30 jul
|
PVH (Tommy Hilfiger/Calvin Klein)
|
Madrid
30 jul
PVH (Tommy Hilfiger/Calvin Klein)
Madrid
At ING Hubs Spain we are looking for a Senior Third-Party Cyber Assurance Expert Your role and work environment: At ING Hubs Spain, we are building a new Cybersecurity organization from the ground up. This is a unique opportunity to join a recently established and fast-growing international Hub, where you will not only contribute to Third-Party Cyber Risk Management activities but also help shape the future capabilities, processes, and culture of the team. As a Senior Third-Party Cyber Assurance Expert , you will play a key role in protecting ING against cyber risks arising from external suppliers and service providers that support critical business operations across the bank.
This role combines cybersecurity, risk management, technical assessments, supplier assurance, stakeholder management, and international exposure. You will work closely with global CISO teams, suppliers, risk professionals, and senior stakeholders to independently assess cybersecurity risks and drive improvements across ING's third-party ecosystem. If you are motivated by investigating complex environments, challenging the status quo, identifying cybersecurity risks, and influencing meaningful improvements, this role offers a unique opportunity to make a global impact.
Why is this role exciting? In this role, you will:
- Assess the cybersecurity posture of critical suppliers supporting ING globally
- Work on real-world cybersecurity risks affecting critical business services
- Perform independent cybersecurity assessments and onsite inspections worldwide
- Collaborate with technical experts, suppliers, security teams, auditors, and senior stakeholders
- Contribute to ING's Third-Party Risk Management, Operational Resilience, and DORA objectives
- Gain international exposure through assessments of providers across different countries and industries
- Develop expertise across multiple technologies, cloud environments, cybersecurity domains, and regulatory frameworks
- Join a growing Cybersecurity Hub and help shape its future direction Your key responsibilities: As a Senior Third-Party Cyber Assurance Expert, you will:
- Plan, organize, and execute risk-based cybersecurity assessments and onsite inspections of ING's critical third-party providers.
- Independently evaluate the design and effectiveness of cybersecurity controls implemented by suppliers.
- Assess security governance, technology controls, operational resilience capabilities, and risk management practices.
- Conduct interviews, documentation reviews, field inspections, configuration assessments, and technical security evaluations.
- Identify cybersecurity risks, control weaknesses, and potential vulnerabilities impacting ING.
- Analyze findings and translate technical gaps into clear business risks and actionable recommendations.
- Support the execution and evaluation of security testing activities, including penetration testing and red teaming results where applicable.
- Produce professional reports and executive-ready dashboards for senior management.
- Support ING's Third-Party Risk Management and Operational Resilience objectives under DORA and other regulatory frameworks.
- Collaborate with integral security, risk, procurement, architecture and audit teams.
- Contribute to continuous improvement initiatives within Third-Party Cyber Risk Management.
- Stay current on emerging threats, technologies, industry trends and cybersecurity best practices. Travel may be required as part of certain assessments, with an estimated travel requirement of approximately 6 to 8 weeks per year. What are we looking for? We are looking for cybersecurity professionals who combine strong technical knowledge, risk awareness, critical thinking, and excellent communication skills.
Required qualifications - Bachelor's or Master's degree in Computer Science, Information Security, Cybersecurity, IT Engineering, IT Risk Management, IT Audit, or related disciplines.
- 3-6 years of professional experience in Cybersecurity, IT Audit, Cyber Risk Management, Third-Party Risk Management, Information Security, or similar fields.
- Strong understanding of cybersecurity technologies and architectures.
- Experience assessing and evaluating IT and cybersecurity controls.
- Good understanding of risk management, governance frameworks, and the Three Lines Model.
- Familiarity with operating systems, networks, databases, identity and access management, cloud technologies, web technologies, software development practices, or containerization technologies.
- Experience performing audits, cybersecurity assessments, supplier reviews, or risk evaluations.
- Strong analytical and problem-solving skills.
- Ability to communicate complex technical topics to technical and non-technical audiences.
- Excellent stakeholder management and influencing skills.
- Fluency in English, both written and spoken.
- Ability to work effectively in multicultural and international environments. You’ll get extra points for - Experience within the banking or financial services sector.
- Experie
📌 Senior Third-Party Cyber Assurance Expert (Madrid)
🏢 PVH (Tommy Hilfiger/Calvin Klein)
📍 Madrid