Security Compliance and Privacy Specialist

Sporty Group
Sporty Group
EMEAPresencialCompetitivoPublicado hace 3 días
🇬🇧Inglés requeridoIt & is

Anuncio original

About the role

Establish and operate a Sporty Group-wide security and privacy baseline by building and coordinating a Group ISMS and Group PIMS. Ensure consistent security and privacy governance across all group companies while enabling regional teams to meet local regulatory requirements.


What You'll Be Doing

  • Define and maintain the Sporty Group global security and privacy baseline, including policies, control framework, and minimum requirements applicable across all group companies.
  • Design and operate the Group ISMS and Group PIMS, coordinating regional ISMS and privacy programs without duplicating local ownership.
  • Establish a clear global baseline plus local add-ons operating model, with defined RACI, exception handling, and escalation paths.
  • Coordinate group-level governance by consolidating regional BDM/PM-owned compliance calendars into a single group view, aligning milestones, reporting cadence, and evidence standards.
  • Maintain the group-level risk register, Statement of Applicability, and control mappings, ensuring traceability between risks, controls, owners, and evidence.
  • Coordinate internal audits and findings management at group level, tracking remediation and closure across regions.
  • Define and standardize privacy operations at group level, including RoPA inputs, DPIA workflows, retention and deletion evidence standards, and breach readiness coordination with Legal and Security.
  • Build and maintain a central evidence library, mapped once to the group control set and reused across ISO, PCI-DSS, and privacy frameworks.
  • Standardize third-party security and privacy compliance artifacts, including questionnaires, minimum requirements, and evidence packages, in coordination with Legal and Procurement.
  • Track regulatory and standard changes and translate them into clear, scoped updates to the group baseline, with owners and timelines.

    What You'll Bring
  • Proven experience operating ISO 27001 programs in practice, including risk management, SoA maintenance, and audit cycles.
  • Practical experience with privacy frameworks and regulations, including GDPR and at least one additional jurisdiction (e.g., LGPD or Nigeria).
  • Strong program coordination skills across multiple regions, teams, and time zones.
  • Ability to translate regulatory requirements into clear, actionable controls without creating unnecessary overhead.
  • Strong written communication skills, able to produce concise policies, standards, and guidance.

    Technology / Domain Expertise


ISO 27001, ISO 27701, privacy management practices, PCI-DSS evidence coordination, risk registers, audit and evidence management, GRC tooling (nice to have).

What's in it for you

  • Sporty is a remote first company in pursuit of sustainability
  • A competitive salary + individual performance based bonuses every quarter
  • 28 days paid annual leave
  • Our core working hours are 10am-3pm in your local time zone with flexibility outside of this
  • Referral bonuses & flash bonuses
  • Top of the line equipment
  • Annual company retreats to provide great internal networking opportunities

Interview Process

  • Remote video screening with our Talent Acquisition Team 
  • Online assessment via Hackerrank
  • Remote video interview with Team Members (60 Mins)
  • Final discussion with the hiring manager (60 mins)

If you're interested, we encourage you to apply! Every application is reviewed by a member of our team (AI is not used in our recruitment process), and we aim to respond within 48 hours.

Remoto

Identity & PAM Security Engineer

Europe - Remote
1sem
Remoto

Software Development Engineer in Test

EMEA - Remote
2sem
Remoto

Backend Software Engineering Team Lead - OpsTech

Europe - Remote
3sem
Remoto

Purple Operations Engineer

Europe - Remote
3sem
Remoto

QA Lead Engineer (Europe only)

Global - Remote
1m
Remoto

Frontend Engineering Team Lead

Europe - Remote
1m
Remoto

Performance Marketing Manager, Paid Social

EMEA - Remote
3m
Remoto

Database Reliability Engineer

Europe - Remote; LATAM - Remote
3m

Tech_Cybersecurity Consultant (Compliance)

Madrid
Nuevo

Tech_Data Protection & Compliance Specialist for BeTerna

Madrid
Nuevo

CIB Legal Markets

Boadilla del Monte
Nuevo

Regulatory Data and Documentation Specialist

Barcelona
Nuevo

Abogado/a Laboralista - Lugo

Lugo, Lugo
59 mil € - 90 mil €Nuevo

Abogado/a Laboralista - Ourense

Ourense, Ourense
59 mil € - 90 mil €Nuevo

Abogado/a especializado en Derecho laboral - Valencia/València

Albalat dels Sorells, Valencia/València
59 mil € - 90 mil €Nuevo

Corporate Governance Legal Trainee

Islas baleares
Nuevo

Legal Secretary | Evening Pool

Madrid
Nuevo

Senior Manager Abogado/a Laboralista

Madrid
Nuevo
Remoto

Lifecycle Specialist, Employee Relations and Transitions - EMEA

Remote-EMEA
37 mil US$ - 84 mil US$1d

Engineering Manager, Mapping Platform

EMEA
3d

Product Manager

EMEA
150 mil US$ - 169 mil US$6d

Channel Partner Sales Executive, UKI

Home based - EMEA
6d

Senior Product Designer

EMEA
60 mil US$ - 168 mil US$1sem
Remoto

Benefits Operations Specialist - EMEA

Remote-EMEA
35 mil US$ - 79 mil US$1sem

Sales Enablement Manager

Home based - EMEA
1sem
Remoto

Software Development Engineer in Test

EMEA - Remote
2sem
Remoto

Senior Customer Success Manager

Americas / Massachusetts, United States / EMEA / Spain
180 mil US$2sem
Remoto

Senior Paid User Acquisition Strategist

Americas / Massachusetts, United States / EMEA / Spain / APAC / South Korea
185 mil US$2sem
Remoto

Senior Content Marketing Manager, Narrative & Comms

APAC / South Korea / EMEA / Spain
155 mil US$3sem
Remoto

Senior Information Security Engineer - Application Security

Remote / EMEA / USEAST
144 mil US$3sem

Candidatura gestionada por Sporty Group