You're seeing this page as if you were . The main menu is still yours, though. Exit from immersion
Tomás Miguel HerreroTM

Tomás Miguel Herrero

Compliance & Risk Expert

560 €/día
Barcelona, ES
8-15 años

Tiempo medio de respuesta: 1h

Acerca de Tomás Miguel

Compliance & Risk Expert with 10+ years in regulated industries (Fintech, Agribusiness, Oil & Gas, Retail, Pharmaceuticals). Skilled in CMS, ISMS, audit frameworks, and corporate governance. Expertise in regulatory risk, process optimization, and digital transformation, ensuring compliance with ISO/PCI/Regional standards, AML/CFT, and sector mandates.
  • Español

    Bilingüe o nativo

  • Inglés

    Bilingüe o nativo

  • Portugués

    Competencia profesional completa

  • Francés

    Competencia profesional completa

Acepta trabajo presencial
Barcelona (hasta 50 km)

Experiencia

  • Onebox
    Information Security, Risk & Compliance Specialist
    enero de 2025 - Hoy (1 año y 6 meses)
    Led ISO 27001:2022, ISO 27701, ENS (Spain), and Omologazione (Italy) certifications, integrating information security and privacy into a unified ISMS deployed across 14 countries in LATAM and EMEA. Coordinated internal and external audits achieving on-time certification. Drove PCI DSS v4.0 compliance for ticketing payment infrastructure, managing the QSA audit process and obtaining certification as Merchant and Service Provider. Designed an enterprise-wide Compliance Management System based on the Three Lines of Defense model, defining roles, controls, and governance structures. Developed and implemented a Criminal Liability Prevention Model (MPDP), establishing risk maps, internal controls, disciplinary protocols, and reporting channels to mitigate corporate criminal exposure across all operating jurisdictions.
    PCI DSS ISO 27001 ISO 27701 Risk Management Governance, Risk and Compliance
  • Nemuru
    Operations & Compliance Coordinator
    enero de 2020 - enero de 2025 (5 años)
    Developed and enforced AML/CFT compliance policies, including risk assessments, transaction monitoring, CDD/EDD measures, and SAR filings. Managed ISMS and ISO 27001/27701 certifications, ensuring compliance with data protection standards and achieving a 20% reduction in security incidents. Led compliance risk management by establishing RCSA matrices, conducting gap analyses, and executing remediation plans, resolving 80% of audit findings. Implemented a control framework under the Three Lines of Defense model, using a RACI matrix to define roles for risk ownership, oversight, and independent assurance across the organization.
    AML AML/CFT ISO 27001
  • Ernst & Young,
    Strategy, Operations & Compliance Consultant
    enero de 2017 - enero de 2019 (2 años)
    Provided regulatory compliance and risk management advisory across agribusiness, retail, pharmaceuticals, and energy, ensuring adherence to sector-specific regulations, governance frameworks, and international standards. Optimized financial compliance in the agribusiness sector through transaction monitoring, supply chain due diligence, and regulatory assessments, achieving a 70% improvement in audit conformity. Automated regulatory controls in the retail industry via BPMN, enhancing workflow standardization and audit traceability, resulting in a 25% reduction in compliance deviations. Developed enterprise risk frameworks in the pharmaceuticals sector, integrating quantitative risk modeling and internal control structures to mitigate 85% of systemic compliance risks. Implemented compliance training programs across the energy industry, strengthening regulatory awareness, audit procedures, and risk mitigation strategies throughout all operating jurisdictions.
    Regulatory Compliance Governance, Risk and Compliance

Recomendaciones

Sé el primero en recomendar a Tomás Miguel

Ayuda a este freelance a destacar compartiendo tu experiencia.

Estos perfiles de freelance también coinciden con tus criterios

AgathaA

Agatha Frydrych

Backend Java Software Engineer

4.7

(3)

2

BaptisteB

Baptiste Duhen

Fullstack developer

4.6

(4)

5

AmedA

Amed Hamou

Senior Lead Developer

4

(2)

7

AudreyA

Audrey Champion

Web developer

4.3

(3)

4

Formación

  • Master Compliance Officer
    UCM – Universidad Complutense de Madrid
    2025
    Master Compliance Officer
  • Interna�onal Diploma in Sustainability and ESG Analysis
    CapacitaRSE - Execu�ve Educa�on Center
    2018
    Interna�onal Diploma in Sustainability and ESG Analysis

Certificados

Conjunto de habilidades profesionales

Categorías