Manager, Information Security GRC
IT
Madrid, Spain
Posted on Jun 9, 2026
Strength in Trust
OneTrust’s mission is to enable innovation through the responsible use of data and AI. We believe that ensuring data is trusted shouldn’t slow teams down—it should accelerate what’s possible. This led us to develop the first technology platform for responsible data use in 2016. Today, with AI representing the latest and most impactful expansion of data yet, OneTrust is once again redefining what responsible innovation looks like. OneTrust, the AI‑Ready Governance Platform™, unifies regulatory intelligence, automation, and connected governance workflows so businesses can continue to move at the speed of AI while ensuring good governance to prevent data misuse at scale. Trusted by thousands of organizations worldwide, OneTrust is shaping the future where trusted data becomes a transformative force for business and society.The Challenge
This role leads one or more GRC (Governance, Risk and Compliance) program functions for OneTrust. This role is also responsible for customer security and third-party risk.
This is a critical role at OneTrust because it helps ensure we have the right processes, oversight, and support in place to protect the company, support our customers, and scale our security and compliance efforts effectively.
Your Mission
Lead and mature the Security GRC team and its programs, ensuring the team is working effectively and is adequate for the size and scope of the company.
This person will, on a daily and weekly basis:
- lead a team of Security GRC analysts
- mature program processes and procedures
- measure quality of work and performance indicators to ensure resources are applied to the right places
- manage the customer security team, which handles customer contract reviews, questionnaires, assessments, RFPs, and customer calls
- manage third-party risk for the company
- manage key vendor relationships
Primary Responsibilities / Expected Results
- manage and mature the Security GRC team, ensuring monitoring so the team is working effectively and is adequate for the size and scope of the company
- create and maintain a scalable process for compliance and continuous assurance
- collaborate with IT, InfoSec, and within the GRC team to mature the compliance process and become a trust advisor to IT, InfoSec, R&D, and the business
- transform our ongoing risk and control self-assessment, audit management, security risk assessment, and third-party assessment processes
- execute risk assessments of third-party vendors
- provide front-line support to customer meetings and audit requests to ensure that OneTrust’s customers understand the security program and controls and how it meets their requirements
- support requests from the audit team, risk team, security awareness team, and other internal stakeholders
Success in This Role
Success in this role is defined by:
- a well-managed and scalable Security GRC team
- strong and repeatable compliance and continuous assurance processes
- improved risk and assessment processes across the business
- effective support for customer security needs and audit requests
- strong collaboration and trusted partnership across IT, InfoSec, R&D, and the business
You Are
- qualified with a College BS/BA degree, progressive educational certificate, or equivalent
- experienced, with 5+ years of experience in Information Security
- knowledgeable, with 3+ years of experience in a GRC analyst or information security support role
- a people leader, with 2+ years as a people leader, team lead, or in a senior analyst/engineer capacity on the team
- experienced managing teams and technologies in a multi-cloud environment