2 дня назад
Risk Technology Risk & Cybersecurity Specialist III (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Analyst — Cybersecurity Risk (2LoD) (Cybersecurity Risk): Leading independent oversight of cybersecurity risk assessments, control evaluations, third-party services, and digital transformation within a global bank with an accent on risk challenge, cyber resilience, and regulated financial-services environments. Focus on reviewing IAM, cloud security, vulnerability management, incident response, and governance reporting while driving remediation to closure.
Location: Boadilla del Monte, Spain; hybrid work with some days remote and some days onsite.
Company
Global banking group provides corporate and investment banking services to complex corporate and institutional clients through Corporate & Investment Banking.
What you will do
- Lead second-line-of-defense reviews and challenge cybersecurity risk assessments, control evaluations, metrics, mitigation plans, and risk acceptances.
- Conduct targeted reviews across IAM, network and firewall security, vulnerability management, cloud security, application security, encryption, DLP, monitoring, and incident response.
- Provide independent cyber-risk oversight for digital transformation and business change from design through go-live.
- Strengthen third-party and critical-services risk management by assessing vendors, assigning residual risk ratings, and tracking remediation.
- Analyze incidents, KRIs, control gaps, and risk-register data to identify emerging hotspots and concentrations.
- Develop policies and frameworks and prepare decision-ready governance reporting for committees and working groups.
Requirements
- 5–8 years of experience in cybersecurity risk, technology risk, cyber audit, or second-/third-line-of-defense roles in financial services or other highly regulated environments.
- Bachelor’s degree in Computer Science, Engineering, or a related field.
- Professional certifications such as CISA, CISM, CRISC, or CISSP are strongly valued; cloud-security certifications across AWS, Azure, or GCP are required.
- Fluent English required.
- Experience with NIST CSF, ISO 27001/22301, COBIT, SOC 2/ISAE 3000, OWASP, and cyber-risk oversight programs.
- Strong risk judgment, documentation skills, cross-team coordination, and the ability to influence stakeholders and drive issues to closure.
Nice to have
- Master’s degree.
- Experience in an international, matrixed organization.
Culture & Benefits
- Hybrid working model with flexible hours.
- Training, certification support, and access to extensive learning platforms.
- Performance-based bonuses and competitive rewards.
- Preferential banking terms, life insurance, childcare support, and family-friendly programs.
- Wellness, medical, gym, meal subsidy, parking, shuttle, and employee discount programs.
Hiring process
- Submit an application for consideration.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
Senior IT Risk Officer (Cybersecurity)
1 день назад
Vulnerability Management Analyst (Cybersecurity)
5 дней назад
Senior Enterprise Security Architect (Cybersecurity)
7 часов назад
Cybersecurity Engineer (Vulnerability Management)
4 дня назад
Infrastructure Security Engineer
42 800 - 77 000€
20 часов назад
Senior Security Architect (Cybersecurity)
60 000 - 100 000€