Sinclair is Hiring! Join Our Team as a IT Security & Compliance Manager
We are currently recruiting for IT Security & Compliance Manager at our Madrid office.
The ideal candidate will have experience in:
Location: Spain
About Sinclair
Founded in 1971, Sinclair is a global medical aesthetics organisation, that delivers an extensive product range. With an in-house commercial infrastructure, including manufacturing and a network of distributors in leading global markets, our products are sold in 55 countries worldwide.
This is a great time to join Sinclair as we continue to increase our product range and expand into new markets and territories.
Act with Integrity Consistently doing the right thing even when it’s the hard choice; 100% Compliance with all rules, standard operating procedures and guidelines
Results-Driven Make a business impact in all you do, whether sales, efficiency, operational excellence; it should make a meaningful impact
Innovation-Centered Redefining Aesthetics, we must be pioneering in how we do business; this can be in products, in service models, or strategy
One Company, One Goal Working towards unified mission, we are all Sinclair and be seen by customers as one company in every way
Own It! Be Accountable for your decisions, actions and consequences; Be Reliable to your customers and colleagues
Audit response and readiness — primary
- Act as the single point of contact for external audit, group internal audit and finance control reviews: scope agreement, evidence, walkthroughs, management responses.
- Maintain one register of IT-related findings from every source, each with a named owner and a date.
- Report remediation status monthly to the Global IT Director, and at each audit cycle to Finance and to Legal & Compliance.
- Assemble the evidence base before it is asked for: application inventory, system owner matrix, access records, change records, backup and restore records.
Internal controls, built from audit requirements- Turn each agreed finding into a documented, repeatable control: control objective, control owner, frequency, evidence retained.
- Start with what is already known to be required — periodic user access review; segregation of duties in ERP and procure-to-pay; a named System Owner for every application.
- Design controls that can be operated at current headcount. Where one cannot be, record the compensating control and the accepted risk rather than writing a control that will fail its next test.
- Re-test what has been remediated, and close findings on evidence rather than assertion.
Standing compliance duties- Keep the IT policy set current — access, information security and acceptable use, continuity — and aligned to what is actually done.
- Review new and renewed software and services before any commitment is made: data location, processing terms, security, GxP impact, exit terms. Conclusion within five working days.
- Support Legal & Compliance on UK and EU data protection where systems are involved: hosting location, transfers, processing agreements, retention.
- Represent controls in the SAP and workflow programmes — authorisation model, segregation-of-duties rules, approval matrix, audit logging — and sign off before configuration freeze.
Essential:
Five or more years in IT audit, IT compliance or IT risk, within or facing a multi-entity international group.
Has personally run the company side of an IT audit — scope, evidence, management response, remediation through to closure.
Has built and operated IT general controls off the back of findings, not only tested them.
Has owned a user access review and segregation-of-duties cycle across an ERP.
English to full professional standard, written and spoken; right to work in the Netherlands or Spain.
Able to work as the only person in the discipline: sets own priorities and writes own material.
Desirable:
CISA, CRISC, or ISO/IEC 27001 Lead Auditor.
Pharmaceutical, medical device or medical aesthetics experience, including GxP and CSV /computerized system validation.
SAP authorisation concept and segregation-of-duties design.
UK and EU data protection as it applies to systems and vendors.
Competitive Salary
Hybrid/Remote Work Options (if applicable)
Career Growth & Learning Opportunities
Health & Wellness Benefits
Fun Team Events & Supportive Culture
We have a real focus on developing our people, and by fostering an entrepreneurial culture, we encourage flexibility, accountability and autonomy. The company is full of opportunity for those who wish to grasp it. Our people thrive on engagement, development and a varied workload. You will often be included in projects that require you to collaborate cross-functionally.
This is an exciting opportunity to join a successful company, with big ambitions for the future.
If this sounds like you and you meet the requirements, please apply, we would love to hear from you.
Please note if we receive a high volume of applications, we may close the role before the closing date noted.
By making this application you give consent for personal information to be used in automated decision-making processes relating to key job requirements which are stated in this ad.
Sinclair does not accept speculative or unsolicited CVs from Recruitment Agencies. Any unsolicited CVs received will be treated as property of Sinclair and Terms & Conditions associated with the use of such CVs will be considered null and void