10 oct
|
Importante empresa
|
Barcelona
10 oct
Importante empresa
Barcelona
- - Identify, assess, document, and manage cyber security risks across technology, business processes, projects, and third parties.
- Maintain and improve the Cyber Security Risk Management framework aligned with NIST, ISO 27001, CIS, and business requirements.
- Support business stakeholders in understanding and managing security risks.
- Support the development, maintenance, and continuous improvement of the Information Security Management System (ISMS).
- Assist with ISO 27001 certification activities, surveillance audits, and internal control reviews.
- Monitor compliance with security policies, standards, and regulatory obligations.
- Perform security assessments of suppliers, partners, and service providers.
- Work with Procurement, Legal, Privacy, and Technology teams to ensure third-party risks are appropriately managed.
- Support ongoing monitoring of critical vendor security posture.
- Support the delivery of the integral Cyber Security Awareness Programme.
- Create and maintain awareness content, campaigns, phishing simulations, communications, and training materials.
- Promote a positive security culture across the organisation.
- Develop, review, and maintain security policies, standards, procedures, and guidelines.
- Ensure documentation remains aligned to industry standards and business objectives.
- Assist business and technology teams with policy interpretation and implementation.
- Collaborate with Cyber Security Operations and Cyber Security Architecture teams to improve the overall security posture.
Essential
- Experience working in Cyber Security Governance, Risk & Compliance (GRC), Security Management,
or Information Security roles.
- Experience with ISO 27001, NIST Cybersecurity Framework, CIS Controls, or similar frameworks.
- Experience conducting security risk assessments and security control reviews.
- Experience supporting audits, compliance activities, and assurance programmes.
- Experience performing vendor or third-party security assessments.
- Strong understanding of information security principles and cyber risk management.
Desirable
- ISO 27001 Lead Implementer or Lead Auditor certification.
- CISSP, CISM, CRISC, or equivalent certification.
- Experience with OneTrust, CyberVadis, ServiceNow, Jira, or GRC platforms.
- Experience delivering security awareness programmes.
- Experience supporting Data Protection Impact Assessments (DPIAs).
Skills & Competencies
- Strong analytical and problem-solving skills.
- Excellent written and verbal communication skills.
- Ability to translate technical security concepts into business language.
- Strong stakeholder management and influencing skills.
- Ability to work independently and manage multiple priorities.
- High attention to detail and quality.
- Strong presentation and reporting capabilities.
- Collaborative mindset with experience working in global, multicultural environments.
Multinational company.
- Competitive salary aligned with your experience
- Permanent, full-time contract
- Meal vouchers
- Private health insurance
- Life Insurance
- Hybrid working model (2 days of home office/week)
- Multicultural environment
- Training and internal development opportunities
- A vibrant and dynamic international workplace located in Barcelona
📌 Cyber Security Analyst (Hybrid in Barcelona)
🏢 Importante empresa
📍 Barcelona