CAREERS & OPPORTUNITIES
Passionate about cybersecurity? So are we.
We are looking for talented, motivated professionals eager to grow in a dynamic, flexible environment aligned with modern ways of working. Build impactful projects free from unnecessary bureaucracy.
Open Opportunities
Available Positions
Barcelona / MadridFull Time · Hybrid ModelActive Opening
Cybersecurity Senior Consultant (GRC) - BCN / MAD
Are you interested in helping organizations establish and strengthen their security programs through solid governance, risk management, and regulatory compliance? At cyber& we are seeking a Senior Cybersecurity Consultant to help our clients design, implement, and maintain effective security frameworks.
ISO 27001ENSNIS2GDPRPCI DSS+5 years exp.Hybrid
Responsibilities
- •Assist in cybersecurity risk evaluations and assessments, delivering clear analyses and actionable reports for leadership decision-making.
- •Collaborate on designing, updating, and documenting security policies, standards, and controls aligned with ISO 27001, NIST, ENS, PCI DSS, GDPR, and other key standards.
- •Participate in internal compliance audits and provide technical support during official external accreditation audits.
- •Facilitate security awareness sessions and stakeholder communication across organization tiers to foster a proactive defense culture.
- •Contribute to identifying and cataloging compliance gaps, formulating remediation roadmaps and tracking closure metrics.
- •Stay up to date on evolving regulatory requirements, emerging frameworks, and modern GRC methodologies.
- •Support executive briefing preparation and steering committee reporting for clients and stakeholders.
Requirements
- •University degree in Computer Engineering, Telecommunications, Cybersecurity, Business Administration, or related field.
- •Minimum 5 years in cybersecurity, with at least 4 years focused on risk management, regulatory compliance, or security audits.
- •Practical knowledge of security frameworks and mandates including ISO 27001, NIST, ENS, GDPR, PCI DSS, or equivalent.
- •Proficiency in tooling for compliance workflows, risk dashboards, audit evidence tracking, and executive technical reporting.
- •Advanced level of English and Spanish, both verbal and written. Knowledge of Catalan is a valued asset.
- •Strong analytical thinking, proactive communication, team mindset, results orientation, and commitment to continuous improvement.
Valued Assets
- •Postgraduate studies in cybersecurity, engineering, technology law, or related disciplines.
- •Solid background in management and compliance frameworks (ISO 27001, NIST, GDPR, ENS).
- •Recognized GRC or security certifications (e.g. ISO 27001 Lead Implementer/Auditor, CRISC, CISSP Associate).
- •Experience or active interest in security controls auditing and consulting engagements.
What We Offer
- ✓Competitive compensation package aligned with your qualifications and experience.
- ✓38-hour work week (summer compensation reduction) with flexible working hours.
- ✓Hybrid working model (2-3 remote days per week depending on project requirements).
- ✓Flexible Remuneration Program: transit pass, meal vouchers, nursery checks.
- ✓Dynamic, appealing work environment focused on long-term stability and professional growth.
- ✓Continuous training, corporate backing for recognized industry certifications, and real technical challenges.
- ✓Collaborative, high-performing team culture with clear pathways for career progression.
Send your CV directly to our recruiting team: rrhh@cyberand.com
Open Application
Don’t see a role matching your exact profile?
We are always eager to connect with great talent. Send us your resume for future opportunities.
