10 дней назад
Third Party Assurance Supervisor (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Third Party Assurance Supervisor (Cybersecurity): Assessing and improving the cybersecurity posture of critical third-party providers supporting ING's global banking operations with an accent on supplier assurance, technical security assessments, operational resilience, and regulatory compliance. Focus on leading risk-based inspections, evaluating controls and data centre security, translating technical gaps into business risks, and identifying automation opportunities through agentic artificial intelligence.
Location: Madrid, Spain, with a hybrid schedule combining work from home and the ING MAD office; travel of approximately 6–8 weeks per year may be required.
Company
Spain is a new technology and operations hub supporting secure, scalable banking solutions for ING customers across more than 38 countries.
What you will do
- Lead, plan, organize, and execute risk-based cybersecurity assessments and onsite inspections of critical third-party providers.
- Evaluate supplier security governance, technology controls, operational resilience, and risk management practices.
- Conduct interviews, documentation reviews, configuration assessments, field inspections, technical evaluations, and data centre security inspections.
- Identify cybersecurity risks and control weaknesses, then translate technical gaps into business risks and actionable recommendations.
- Review security testing activities, including penetration testing and red teaming results, and prepare reports and executive dashboards.
- Collaborate with global security, risk, procurement, operations, and audit teams while contributing to DORA objectives, continuous improvement, coaching, and automation initiatives.
Requirements
- Bachelor’s or Master’s degree in Computer Science, Information Security, Cybersecurity, IT Engineering, IT Risk Management, IT Audit, or a related field.
- 7–9 years of experience in cybersecurity, IT audit, cyber risk management, third-party risk management, information security, or a related area.
- Strong knowledge of cybersecurity technologies and architecture, IT processes, COBIT, ISO 27001, ISO 22001, risk management, governance frameworks, and the Three Lines Model.
- Knowledge of operating systems, networks, databases, identity and access management, cloud, web technologies, software development practices, and containerization.
- Experience with audits, cybersecurity assessments, supplier reviews, or risk evaluations, together with strong analytical, communication, stakeholder management, and influencing skills.
- Fluent English, written and spoken, and the ability to work effectively in multicultural and international environments.
Nice to have
- Banking or financial services experience, especially in operational resilience or third-party risk management.
- Experience with penetration testing, red teaming, vulnerability assessments, or technical security testing.
- Knowledge of DORA, NIST Cybersecurity Framework, ISO 27001, SOC 2, cloud security frameworks, NIS2, and other EU regulatory frameworks.
- Experience with Nessus, Burp Suite, Kali Linux, Wireshark, Docker, scripting, data analytics, or automation tools.
- CISSP, CISA, CEH, OSCP, or ISO 27001 Lead Auditor certification.
Culture & Benefits
- Hybrid work model based on flexibility and accountability.
- Health insurance for the employee and family, life insurance, and a pension plan available after one month.
- Restaurant card, transport allowance, and flexible remuneration for services such as childcare, transport, and training.
- Office facilities including electric mobility solutions, medical services, a hairdresser, gym, and practical support services.
- International, collaborative, agile, tech-first environment focused on diversity, inclusion, sustainability, and continuous learning.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →