Security Specialist - IT Governance
Role details
Job location
Tech stack
Job description
Our offices are in Spain (Madrid) and Portugal (Lisbon, Porto). The company brings together over 200+ employees, with expertise in various technologies (Java, .Net, Python, Tibco, APIGee) and other operational roles (Functional Analyst, Project Manager, Business Analyst, Auto Stock Financing operators). We keep growing!
About the job
Main responsibility:
As an SSr Security Specialist IT Governance, your primary mission is to ensure the effective implementation, monitoring, and continuous improvement of cybersecurity controls defined within BNP Paribas' Cybersecurity Program. This includes analyzing evidence, tracking control effectiveness, and coordinating with stakeholders to ensure compliance and risk mitigation.
Your functions will include:
· Objective's evaluation: review and validate evidence related to cybersecurity controls (technical and organizational), ensuring alignment with Group policies and standards, and effectiveness in mitigating risks.
· Compliance Monitoring: track the implementation status of controls across BNP Paribas entities, identify gaps or deviations, and support remediation planning.
· Stakeholder Coordination: collaborate with local and central teams (IT Risk, CISO's team, etc.) to ensure a comprehensive view of control status and risk posture.
· Reporting: prepare regular reports on control status, identified risks, and ongoing actions for cybersecurity leadership and risk committees.
· Continuous Improvement: recommend enhancements to governance processes, control tracking mechanisms, and automation opportunities.
What is in it for you?
· Be part of an international team delivering services worldwide for BNP Paribas Personal Finance subsidiaries.
· Excellent growth prospects as our service catalog expands annually to meet the evolving needs of BNPP PF entities., BNP Paribas Group in Spain is an equal opportunity employer and proud to provide equal employment opportunity to all job seekers. We are actively committed to ensuring that no individual is discriminated against on the grounds of age, disability, gender reassignment, marriage or civil partnership status, pregnancy and maternity/paternity, race, religion or belief, sex or sexual orientation. Equity and diversity are at the core of our recruitment policy because we believe that they foster creativity and efficiency, which in turn increase performance and productivity. We strive to reflect the society we live in, while keeping with the image of our clients.
Requirements
· Advanced student/graduate of a computer science related career
· Proven experience in assessing and governance of IT and Cybersecurity risks and controls.
· Proven experience with the definition of action plans for identified risks.
· Proven experience in monitoring action plans for identified risks.
· Knowledge of standards like NIST Framework or ISO27001.
Skills:
Behavioral Skills
· Proactivity
· Customer-oriented (service delivery will be the heart of the activity).
· Drive and autonomy.
· Attention to details.
· Motivated to pick up new skills as you go.
· Organized, efficient, and able to meet deadlines.
Transversal Skills
· Analytical ability
· Project management
· Critical thinking
Tools - Methodologies - Technologies
· MS Office Pack (Excel, Word, PowerPoint)
Language skills:
· Proficient in English (Reading and writing - C1 minimum)
Benefits & conditions
-
Training programs, career plans and internal mobility opportunities, national and international thanks to our presence in different countries.
-
Diversity and Inclusion Committee that ensures an inclusive work environment. In recent years, several employee communities have been created to organize diversity and inclusion awareness actions (PRIDE, We Generations and MixCity).
-
Corporate volunteering program (1 Million Hours 2 Help) in which employees can dedicate time out of their working hours to volunteer activities.
-
Flexible compensation plan.
-
Hybrid telecommuting model (50%).
-
31 vacation days.
Diversity and inclusion commitment