Tech Specialist

Banco Santander, S.A.
Madrid, Spain
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Security Control Objectives for Information and Related Technology (COBIT) Identity and Access Management Open Web Application Security Systems Development Life Cycle Data Logging Software Security Containerization Information Technology Patch Management

Job description

IT STARTS HERE Santander ( is evolving from Country: Spain IT STARTS HERE Santander ( is evolving from a global, high-impact brand into a technology-driven organization, and our people are at the heart of this journey.Together, we are driving a customer-centric transformation that values bold thinking, innovation, and the courage to challenge what’s possible.This is more than a strategic shift.It’s a chance for driven professionals to grow, learn, and make a real difference.Our mission is to contribute to help more people and businesses prosper.We embrace a strong risk culture and all our professionals at all levels are expected to take a proactive and responsible approach toward risk management.Santander Corporate & Investment Banking (Santander CIB) is Santander’s global division that supports some of the world’s most complex and sophisticated corporate and institutional clients, offering customized services and value-added wholesale products to best meet their needs.THE DIFFERENCE YOU MAKE SCIB is looking for a Senior Analyst - Cybersecurity Risk (2LoD) based out of Boadilla (Madrid) Responsibilities Lead 2LoD review & challenge of cybersecurity risk assessments, control evaluations, risk metrics, mitigation plans and risk acceptances; synthesize into clear risk opinions for senior stakeholders.Run targeted risk reviews of priority domains (e.G., IAM, network/firewall, vulnerability & patch management, cloud security, AppSec/containers, encryption/tokenization, DLP, logging/monitoring, incident response/SOC); track remediation to closure.Provide independent oversight on digital transformation and business change, assessing cyber risk impacts and required controls from design to go-live.Strengthen third?party/critical services risk management: certify services/vendors, challenge inherent risk scoring, assign residual risk ratings, and monitor remediation.Analyze cyber risk data (incidents-internal/external, KRIs, control gaps, risk register) to identify patterns, concentrations, and emerging hotspots.Evolve and transpose policies/frameworks to steer safe technology adoption; align to industry standards.Prepare clear, decision-ready governance reporting for committees and working groups; escalat issues with urgency and evidence.What You’ll Bring Our people are our greatest strength.Every individual contributes unique perspectives that make us stronger as a team and as an organization.We’re enabling teams to go beyond by valuing who they are and empowering what they bring.The following requirements represent the knowledge, skills, and abilities essential for success in this role.Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.Professional Experience ~5-8 years in cybersecurity risk, technology risk, cyber audit or 2LoD/3LoD roles in financial services or other highly regulated environments.(Required) Education Bachelor’s in Computer Science, Engineering or related (Required) Master’s a plus.(Prefered) Professional certifications strongly valued: CISA, CISM, CRISC, CISSP; plus cloud security (AWS/Azure/GCP).(Required) Languages Fluent English (Required) Technical expertise (you don’t need all, but you know many) IAM, network & firewall management, vulnerability/patch management, cloud security architecture, secure SDLC & containerization, encryption/tokenization, DLP, security logging & monitoring, incident detection & response, and offensive security understanding.Frameworks & practices NIST CSF, ISO *****, COBIT, SOC 2/ISAE **, OWASP; proven experience executing cyber risk oversight programs in 2LoD/3LoD.How You Work Strong risk judgment and documentation quality; ability to coordinate across teams, influence constructively, and drive issues to closure in a matrixed, international setting.What’s In It For You Real impact on the cyber resilience of a global

Requirements

Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Professional Experience ~5-8 years in cybersecurity risk, technology risk, cyber audit or 2LoD/3LoD roles in financial services or other highly regulated environments. (Required) Education Bachelor’s in Computer Science, Engineering or related (Required) Master’s a plus. (Prefered) Professional certifications strongly valued: CISA, CISM, CRISC, CISSP; plus cloud security (AWS/Azure/GCP). (Required) Languages Fluent English (Required) Technical expertise (you don’t need all, but you know many) IAM, network & firewall management, vulnerability/patch management, cloud security architecture, secure SDLC & containerization, encryption/tokenization, DLP, security logging & monitoring, incident detection & response, and offensive security understanding. Frameworks & practices NIST CSF, ISO *****, COBIT, SOC 2/ISAE **, OWASP; proven experience executing cyber risk oversight programs in 2LoD/3LoD. How You Work Strong risk judgment and documentation quality; ability to coordinate across teams, influence constructively, and drive issues to closure in a matrixed, international setting. What’s In It For You Real impact on the cyber resilience of a global

About the company

Vera, AlmerĂ­a, EspaĂąa

IT STARTS HERE Santander ( is evolving from Country: Spain IT STARTS HERE Santander ( is evolving from a global, high-impact brand into a technology-driven organization, and our people are at the heart of this journey. Together, we are driving a customer-centric transformation that values bold thinking, innovation, and the courage to challenge what’s possible. This is more than a strategic shift. It’s a chance for driven professionals to grow, learn, and make a real difference. Our mission is to contribute to help more people and businesses prosper.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 ¡ WWC Europe 2026

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea ¡ WWC 2022

2:54 min

Configuring database and caching containers in the builder

Shako Turashvili Shako Turashvili ¡ WWC 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

5:01 min

Container hosting options available on Microsoft Azure

Federico Fregosi ¡ WWC 2022

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann ¡ WWC 2023

Videos

See all

Related articles

See all