SlipstreamJobsFresh Startup & VC-Backed Jobs

Information Security Assurance analyst

OneTrust - Madrid, Spain - In-office - posted 2026-08-31

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

OneTrust is seeking an Information Security Assurance Analyst to join its GRC (Governance, Risk, and Compliance) team in Madrid. The role focuses on enabling responsible innovation through trusted data and AI governance. Key responsibilities include: **Customer Security Assurance & Questionnaires**: Own end-to-end completion of high-volume customer security questionnaires (CAQs), RFP security sections, and assurance artifacts (SOC reports, ISO certificates, policies, pen test summaries). Provide accurate, defensible responses by leveraging internal evidence repositories and partnering with cross-functional stakeholders (Sales, Marketing, Customer Success, Security, Engineering, Privacy, Legal, Compliance, Product) to validate responses and resolve gaps. **Customer Engagement & Security Discussions**: Meet with customers and prospects to explain security controls, risk posture, and compliance commitments. Present security topics with confidence to both technical and non-technical audiences. Support Sales and Customer Success by addressing security objections, clarifying audit scope, and enabling procurement cycles. **Contract & Security Review**: Perform security reviews of contracts, Data Processing Agreements (DPAs), security addendums, and customer security terms. Identify security requirements, non-standard obligations, and risk areas; propose mitigations and collaborate with Legal and Security leadership on negotiation positions. Track contractual security commitments to ensure operational feasibility and control alignment. **Operational Excellence**: Improve team efficiency through standardization, playbooks, and continuous refinement of response libraries. Manage and prioritize high-volume concurrent requests with accuracy while meeting SLAs. Contribute to internal readiness by keeping evidence current, identifying documentation gaps, and recommending process improvements. **Required Experience**: 3-6 years in information security, security compliance, GRC, security assurance, third-party risk, or customer trust functions. Demonstrated experience responding to customer security questionnaires and security due diligence requests. Familiarity with SOC 2, ISO 27001, NIST, CIS, PCI DSS, HIPAA, GDPR. Strong understanding of security fundamentals (access control, encryption, vulnerability management, secure SDLC, incident response, logging/monitoring, vendor risk). Excellent written and verbal communication skills with strong organizational abilities. **Preferred Qualifications**: Industry certifications (CISA, CISM or equivalent). Experience reviewing/negotiating security contract terms and assurance language. Background in SaaS/cloud security assurance or supporting enterprise customers.

Similar roles