Назад
Company hidden
2 дня назад

Senior Third-Party Cyber Assurance Expert (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
Spain
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Senior Third-Party Cyber Assurance Expert (Cybersecurity): Assessing and managing cybersecurity risks from external suppliers for a global banking infrastructure with an accent on risk-based technical assessments and regulatory compliance. Focus on evaluating supplier control effectiveness, conducting onsite inspections, and translating technical gaps into business risks.

Location: Hybrid in Madrid, Spain

Company

A global technological hub for ING, designing and delivering secure, scalable technological and operational solutions for millions of customers across 38 countries.

What you will do

  • Execute risk-based cybersecurity assessments and onsite inspections of critical third-party providers globally.
  • Evaluate the design and effectiveness of supplier cybersecurity controls, governance, and operational resilience.
  • Conduct technical evaluations, documentation reviews, and interviews to identify vulnerabilities and risks.
  • Translate technical findings into actionable business risks and executive-ready reports/dashboards.
  • Collaborate with global CISO, procurement, architecture, and audit teams.
  • Align third-party risk management with DORA and other EU regulatory frameworks.

Requirements

  • Bachelor's or Master's degree in Computer Science, Cybersecurity, IT Audit, or related disciplines.
  • 3-6 years of professional experience in Cybersecurity, IT Audit, or Cyber Risk Management.
  • Strong understanding of cybersecurity architectures, networks, and cloud technologies.
  • Experience performing supplier reviews, cybersecurity assessments, or risk evaluations.
  • Fluency in English, both written and spoken.
  • Ability to work in a hybrid model based in Madrid, Spain.

Nice to have

  • Experience within the banking or financial services sector.
  • Certifications such as CISSP, CISA, CISM, CRISC, or OSCP.
  • Knowledge of DORA, NIST, ISO 27001, SOC 2, or NIS2.
  • Hands-on experience with tools like Nessus, Burp Suite, Kali Linux, or Wireshark.
  • Experience with penetration testing, red teaming, or vulnerability assessments.

Culture & Benefits

  • Flexible hybrid work model balancing home and office presence.
  • Comprehensive health and life insurance for the employee and their family.
  • Financial perks including a restaurant card, transport allowance, and pension plan.
  • Flexible remuneration model for tax-advantaged services (nursery, training aids, etc.).
  • Modern office amenities including a gym, doctor, and hairdresser.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →