Information Risk Specialist - 2nd Line of Defense

NN Group
Madrid, Spain
27 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
4 years minimum
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Artificial Intelligence Software System Penetration Testing Cloud Computing Control Objectives for Information and Related Technology (COBIT) Cyber Security Information Technology Audit IT General Controls (ITGC)

Job description

This position sits at the intersection of technology, security, regulation and business. Its purpose is to bring clarity to complex risk topics and enable secure, responsible decision-making in areas such as cloud, AI, data protection and emerging technologies.

The role offers real influence, working closely with technology, security and business teams, as well as visibility at senior-management level.

What makes Nationale-Nederlanden Spain an attractive environment

  • Recognised as Top Employer Spain
  • Hybrid work model and flexible schedule
  • A stable organisation with a strong digital and innovation roadmap
  • Continuous learning and support for security and risk certifications
  • Exposure to strategic initiatives: AI governance, DORA, GDPR, cloud and new technologies
  • Competitive benefits: life insurance, pension plan, flexible compensation, telework and meal allowance
  • Wellness programme, volunteering initiatives and free parking with EV charging
  • Digital culture supported by agile ways of working

What you will take ownership of

  • Shaping how IT security frameworks and standards (ISO 27001/27002, COBIT, ISF) are applied and challenged across the organisation
  • Translating regulations such as GDPR, DORA, EIOPA and the AI Act into practical, actionable guidance
  • Evaluating whether IT controls, processes and architectures effectively manage real risks
  • Interpreting insights from penetration tests, vulnerability scans and threat-modelling
  • Providing independent risk input to major technology projects and change initiatives
  • Reviewing incidents, remediation plans and audit findings to strengthen resilience
  • Assessing vendor and third-party risks together with asset owners
  • Acting as a trusted advisor for management and business teams on information-risk topics
  • Supporting AI-related initiatives from a risk and governance perspective

Requirements

  • 4+ years of experience in IT Risk, Information Security, IT Audit or similar areas
  • Strong understanding of security frameworks and regulatory environments
  • Ability to translate technical cybersecurity risks into clear, business-focused guidance
  • Confidence working with both technical and non-technical stakeholders
  • Analytical mindset, curiosity and a proactive approach
  • English proficiency for collaboration in an international context

If you are interested in a role where your expertise directly influences how a leading organisation manages technology and information risk, feel free to reach out or start a conversation.

Benefits & conditions

Pulled from the full job description

  • Retirement plan
  • Life insurance
  • Free parking

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on es.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · WWC 2024

3:46 min

Core terminology and audiences for interpretable artificial intelligence

Karol Przystalski · LIVE

1:48 min

Utilizing the NIST framework for risk management

Rebekka Weiss Rebekka Weiss +1 · WWC 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all