Information Risk Specialist - 2Nd Line Of Defense

NATIONALE - NEDERLANDEN
Madrid, Spain
21 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
4 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Artificial Intelligence Software System Penetration Testing Cloud Computing Control Objectives for Information and Related Technology (COBIT) Cyber Security Information Technology Audit IT General Controls (ITGC)

Job description

OverviewDo you want to play a key role in strengthening the digital resilience of a leading Top Employer in Spain?This position sits at the intersection of technology, security, regulation and business, bringing clarity to complex risk topics and enabling secure, responsible decision?making in areas such as cloud, AI, data protection and emerging technologies.It offers real influence, working closely with technology, security and business teams, with visibility at the senior?management level.ResponsibilitiesShaping how IT security frameworks and standards (ISO ****, COBIT, ISF) are applied and challenged across the organisation.Translating regulations such as GDPR, DORA, EIOPA and the AI Act into practical, actionable guidance.Evaluating whether IT controls, processes and architectures effectively manage real risks.Interpreting insights from penetration tests, vulnerability scans and threat?modelling.Providing independent risk input to major technology projects and change initiatives.Reviewing incidents, remediation plans and audit findings to strengthen resilience.Assessing vendor and third?party risks together with asset owners.Acting as a trusted advisor for management and business teams on information?risk topics.Supporting AI?related initiatives from a risk and governance perspective.Qualifications4+ years of experience in IT Risk, Information Security, IT Audit or similar areas.Strong understanding of security frameworks and regulatory environments.Ability to translate technical cybersecurity risks into clear, business?focused guidance.Confidence working with both technical and non?technical stakeholders.Analytical mindset, curiosity and a proactive approach.English proficiency for collaboration in an international context.BenefitsLife insurance and pension plan.Flexible compensation, telework and meal allowance.Wellness programme, volunteering initiatives and free parking with EV charging.Continuous learning and support for security and risk certifications.In Nationale?Nederlanden we are committed to diversity and inclusion.We offer equal opportunities regardless of race, cultural background, gender, gender identity, religion, national origin, age, disability, marital status, and sexual orientation.#J-**-Ljbffr

Requirements

4+ years of experience in IT Risk, Information Security, IT Audit or similar areas. Strong understanding of security frameworks and regulatory environments. Ability to translate technical cybersecurity risks into clear, business?focused guidance. Confidence working with both technical and non?technical stakeholders. Analytical mindset, curiosity and a proactive approach. English proficiency for collaboration in an international context.

Benefits & conditions

Life insurance and pension plan. Flexible compensation, telework and meal allowance. Wellness programme, volunteering initiatives and free parking with EV charging. Continuous learning and support for security and risk certifications. In Nationale?Nederlanden we are committed to diversity and inclusion. We offer equal opportunities regardless of race, cultural background, gender, gender identity, religion, national origin, age, disability, marital status, and sexual orientation. #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:48 min

Utilizing the NIST framework for risk management

Rebekka Weiss Rebekka Weiss +1 · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

3:46 min

Core terminology and audiences for interpretable artificial intelligence

Karol Przystalski · LIVE

5:30 min

Identifying non-coding software vulnerabilities and organizational risks

Tino Sokic · World Congress 2023

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all