08 oct
|
Jobbydoo
|
Zaragoza
At adidas, every day is a chance to flip the script. An invitation to take everything we know and re:invent it. Do it better. Never settling for good enough.
Every day we get up, invent, adapt, improvise, find new ways to collaborate,
and do the unexpected. We're creators, makers and doers. Helping athletes make
a difference, not just in their games, but in their lives and in their world.
It's an obsession.
We've been doing this for more than 75 years. With an unmatched history and tradition
of creating iconic products, consumer connections and experiences, we've been defining
sport culture since the beginning.
And we're never done.
Come be a part of shaping the future together with us.
IT STARTS WITH YOU
MANAGER INFORMATION SECURITY GOVERNANCE
INFORMATION SECURITY GOVERNANCE
PURPOSE:
The role is responsible for all efforts to reach a state of continuous compliance by partnering and engaging with our technology, business, and brand teams to adhere to policies, reduce security risks and maintain compliance in the area of Third Party Mgt. Part of overall duties is to establish, maintain and advance the information security governance framework.
KEY ACCOUNTABILITIES:
Third Party Risk Management Process Leadership
:Own and maintain the Third Party Information Security Risk Management process, including procedures, assessment methodology, templates, playbooks and supporting documentation.
:Define risk:based assessment criteria, supplier segmentation and prioritization logic based on data sensitivity, service criticality, access type, hosting model and business impact.
:Drive process improvement initiatives to increase assessment quality and scope, cycle time, stakeholder experience and audit readiness.
:Coordinate the annual review of the TPRM framework, ensuring alignment with information security policies, enterprise risk management and relevant regulatory expectations.
Third Party Security Assessments
:Lead and coordinate security due diligence for new and existing third parties, including suppliers, outsourced service providers, technology vendors, cloud providers and strategic partners.
:Review third party evidence such as security questionnaires, ISO 27001 certificates, SOC reports, penetration test summaries, business continuity documentation, data protection evidence and remediation plans.
:Assess security risks across relevant control domains including access management, data protection, cloud security, application security, vulnerability management, incident response, business continuity and subcontractor management.
:Determine residual risk ratings, document assessment outcomes and recommend risk treatment actions aligned to policy and business context.
Third Party Lifecycle Integration
:Partner with Procurement, Legal, Privacy and business stakeholders to embed security controls into sourcing, onboarding, contracting, renewal, change and exit processes.
:Provide guidance on minimum information security requirements, contractual security clauses, audit rights, breach notification, subcontractor controls, data return and deletion requirements.
:Support risk:based contract reviews and supplier negotiations where information security risks are material.
:Ensure clear handover points between security assessment, contract execution, operational third party management and recurring review cycles.
Risk Treatment, Monitoring and Escalation
:Track remediation actions, exceptions and risk acceptances to closure, ensuring accountable owners, due dates and evidence are documented.
:Escalate critical third party risks, overdue remediation or unresolved risk acceptance decisions to appropriate governance forums.
:Define and operate monitoring activities for higher:risk third paties, including periodic reassessments, trigger:based reviews and review of external assurance or security rating information where applicable.
:Contribute to third:party
📌 Third Party Cybersecurity Risk Management (Zaragoza)
🏢 Jobbydoo
📍 Zaragoza