Skip to content

Farfetch

GRC Specialist

Location
Porto, PT
Arrangement
Hybrid
Employment type
Full-time
Posted
29 September 2026 (2 days ago)

Checked todayApplications go to the employer, never to RoleSprint

About this role

Farfetch is a leading global marketplace for the luxury fashion industry. The Farfetch Marketplace connects customers in over 190 countries and territories with items from more than 50 countries and over 1,400 of the world’s best brands, boutiques, and department stores, delivering a truly unique shopping experience and access to the most extensive selection of luxury on a global marketplace.

TECHNOLOGY We're on a mission to build end-to-end products and technology that powers the an incredible e-commerce experience for luxury customers everywhere, understanding the motivations and needs of our customers and partners, to designing and testing hypotheses, to creating industry-leading experiences for luxury customers.

PORTO Our office is near Porto, in the north of Portugal, and is located in a vibrant business hub. It offers a dynamic and welcoming environment where our employees can connect and network with a large community of tech professionals.

THE ROLE We're looking for a Cyber Governance, Risk and Compliance Specialist to join our Information Security team. In this role, you'll help strengthen Farfetch's cybersecurity governance, risk management, and compliance practices, ensuring our security policies, controls, and processes align with business needs, regulatory requirements, and industry standards. You'll work closely with stakeholders across the business to identify and assess security risks, monitor compliance, support audits and assessments, and continuously improve Farfetch's Information Security framework.

WHO YOU ARE • You have a degree in Computer Science, Information Security, or a related field.

• You have a background in software development or systems administration.

• You have more than 4 years of experience in a similar Information Security, GRC, Risk, or Compliance role.

• You have a good understanding of network protocols, design, and operations.

• You have working knowledge of Information Security principles, techniques, and technologies.

• You have experience with Information Security governance frameworks and standards, such as COBIT and ISO 27001.

• You have experience reviewing security policies and procedures, managing documentation, and performing gap analyses.

• You have a good understanding of risk assessment methodologies, such as OCTAVE and NIST SP 800-30.

• Certifications in Information Security, such as CRISC, CISA, CEH, or similar, are a plus.

• Experience with Data Privacy Impact Assessments (DPIAs) is a plus.

• Experience working on AI and Data Governance projects is a plus.

• You have strong English communication skills, both written and verbal.

• You're self-motivated, proactive, and comfortable working with minimal supervision

WHAT YOU'LL DO • Support the development, implementation, and continuous improvement of Farfetch's Information Security governance framework.

• Recommend and implement changes to strengthen security controls and reduce the risk of unauthorized access.

• Review, maintain, and audit Information Security policies, procedures, and related documentation.

• Monitor compliance with applicable legal, regulatory, and industry standards and requirements.

• Perform Information Security risk assessments and other security reviews, identifying gaps and supporting the definition of appropriate mitigation actions.

• Support audits, compliance assessments, and gap analyses across the Information Security landscape.

• Coordinate and monitor company-wide Information Security controls to help protect the integrity of Farfetch's assets.

• Contribute to increasing Information Security awareness across the business.

• Collaborate with internal stakeholders to ensure security risks, controls, policies, and compliance requirements are effectively managed.

• Contribute to Information Security initiatives involving areas such as Data Privacy, AI Governance, and Data Governance.

REWARDS & BENEFITS • Health insurance for the whole family, flexible working environment and well-being support and tools

• Extra days off, sabbatical program and days for you to give back for the community

• Training opportunities and free access to Udemy

• Flexible benefits program

EQUAL OPPORTUNITIES STATEMENT • Farfetch is an equal opportunities employer ensuring that all applicants are treated equally and fairly throughout our recruitment process. We are determined that no applicant experiences discrimination on the basis of sex, race, ethnicity, religion or belief, disability, age, gender identity, ancestry, sexual orientation, veteran status, marriage and civil partnership, pregnancy and maternity, or any other basis prohibited by applicable law.

SCAM DISCLAIMER • It has come to our attention that there may be fraudulent activities involving individuals or organizations falsely claiming to represent Farfetch in order to attract candidates to a SCAM. Please be aware that Farfetch does not conduct recruitment processes through messaging apps or any unofficial communication channels, other than our official careers website. Additionally, Farfetch will never ask candidates for any form of payment during the recruitment process.

Work location

  • Porto, PT

Related jobs

Ready to make a decision?

This role is either worth your time or it isn’t.

Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.

Nothing is submitted automatically. You choose what happens next.

About this listing

Advertised by Farfetch and published on Lever, the applicant tracking system they use.

RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.

Published 29 September 2026, last checked today. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.

Browse all current openings

No credit card requiredStart free