15 sep
|
Bunge
|
Sant Just Desvern
15 sep
Bunge
Sant Just Desvern
Overview In this role you oversee cybersecurity governance, risk and compliance activities to support BT's risk posture. You'll coordinate with stakeholders to manage risk assessments, third‐party risk, and control improvements, aligning with standards like NIST and ISO. You'll drive remediation tracking and contribute to continuous GRC automation and program enhancements. You join a general team that champions robust internal controls and proactive risk management.
Responsabilidades
Coordinate GRC activities with key stakeholders to enable effective cybersecurity risk assessment and remediation tracking
Define control gaps and provide recommendations for improvement, supporting corrective action plans
Conduct risk assessments, audits, and investigations to identify compliance issues
Perform end-to-end third-party risk assessments and ongoing vendor monitoring
Document risk findings, risk ratings, and remediation actions aligned with risk appetite
Stay updated on regulatory requirements and best practices related to third-party and supply chain risk
Support automation and reporting through GRC tooling (Optro InfoSec) and drive process improvements
Collaborate across BT and Cybersecurity functions, contributing to large global governance, risk and compliance projects
Educate leadership on control design and operating effectiveness to ensure ongoing compliance
Apply best practices to strengthen internal controls and drive risk-prioritized remediation
Requisitos principales 7+ years in compliance, controls assurance, internal audit, or related field
Extensive knowledge of IT/cyber risk management practices and frameworks
Experience monitoring/improving IT general controls, cybersecurity controls, and/or compliance programs
Solid understanding of GRC methodologies and automation through tooling
Proven experience with information security frameworks (e.g., COBIT, NIST CSF 2.0, ISO 27000, NIST 800-30/37/53)
Certifications such as CISA, CRISC, CGEIT or CISSP preferred
Ability to manage multiple parallel activities in a fast-paced environment
Strong communication skills to influence technical and non-technical audiences
Ability to work independently and in cross-functional teams
Recognized expert in risk management and third-party risk management strong analytical and problem-solving abilities excellent written and verbal communication ability to influence executives and stakeholders
IT/cyber risk management practices
GRC tooling and automation (Optro InfoSec)
third-party risk management
📌 Cybersecurity Risk Management Specialist (Sant Just Desvern)
🏢 Bunge
📍 Sant Just Desvern