About the job
OneTrust develops technology that supports responsible data and AI practices. Since 2016, the company has helped organizations manage data ethically while maintaining momentum in innovation. The AI-Ready Governance Platform™ combines regulatory insights, automation, and unified workflows to help businesses worldwide ensure data reliability and responsible growth.
Role overview
The Information Security Governance, Risk, and Compliance (GRC) Analyst works within the InfoSec GRC group, collaborating with IT and Information Security teams. The analyst manages a variety of governance, risk, and compliance activities to support OneTrust’s security posture.
Main responsibilities
-
Customer Security Assurance & Questionnaires
- Manage a large volume of customer security questionnaires (CAQs), RFP security sections, and assurance documents such as SIG, CAIQ, and custom questionnaires from start to finish.
- Deliver accurate, consistent responses using internal resources, including SOC reports, ISO certifications, company policies, standards, network diagrams, and penetration test summaries.
- Coordinate with teams across Sales, Marketing, Customer Success, Security, Engineering, Privacy, Legal, Compliance, and Product to confirm information and resolve any discrepancies.
-
Customer Engagement & Security Discussions
- Communicate directly with customers and prospects about security controls, risk management practices, and compliance needs.
- Present security topics clearly, adapting the level of detail for both technical and non-technical audiences.
- Assist Sales and Customer Success teams by addressing security concerns, clarifying audit scopes, and supporting procurement activities.
Location
This role is based in Madrid, Spain.

