About the Role
Ebury is seeking a high-caliber Information Security & GRC Manager to spearhead our global governance, risk, and compliance initiatives. This role is for a seasoned professional who thrives on owning programs rather than just executing tasks. You will act as the primary architect of our security frameworks, ensuring our ISMS is audit-ready and serves as a strategic enabler for Ebury’s global expansion. You will be the bridge between technical security requirements and business risk, providing expert guidance on complex regulatory landscapes. This is an opportunity to be a strategic part of an experienced infosec team at a high-growth fintech scale-up.
Responsibilities
- Design, implement, and mature our global GRC framework, collaborating with other teams to align it with ISO 27001, NIST, GDPR, and DORA.
- Own the risk assessment process, leading the quantification and communication of risk to business stakeholders to drive informed decision-making.
- Lead and manage external audits as the primary liaison, overseeing the remediation of findings and ensuring continuous compliance across multiple jurisdictions.
- Mature our Third-Party Risk Management program by defining standards for vendor security and ensuring high-impact partners meet Ebury’s risk appetite.
- Proactively monitor the evolving fintech regulatory landscape (e.g., EU AI Act, NIS2, regional cyber laws) and design roadmaps to ensure Ebury remains ahead of the curve.
- Lead the selection and full-scale implementation of automated GRC platforms to establish automation and robustness in GRC operations.
- Act as a high-level consultant for new product launches and international expansions, ensuring "Security by Design" is incorporated.
- Design and champion advanced security awareness programs that focus on shifting organizational behavior through metrics-driven insights.
Requirements
- 5+ years of experience in Information Security, GRC, or Risk Management roles.
- Strong knowledge of information security standards and regulations (ISO 27001, SOC 2, GDPR, FCA/DORA, NIST, etc.).
- Analytical skills: Ability to assess a "Security Exception", experience with regulatory audits and working with financial regulators.
- Hands-on experience implementing risk management processes, control frameworks, and security metrics.
- Familiarity with GRC or risk platforms (e.g. OneTrust).
- Team player with exceptional communication and stakeholder management skills.
- Industry certifications such as CISSP, CRISC, CISA, or ISO 27001 Lead Implementer/Auditor are preferred.
Skills
- Information Security
- GRC
- Risk Management
- ISO 27001
- NIST
- GDPR
- DORA
- SOC 2
- FCA
- CISSP
- CRISC
- CISA
- OneTrust
Location
- Madrid
- Remote
Work Type
- Hybrid
- Full-time
Experience Level
- Senior
- 5+ years
Salary/Compensations
- Competitive Starting Salary with an annual discretionary bonus
Benefits
- Dedicated Mentorship
- Cutting-Edge Technology
- Clear, Accelerated Career Progression
- Dynamic & Supportive Culture
- Generous Benefits Package
- Central Madrid Office
About the Company
- Ebury helps ambitious businesses unlock global growth, and we take the same approach with our people. We encourage innovation and movement, collaboration and problem-solving, and foster an environment where everyone can feel they belong, are valued, supported and empowered to succeed.
- Ebury delivers sophisticated, integrated solutions — business accounts, hedging, and financing — on a single platform with a seamless workflow. Our success is built on a simple premise and singular purpose: To help businesses operate and scale globally.
- Since its founding in 2009, Ebury has always been a fast-growing leader in fintech. Today, we bring together 1,800+ Eburians across nearly 70 cities and we’re always looking to add to our team.
- At the heart of our offering is a proprietary platform, purpose-built to help businesses seamlessly streamline and manage global cash flow. We focus on continuous product evolution and innovation to build the infrastructure for borderless growth and help our clients scale at every stage.
- The opportunities at Ebury are as diverse as our people, ranging from business development to engineering roles across our tech pillars.
Equal Opportunity
- We believe in inclusion. We stand against discrimination in all forms and are against the intolerance of differences that makes us a modern and successful organisation. At Ebury, you can be whoever you want to be and still feel a sense of belonging no matter your story.
