Third Party Audit Supervisor
At ING Hubs Spain we are looking for a Third Party Audit Supervisor.
Your role and work environment
We are searching for a talented and enthusiastic leader to join our Tech Hub Spain Team of Third Party Cyber Risk Management. The team performs onsite inspections worldwide, focusing on ING third parties supporting critical processes. We are a collaborative group of IT auditors who enjoy tackling new challenges related to third‑party vulnerabilities and IT risks.
Your key responsibilities
Lead a team of IT auditors to conduct onsite inspections on behalf of ING for third parties. Evaluate the design and implementation of IT controls executed by outsourcers, plan and execute risk‑based onsite audits, coordinate with senior management and suppliers, and assess the control environment through interviews, documentation review, field inspections, configuration assessment and technical tests—including penetration tests and/or red‑team exercises for critical third parties. Deliver executive‑ready dashboards and communicate systemic risk insights to management, helping ING improve its security control environment and mitigate risks across third parties. Travel may be required for some audits, with an estimated period of 6‑8 weeks per year.
Qualifications and experience
- A bachelor’s or master’s degree in Computer Science, IT Engineering, IT Security, IT Risk Management or IT Audit.
- Technical security knowledge of IT technologies, including operating systems, network infrastructure, database management systems, web technologies, mobile operating systems, and expertise in at least one IT area such as cloud, development, IAM, container (Docker) or web/mobile applications.
- More than six years of experience in IT audit with sound knowledge of IT risk management,
governance and the three‑lines of defence model. Experience managing a team is a plus.
- Strong vendor negotiation and stakeholder management skills.
- Ability to translate technical gaps into business‑impact language.
- Experience performing penetration tests or red‑team exercises is preferred.
- Strong knowledge of IT processes and standards, best practices such as COBIT, ISO 27001, ISO 22001, etc.
- Comfortable leading technical and process audits, dealing with conflicts, managing expectations, and organising field‑work testing to meet timelines.
- Coaching other team members and helping them grow is encouraging.
- Good written and verbal English; accustomed to working in multicultural environments.
- Certifications in good standing (e.g., CISA, CISSP, OSCP, ISO27001LA).
- Bonus: knowledge of banking regulations (PSD2, EBA guidelines, DORA, NIST CSF, ISO/IEC 27001, SOC 2, Cloud Security Frameworks, EU regulatory frameworks); experience with vulnerability assessment and pentesting tools (Nessus, Wireshark, Burp, Kali); experience with data analytics tools or scripting (Knime).
What do we offer?
- Versátil work model with autonomy to choose days working from home or at the ING Madrid office.
- Well‑deserved break time so you can enjoy life without compromising productivity.
- Access to on‑site facilities: electric mobility solutions, doctor, hairdresser, gym, the Good Service for errands, and more.
- Comprehensive health insurance for you and your family (spouse/partner and children).
- Life insurance to protect what matters most.
- Flexible remuneration model with tax‑advantaged options and access to services such as nursery, transport card, and training aids.
- Insurance and other benefits to support your professional growth.
- Participation in the company pension plan after one month of employment.
#J-18808-Ljbffr
📌 Third party Audit Supervisor (España)
🏢 Ing
📍 España