Governance, Risk & Compliance Specialist

Posted 5 Days Ago
Be an Early Applicant
Madrid, Comunidad de Madrid, ESP
In-Office
Mid level
Consumer Web
The Role
Supports global governance, risk, and compliance initiatives by developing cybersecurity policies, monitoring KPIs and KRIs, supporting audits and risk assessments, coordinating regulatory alignment, delivering awareness training, researching emerging requirements, and implementing GRC tools and controls across countries and business lines.
Summary Generated by Built In

At Pluxee, we shape the world of employee benefits and engagement by bringing to life a personalized and sustainable employee experience, at work and beyond.

Permanent Regular

Job Description:

Pluxee is a global player in employee benefits and engagement that operates in 28 countries. We help companies attract, engage, and retain talent thanks to a broad range of solutions across Meal & Food, Wellbeing, Lifestyle, Reward & Recognition, and Public Benefits.


Powered by leading technology and more than 5,000 engaged team members, Pluxee acts as a trusted partner within a highly interconnected B2B2C ecosystem made up of more than 500,000 clients, 36 million consumers and 1.7 million merchants.


Conducting its business as a trusted partner for more than 45 years, Pluxee is committed to creating a positive impact on all its stakeholders, from driving business to local communities, to supporting wellbeing at work for employees while protecting the planet.


🚀 Your next challenge


The GRC (Governance, Risk, and Compliance) Analyst supports Pluxee’s global cybersecurity, compliance, and risk management initiatives by developing, implementing, and monitoring GRC frameworks. Operating within a dynamic B2B2C environment, this global individual contributor role collaborates across functions to ensure regulatory alignment, policy compliance, and continuous risk mitigation. The role contributes directly to Pluxee’s strategic ambition to be a SMART Leader in employee benefits by embedding robust and responsible governance practices.

🚀 Key Responsibilities

1. Policy & Framework Development
- Develop, update, and maintain cybersecurity and compliance-related policies, procedures, and standards.
- Ensure alignment with global regulatory and industry frameworks (e.g., ISO 27001, NIST, GDPR, LGPD, DORA).
- Support the continuous improvement and application of Pluxee’s GRC framework.
2. Monitoring & Reporting
- Track and analyze cybersecurity KPIs and KRIs, providing data-driven insights and risk posture updates to senior stakeholders.
- Contribute to regular internal reporting and audits, ensuring visibility and transparency on compliance efforts.
3. Collaboration & Alignment
- Collaborate with cross-functional teams including IT, Privacy, Legal, and -Compliance to ensure integrated governance approaches.
- Support business units in applying policies and resolving GRC-related questions or challenges.
4. Awareness & Training
- Participate in the rollout of awareness campaigns and employee training programs aligned with cybersecurity and compliance priorities.
- Provide subject matter input to content development for GRC education.
5. Research & Innovation
- Conduct research on evolving GRC practices, regulatory updates, and technological advancements.
- Identify improvement opportunities and recommend enhancements to existing controls and methodologies.
6. Operational Support
- Support the implementation of GRC initiatives, tools, and controls across countries and business lines.
- Provide subject matter input during audits, risk assessments, and control testing activities.
🌟 You are a match
- Bachelor’s degree in Risk Management, Business Administration, Cybersecurity, or a related field.

- 3–5 years of relevant experience in GRC, cybersecurity compliance, or information risk management in a multinational or regulated environment.
- Certification preferred: CRISC, ISO 27001 Lead Implementer, CISA, or equivalent.

- Certification in Esquema Nacional de Seguridad (ENS) will be a plus.

- Knowledge and experience on global regulatory and industry frameworks (e.g., ISO 27001, NIST, GDPR, LGPD, DORA).
- Familiarity with GRC tools and platforms such as OneTrust, Sandas GRC, GlobalSuite.
- Strong analytical and documentation skills.

- Excellent communication skills and ability to interact with multiple stakeholders (IT, HR, Compliance, C level, Cybersecurity comitee members).
- Proficiency in Microsoft 365 suite.

- Fluent in English and Spanish.
☀️ Why join Pluxee?


Join an inclusive team: work at the heart of the community alongside 5,000 experts across 29 countries - we embrace diversity and value uniqueness, fostering a workplace where everyone can thrive.

Turn inspiration into possibility: get space to try new ideas, experiment and move the world of work forward as you bring new digital experiences - and moments of connection - to millions of people.

Make a positive impact: touch millions of lives and create meaningful change for people and the world we share, supporting our commitments to diversity, sustainability, and local economies.

Grow with us: get support you need to take meaningful steps in your career, whether you're performing your work/life balance or learning new skills.


Why join Pluxee?


Join an inclusive team

Work at the heart of the community alongside 5,000 experts across 29 countries - we embrace diversity and value uniqueness, fostering a workplace where everyone can thrive.

Turn inspiration into possibility

Get space to try new ideas, experiment and move the world of work forward as you bring new digital experiences - and moments of connection - to millions of people.

Make a positive impact

Touch millions of lives and create meaningful change for people and the world we share, supporting our commitments to diversity, sustainability, and local economies.

Grow with us

Get support you need to take meaningful steps in your career, whether you're performing your work/life balance or learning new skills.

Skills Required

  • Bachelor’s degree in Risk Management, Business Administration, Cybersecurity, or a related field
  • 3–5 years of relevant experience in GRC, cybersecurity compliance, or information risk management in a multinational or regulated environment
  • CRISC, ISO 27001 Lead Implementer, CISA, or equivalent certification
  • Knowledge and experience with ISO 27001, NIST, GDPR, LGPD, DORA, and other global regulatory or industry frameworks
  • Familiarity with OneTrust, Sandas GRC, GlobalSuite, or similar GRC tools
  • Strong analytical and documentation skills
  • Excellent communication skills and ability to interact with IT, HR, Compliance, executives, and cybersecurity committee members
  • Proficiency in Microsoft 365
  • Fluency in English and Spanish
  • Esquema Nacional de Seguridad certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Fort Worth, TX
5,636 Employees

What We Do

The leading global employee benefits and engagement partner that opens up a world of opportunities to help people enjoy more of what really matters We believe that living life to the full means making the most of every moment and sharing experiences with the people we care about. To make these experiences meaningful, fulfilling, and personalised, we combine our 45+ years of experience with the agility and energy of a new digital brand. The result is an exciting mix of 250+ products that give employees more freedom in the choices they make every day across 31 countries – from restaurant meals to culture, incentives, and gift vouchers. Are you looking to shape the future of employee benefits and engagement? Get in touch directly with our teams at: [email protected]

Similar Jobs

Mastercard Logo Mastercard

Account Manager

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Madrid, Comunidad de Madrid, ESP
38800 Employees

Pfizer Logo Pfizer

Senior Manager, HTA, Value and Evidence (HV&E), Genitourinary Cancer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
30 Locations
121990 Employees
139K-232K Annually

Cloudflare Logo Cloudflare

Account Manager

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
Spain
4400 Employees

Pfizer Logo Pfizer

MSR Oncology Genitourinary tumors(Cataluña)

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office
5 Locations
121990 Employees

Similar Companies Hiring

Munchkin, Inc. Thumbnail
Consumer Web • eCommerce • Food • Kids + Family • Design • Manufacturing
Milton, Ontario
325 Employees
Hedra Thumbnail
Software • News + Entertainment • Marketing Tech • Generative AI • Enterprise Web • Digital Media • Consumer Web
San Francisco, CA
14 Employees
Bankrate Thumbnail
Artificial Intelligence • Consumer Web • Digital Media • Fintech • Marketing Tech • Software • Financial Services
US
160 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account