Назад
Company hidden
2 дня назад

Risk Technology Risk & Cybersecurity Specialist III (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
c1
Страна
Spain
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Analyst — Cybersecurity Risk (2LoD) (Cybersecurity Risk): Leading independent oversight of cybersecurity risk assessments, control evaluations, third-party services, and digital transformation within a global bank with an accent on risk challenge, cyber resilience, and regulated financial-services environments. Focus on reviewing IAM, cloud security, vulnerability management, incident response, and governance reporting while driving remediation to closure.

Location: Boadilla del Monte, Spain; hybrid work with some days remote and some days onsite.

Company

Global banking group hirify.global provides corporate and investment banking services to complex corporate and institutional clients through hirify.global Corporate & Investment Banking.

What you will do

  • Lead second-line-of-defense reviews and challenge cybersecurity risk assessments, control evaluations, metrics, mitigation plans, and risk acceptances.
  • Conduct targeted reviews across IAM, network and firewall security, vulnerability management, cloud security, application security, encryption, DLP, monitoring, and incident response.
  • Provide independent cyber-risk oversight for digital transformation and business change from design through go-live.
  • Strengthen third-party and critical-services risk management by assessing vendors, assigning residual risk ratings, and tracking remediation.
  • Analyze incidents, KRIs, control gaps, and risk-register data to identify emerging hotspots and concentrations.
  • Develop policies and frameworks and prepare decision-ready governance reporting for committees and working groups.

Requirements

  • 5–8 years of experience in cybersecurity risk, technology risk, cyber audit, or second-/third-line-of-defense roles in financial services or other highly regulated environments.
  • Bachelor’s degree in Computer Science, Engineering, or a related field.
  • Professional certifications such as CISA, CISM, CRISC, or CISSP are strongly valued; cloud-security certifications across AWS, Azure, or GCP are required.
  • Fluent English required.
  • Experience with NIST CSF, ISO 27001/22301, COBIT, SOC 2/ISAE 3000, OWASP, and cyber-risk oversight programs.
  • Strong risk judgment, documentation skills, cross-team coordination, and the ability to influence stakeholders and drive issues to closure.

Nice to have

  • Master’s degree.
  • Experience in an international, matrixed organization.

Culture & Benefits

  • Hybrid working model with flexible hours.
  • Training, certification support, and access to extensive learning platforms.
  • Performance-based bonuses and competitive rewards.
  • Preferential banking terms, life insurance, childcare support, and family-friendly programs.
  • Wellness, medical, gym, meal subsidy, parking, shuttle, and employee discount programs.

Hiring process

  • Submit an application for consideration.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →