IT Security & Compliance Manager
Publicado en 2026-09-23
-
TI/Tecnología
Seguridad cibernética, Seguridad de la Información, Analista de negocios de TI, Consultoría TI
Sinclair is Hiring! Join Our Team as a IT Security & Compliance Manager 🚀
We are currently recruiting for IT Security & Compliance Manager at our Madrid office.
The ideal candidate will have experience in:
ITGC
SoD
ERP Controls
Location:
Spain
About Sinclair
Founded in 1971, Sinclair is a global medical aesthetics organisation, that delivers an extensive product range. With an in-house commercial infrastructure, including manufacturing and a network of distributors in leading global markets, our products are sold in 55 countries worldwide.
This is a great time to join Sinclair as we continue to increase our product range and expand into new markets and territories.
Sinclair Values:✅ Act with Integrity Consistently doing the right thing even when it’s the hard choice; 100% Compliance with all rules, standard operating procedures and guidelines
✅ Results-Driven Make a business impact in all you do, whether sales, efficiency, operational excellence; it should make a meaningful impact
✅ Innovation-Centered Redefining Aesthetics, we must be pioneering in how we do business; this can be in products, in service models, or strategy
✅ One Company, One Goal Working towards unified mission, we are all Sinclair and be seen by customers as one company in every way
✅ Own It! Be Accountable for your decisions, actions and consequences;
Be Reliable to your customers and colleagues
🔹 Audit response and readiness — primary
• Act as the single point of contact for external audit, group internal audit and finance control reviews: scope agreement, evidence, walkthroughs, management responses.
• Maintain one register of IT-related findings from every source, each with a named owner and a date.
• Report remediation status monthly to the Global IT Director, and at each audit cycle to Finance and to Legal & Compliance.
• Assemble the evidence base before it is asked for: application inventory, system owner matrix, access records, change records, backup and restore records.
🔹Internal controls, built from audit requirements
• Turn each agreed finding into a documented, repeatable control: control objective, control owner, frequency, evidence retained.
• Start with what is already known to be required — periodic user access review; segregation of duties in ERP and procure-to-pay; a named System Owner for every application.
• Design controls that can be operated at current headcount. Where one cannot be, record the compensating control and the accepted risk rather than writing a control that will fail its next test.
• Re-test what has been remediated, and close findings on evidence rather than assertion.
🔹Standing compliance duties
• Keep the IT policy set current — access, information security and acceptable use, continuity — and aligned to what is actually done.
• Review new and renewed software and services before any commitment is made: data location, processing terms, security, GxP impact, exit terms. Conclusion within five working days.
• Support Legal & Compliance on UK and EU data protection where systems are involved: hosting location, transfers, processing agreements, retention.
• Represent controls in the SAP and workflow programmes — authorisation model, segregation-of-duties rules, approval matrix, audit logging — and sign off before configuration freeze.
Your skills and experienceEssential:
🔹Five or more years in IT audit, IT compliance or IT risk, within or facing a multi-entity international group.
🔹Has personally run the company side of an IT audit — scope, evidence, management response, remediation through to closure.
🔹 Has built and operated IT general controls off the back of findings, not only tested them.
🔹Has owned a user access review and segregation-of-duties cycle across an ERP.
🔹English to full…
(Si este trabajo está en su jurisdicción, entonces puede estar usando un Proxy o VPN para acceder a este sitio, para seguir avanzando, debe cambiar su conectividad a otro dispositivo móvil o PC).