Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

3 weeks ago

Information Security Intern – Governance, Risk & Compliance (GRC)

Cc · LONDON BOND STREET HOUSE, United Kingdom

3 weeks ago

Vice Manager, IT Security Group - Information Security Management Office, Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

1 month ago

Information Governance Specialist/Domestic Group Company Support of Communication and Energy Company - Rakuten Mobile & RTS Support Group, Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

1 month ago

Privacy Expert, Global Privacy - Global DPO Office, Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

1 month ago

Director of Information Security & AI Governance

Flagstone · London

3 months ago

Vice Group Manager, Information Security Policy Group - Information Security Management Office, Information Security & Privacy Governance Department (ISPD)

Rakuten · Rakuten Crimson House, Japan

6 months ago

Senior Information Security Analyst (Vulnerability Governance)

Td · 310/320 Front Street West Corporate, Toronto, Ontario, Canada · Hybrid

Yesterday

Head of the Regional Governance Unit for Information Security and Data Protection - Bosch Switzerland 100% (f/m/div.) REF290730T

Robert Bosch · Zuchwil, SO, Switzerland · Hybrid

2 days ago

Information Security Analyst 5, Governance, Risk & Compliance (GRC)

SanDisk · Batu Kawan, Penang, Malaysia

1 month ago

Head of Governance, Risk and Compliance (Information Security)

Leonardocompany · GB - Basildon - Home Based, United Kingdom +9 · Hybrid, Remote

2 weeks ago