09 oct
|
Adidas Group
|
Zaragoza
09 oct
Adidas Group
Zaragoza
Overview
In this role you will lead the Third Party Information Security Risk Management program, partnering with technology, business, and brand teams to uphold policies and reduce security risks. You will advance the governance framework and drive continuous improvement across risk assessment, supplier due diligence, and lifecycle controls. You will work with stakeholders across Procurement, Legal, Privacy, and business units to embed security into sourcing and contracting. You will deliver governance reporting and support audits, shaping adidas' approach to third-party risk in a general, fast-moving environment.
Compensaciones / Beneficios
- Hybrid work setup (40% remote)
- Competitive salary and benefits
- Individual development and training
- International career opportunities
- Tech community involvement
- Product discounts
Responsabilidades
- Own and maintain the Third Party Information Security Risk Management process, including procedures, templates and playbooks; set risk-based assessment criteria and segmentation.
- Lead and coordinate security due diligence for third parties, reviewing evidence like ISO 27001, SOC reports, penetration test results, and remediation plans.
- Embed security controls across the supplier lifecycle (sourcing, onboarding, contracting, renewal, change, exit) with Procurement, Legal and Privacy.
- Track remediation actions, manage risk acceptance, and escalate critical risks through governance forums.
- Develop and maintain executive reporting on risk ratings, remediation status and key risk themes; support audits and regulatory inquiries.
- Act as owner for the TPRM module in the GRC tool; explore automation of assessments, evidence collection, reminders, and dashboards.
- Oversee enterprise information security governance activities and ensure alignment with policy, standards, and regulatory obligations.
Requisitos principales
- 5+ years in information security, IT risk, cyber risk, third party risk management, audit, or governance
- 3+ years of supplier security assessments or vendor risk management experience
- Experience in global, matrixed organizations with cross-functional stakeholders
- Strong understanding of information security risk management and supplier lifecycle controls
- Knowledge of ISO 27001, SOC reports, NIST frameworks, GDPR and cloud security practices
- Understanding of contractual security requirements, risk acceptance and audit evidence expectations
- Ability to translate technical risks into actionable business recommendations
- Effective stakeholder management, communication, facilitation, and negotiation skills
- Proficiency with GRC or TPRM platforms and reporting dashboards
- Stakeholder management
- Communication and facilitation
- Negotiation
- GRC/TPRM platforms
- Assessment questionnaires and evidence management
- Control mappings and issue registers
📌 Third Party Cybersecurity Risk Management (Zaragoza)
🏢 Adidas Group
📍 Zaragoza