Senior Third-Party Cyber Assurance Expert (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Third-Party Cyber Assurance Expert (Cybersecurity): Assessing and managing cybersecurity risks from external suppliers for a global banking infrastructure with an accent on risk-based technical assessments and regulatory compliance. Focus on evaluating supplier control effectiveness, conducting onsite inspections, and translating technical gaps into business risks.
Location: Hybrid in Madrid, Spain
Company
A global technological hub for ING, designing and delivering secure, scalable technological and operational solutions for millions of customers across 38 countries.
What you will do
- Execute risk-based cybersecurity assessments and onsite inspections of critical third-party providers globally.
- Evaluate the design and effectiveness of supplier cybersecurity controls, governance, and operational resilience.
- Conduct technical evaluations, documentation reviews, and interviews to identify vulnerabilities and risks.
- Translate technical findings into actionable business risks and executive-ready reports/dashboards.
- Collaborate with global CISO, procurement, architecture, and audit teams.
- Align third-party risk management with DORA and other EU regulatory frameworks.
Requirements
- Bachelor's or Master's degree in Computer Science, Cybersecurity, IT Audit, or related disciplines.
- 3-6 years of professional experience in Cybersecurity, IT Audit, or Cyber Risk Management.
- Strong understanding of cybersecurity architectures, networks, and cloud technologies.
- Experience performing supplier reviews, cybersecurity assessments, or risk evaluations.
- Fluency in English, both written and spoken.
- Ability to work in a hybrid model based in Madrid, Spain.
Nice to have
- Experience within the banking or financial services sector.
- Certifications such as CISSP, CISA, CISM, CRISC, or OSCP.
- Knowledge of DORA, NIST, ISO 27001, SOC 2, or NIS2.
- Hands-on experience with tools like Nessus, Burp Suite, Kali Linux, or Wireshark.
- Experience with penetration testing, red teaming, or vulnerability assessments.
Culture & Benefits
- Flexible hybrid work model balancing home and office presence.
- Comprehensive health and life insurance for the employee and their family.
- Financial perks including a restaurant card, transport allowance, and pension plan.
- Flexible remuneration model for tax-advantaged services (nursery, training aids, etc.).
- Modern office amenities including a gym, doctor, and hairdresser.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →