> Markdown version of [/jobs/ext/1937168-risk-technology-risk-cybersecurity-specialist-iii](https://www.wearedevelopers.com/jobs/ext/1937168-risk-technology-risk-cybersecurity-specialist-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Risk Technology Risk & Cybersecurity Specialist Iii - **Company:** Banco Santander, S.A. - **Location:** Salamanca, Spain - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Identity and Access Management, Intrusion Detection and Prevention, Open Web Application Security, Systems Development Life Cycle, Data Logging, Software Security, Containerization, Information Technology, Patch Management - **Published:** August 5, 2026 - **Apply:** https://www.buscojobs.com.es/risk-technology-risk-cybersecurity-specialist-iii-en-salamanca-ID-365603449 ## About the Role (Required)EducationBachelor's in Computer Science, Engineering or related (Required)Master's a plus. (Prefered)Professional certifications strongly valued: CISA, CISM, CRISC, CISSP; plus cloud security (AWS/Azure/GCP). (Required)LanguagesFluent English (Required)Technical expertise(you don't need all, but you know many)IAM, network & firewall management, vulnerability/patch management, cloud security architecture, secure SDLC & containerization, encryption/tokenization, DLP, security logging & monitoring, incident detection & response, and offensive security understanding.Frameworks & practicesNIST CSF, ISO ***********, COBIT, SOC 2/ISAE ****, OWASP; proven experience executing cyber risk oversight programs in 2LoD/3LoD.How You WorkStrong risk judgment and documentation quality; ability to coordinate across teams, influence constructively, and drive issues to closure in a matrixed, international setting.What's In It For YouReal impact on the cyber resilience of a global ## Description Santander ( is evolving fromCountry: Spaina global, high-impact brand into a technology-driven organization, and our people are at the heart of this journey.Together, we are driving a customer-centric transformation that values bold thinking, innovation, and the courage to challenge what's possible.It's a chance for driven professionals to grow, learn, and make a real difference .Our mission is to contribute to help more people and businesses prosper.We embrace a strong risk culture and all our professionals at all levels are expected to take a proactive and responsible approach toward risk management.Santander Corporate & Investment Banking (Santander CIB) is Santander's global division that supports some of the world's most complex and sophisticated corporate and institutional clients, offering customized services and value-added wholesale products to best meet their needs.THE DIFFERENCE YOU MAKESCIB s looking for a Senior Analyst - Cybersecurity Risk (2LoD) based out of Boadilla (Madrid) .We're shaping the way we work through innovation, cutting-edge technology, collaboration and the freedom to explore new ideas.To succeed in this role, you will be responsible for:Lead 2LoD review & challenge of cybersecurity risk assessments, control evaluations, risk metrics, mitigation plans and risk acceptances; synthesize into clear risk opinions for senior stakeholders.Run targeted risk reviews of priority domains (e.G., IAM, network/firewall, vulnerability & patch management, cloud security, AppSec/containers, encryption/tokenization, DLP, logging/monitoring, incident response/SOC); track remediation to closure.Provide independent oversight on digital transformation and business change, assessing cyber risk impacts and required controls from design to go-live.Strengthen third-party/critical services risk management: certify services/vendors, challenge inherent risk scoring, assign residual risk ratings, and monitor remediation.Analyze cyber risk data (incidents-internal/external, KRIs, control gaps, risk register) to identify patterns, concentrations, and emerging hotspots.Evolve and transpose policies/frameworks to steer safe technology adoption; align to industry standards.Prepare clear, decision-ready governance reporting for committees and working groups; escape issues with urgency and evidence.What You'll BringOur people are our greatest strength.Every individual contributes unique perspectives that make us stronger as a team and as an organization.We're enabling teams to go beyond by valuing who they are and empowering what they bring.Professional Experience~5-8 years in cybersecurity risk, technology risk, cyber audit or 2LoD/3LoD roles in financial services or other highly regulated environments.(Required)EducationBachelor's in Computer Science, Engineering or related (Required)Master's a plus.(Prefered)Professional certifications strongly valued: CISA, CISM, CRISC, CISSP; plus cloud security (AWS/Azure/GCP).(Required)LanguagesFluent English (Required)Technical expertise(you don't need all, but you know many)IAM, network & firewall management, vulnerability/patch management, cloud security architecture, secure SDLC & containerization, encryption/tokenization, DLP, security logging & monitoring, incident detection & response, and offensive security understanding.Frameworks & practicesNIST CSF, ISO ***********, COBIT, SOC 2/ISAE ****, OWASP; proven experience executing cyber risk oversight programs in 2LoD/3LoD.How You WorkStrong risk judgment and documentation quality; ability to coordinate across teams, influence constructively, and drive issues to closure in a matrixed, international setting.What's In It For YouReal impact on the cyber resilience of a global ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Spanish Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/353-spanish-business-culture-and-etiquette) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)