In this role you oversee cybersecurity governance, risk and compliance activities to support BT’s risk posture. You’ll coordinate with stakeholders to manage risk assessments, third‑party risk, and control improvements, aligning with standards like NIST and ISO. You’ll drive remediation tracking and contribute to continuous GRC automation and program enhancements. You join a integral team that champions robust internal controls and proactive risk management.
Responsabilidades
- Coordinate GRC activities with key stakeholders to enable effective cybersecurity risk assessment and remediation tracking
- Define control gaps and provide recommendations for improvement, supporting corrective action plans
- Conduct risk assessments, audits, and investigations to identify compliance issues
- Perform end-to-end third-party risk assessments and ongoing vendor monitoring
- Document risk findings, risk ratings, and remediation actions aligned with risk appetite
- Stay updated on regulatory requirements and best practices related to third-party and supply chain risk
- Support automation and reporting through GRC tooling (Optro InfoSec) and drive process improvements
- Collaborate across BT and Cybersecurity functions, contributing to large global governance, risk and compliance projects
- Educate leadership on control design and operating effectiveness to ensure ongoing compliance
- Apply best practices to strengthen internal controls and drive risk-prioritized remediation
Requisitos principales
- 7+ years in compliance, controls assurance, internal audit, or related field
- Extensive knowledge of IT/cyber risk management practices and frameworks
- Experience monitoring/improving IT general controls, cybersecurity controls, and/or compliance programs
- Solid understanding of GRC methodologies and automation through tooling
- Proven experience with information security frameworks (e.g., COBIT, NIST CSF 2.0, ISO 27000, NIST 800-30/37/53)
- Certifications such as CISA, CRISC, CGEIT or CISSP preferred
- Ability to manage multiple parallel activities in a fast-paced environment
- Strong communication skills to influence technical and non-technical audiences
- Ability to work independently and in cross-functional teams
- Recognized expert in risk management and third-party risk management
- strong analytical and problem-solving abilities
- excellent written and verbal communication
- ability to influence executives and stakeholders
- IT/cyber risk management practices
- GRC tooling and automation (Optro InfoSec)
- third-party risk management
📌 Cybersecurity Risk Management Specialist - sant just desvern
🏢 Bunge
📍 Sant Just Desvern
Postulate a este anuncio
Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.