28 sep
|
Crossell
|
Madrid
Risk Manager, ISOC, Security Operations Group | Worldwide Operations Security Description You will own the operational enablement functions that allow ISOC (Intervention Security Operations Center) international monitoring operations to run at scale across regulated jurisdictions. This role is responsible for regulatory compliance management, technology integration coordination, vendor contract management, training and certification programs, and the standard operating procedures that ensure consistent execution regardless of location or operator. You will not manage shifts or handle alerts.
You will build the compliance backbone, negotiate vendor agreements, coordinate platform deployments, develop training curricula, and maintain the audit and governance frameworks that keep operations legally sound and operationally excellent. You enable the people who execute by giving them the tools, training, standards, and contracts they need to perform. Key job responsibilities Own regulatory and compliance management for ISOC monitoring operations across all international jurisdictions, ensuring operations meet data protection, surveillance, and privacy requirements Navigate legal frameworks for remote monitoring, cross-border data transfer, and alert handling, partnering with legal counsel to translate regulatory requirements into operational procedures Manage vendor contracts for third party monitoring operators, including agreement negotiation, SLA definition, performance measurement, cost optimization, and renewal planning Coordinate technology integration across the monitoring platform, including new system deployments, platform standardization, configuration management,
and tool selection Develop and maintain the training and certification program for ISOC analysts, including onboarding curricula, recurring proficiency assessments, and specialized skill development for new use cases Build and maintain the audit and compliance framework, including internal assessment schedules, evidence collection, regulatory reporting, and remediation tracking Drive operational excellence initiatives: process improvement, efficiency analysis, quality management, and standardization across international control room operations Your morning starts with reviewing a regulatory update from counsel on a pending change to monitoring consent requirements in one of your operating jurisdictions.
You assess the operational impact, draft the Standard Operating Procedure revision needed, and flag the training update required for affected analysts. Mid-morning, you join a vendor performance review call to discuss compliance, staffing shortfalls, and contract renewal terms for one of your third party operator agreements. You spend part of your day working on the technology integration roadmap: coordinating with the platform team on a new system deployment timeline, validating that data handling configurations meet jurisdictional requirements, and updating the integration checklist for the operations team.
After lunch,
you review the latest analyst certification results from the quarterly assessment cycle, identify skill gaps, and adjust the training program accordingly. You close the day updating the compliance tracker for an upcoming audit and preparing a cost optimization proposal for the next vendor negotiation cycle. Operating 24/7 control rooms across multiple general locations, ISOC receives technology-generated signals, validates threats in real time, and coordinates the appropriate response function.
Bachelor's degree or equivalent Experience overseeing security operations and working with security vendors/contractors Experience with multi-jurisdictional regulatory compliance, including data protection frameworks and operational licensing requirements Demonstrated ability to build and maintain training programs, standard operating procedures, or certification frameworks for operational teams Direct experience with EU data protection regulations (GDPR, ePrivacy Directive) and their application to surveillance or monitoring operations Experience with security technology procurement, including vendor evaluation, RFP development, and contract structuring Background in SOC compliance, including quality management systems or ISO certification frameworks Experience developing training programs for technical operator roles, including competency assessment and recurrent certification Protecting your privacy and the security of your data is a longstanding top priority for Amazon. Please consult our Privacy Notice () to know more about how we collect, use and transfer the personal data of our candidates.
📌 Credit Risk Analyst (Hybrid) (Madrid)
🏢 Crossell
📍 Madrid