9 дней назад
Third-Party Cyber Assurance Supervisor (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Third-Party Cyber Assurance Supervisor (Cybersecurity): Assessing and improving the cybersecurity posture of critical suppliers through risk-based assessments, onsite inspections, and technical evaluations with an accent on third-party risk, operational resilience, DORA, and data-centre security. Focus on translating control weaknesses into business risks, evaluating security testing results, producing executive dashboards, and identifying automation opportunities through agentic artificial intelligence.
Location: Madrid, Spain; hybrid work with days at home and at the MAD office. Travel may be required for assessments for approximately 6–8 weeks per year.
Company
Hubs Spain is a newly established technology and operations hub support ’s bank solutions, cybersecurity capabilities, and global customer base.
What you will do
- Lead, plan, and execute risk-based cybersecurity assessments and onsite inspections of critical third-party providers.
- Evaluate supplier security governance, technology controls, operational resilience, risk management practices, and control effectiveness.
- Conduct interviews, documentation reviews, field inspections, configuration assessments, technical security evaluations, and data-centre inspections.
- Identify cybersecurity risks, control weaknesses, and vulnerabilities, then translate technical finds into business risks and actionable recommendations.
- Support the evaluation of penetration test and red-team results, and produce professional reports and executive-ready dashboards.
- Collaborate with global security, risk, procurement, operations, and audit teams while coach new team members and implement automation opportunities through agentic AI.
Requirements
- Bachelor’s or Master’s degree in Computer Science, Information Security, Cybersecurity, IT Engineer, IT Risk Management, IT Audit, or a related field.
- 7–9 years of experience in cybersecurity, IT audit, cyber risk management, third-party risk management, information security, or a similar area.
- Strong knowledge of cybersecurity technologies and architecture, IT processes, COBIT, ISO 27001, ISO 22001, risk management, governance frameworks, and the Three Lines Model.
- Knowledge of operat systems, networks, databases, identity and access management, cloud and web technologies, software development practices, and containerization.
- Experience with audits, cybersecurity assessments, supplier reviews, or risk evaluations, combined with strong analytical, problem-solv, communication, and stakeholder-management skills.
- Fluency in English, written and spoken, and the ability to work in multicultural and international environments.
Nice to have
- Experience in bank or financial services, operational resilience, or third-party risk management.
- Experience with penetration test, red team, vulnerability assessments, or technical security test.
- Knowledge of DORA, NIST Cybersecurity Framework, ISO 27001, SOC 2, cloud security frameworks, NIS2, and other EU regulatory frameworks.
- Hands-on experience with Nessus, Burp Suite, Kali Linux, Wireshark, Docker, script, data analytics, or automation tools.
- CISSP, CISA, CEH, OSCP, or ISO 27001 Lead Auditor certification.
Culture & Benefits
- Flexible hybrid model with shared accountability for choos home and office days.
- Health insurance for the employee and family, plus life insurance.
- Restaurant card, transport allowance, flexible remuneration, and access to train support.
- Pension plan available after one month of employment.
- Office facilities include electric mobility solutions, a doctor, hairdresser, gym, and personal-services support.
- International, inclusive, agile, and technology-focused environment with opportunities to shape a grow cybersecurity hub.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
10 дней назад
Third Party Assurance Supervisor (Cybersecurity)
12 дней назад
Cyber Security Architect (IT/OT)
10 дней назад
IT Audit Specialist (Fintech)
12 дней назад
Application & Cloud Security Consultant (Cybersecurity)
10 дней назад
Senior Platform Security Engineer (AI)
11 дней назад