Risk Technology Risk & Cybersecurity Specialist Iii
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+2 more
Job description
PositionRisk Technology Risk & Cybersecurity Specialist III - SpainAbout the roleIT STARTS HERE Santander is evolving from a global, high-impact brand into a technology-driven organization, and our people are at the heart of this journey. We are driving a customer?centric transformation that values bold thinking, innovation, and the courage to challenge whatâs possible. Our mission is to help more people and businesses prosper. We embrace a strong risk culture and expect all professionals to take a proactive and responsible approach toward risk management.About the organizationSantander Corporate & Investment Banking (Santander CIB) is Santanderâs global division that supports some of the worldâs most complex and sophisticated corporate and institutional clients, offering customized services and value?added wholesale products.ResponsibilitiesLead 2LoD review & challenge of cybersecurity risk assessments, control evaluations, risk metrics, mitigation plans and risk acceptances; synthesize into clear risk opinions for senior stakeholders.Run targeted risk reviews of priority domains (e.g., IAM, network/firewall, vulnerability & patch management, cloud security, AppSec/containers, encryption/tokenization, DLP, logging/monitoring, incident response/SOC); track remediation to closure.Provide independent oversight on digital transformation and business change, assessing cyber risk impacts and required controls from design to go?live.Strengthen third?party/critical services risk management: certify services/vendors, challenge inherent risk scoring, assign residual risk ratings, and monitor remediation.Analyze cyber risk data (incidents-internal/external, KRIs, control gaps, risk register) to identify patterns, concentrations, and emerging hotspots.Evolve and transpose policies/frameworks to steer safe technology adoption; align to industry standards.Prepare clear, decision?ready governance reporting for committees and working groups; escape issues with urgency and evidence.QualificationsProfessional Experience ~5-8 years in cybersecurity risk, technology risk, cyber audit or 2LoD/3LoD roles in financial services or other highly regulated environments. (Required)Education: Bachelorâs in Computer Science, Engineering or related. (Required)Masterâs a plus. (Preferred)Professional certifications strongly valued: CISA, CISM, CRISC, CISSP; plus cloud security (AWS/Azure/GCP). (Required)Languages: Fluent English. (Required)Technical expertise (not all required, but many): IAM, network & firewall management, vulnerability/patch management, cloud security architecture, secure SDLC & containerization, encryption/tokenization, DLP, security logging & monitoring, incident detection & response, and offensive security understanding.Frameworks & practices: NIST CSF, ISO ****, COBIT, SOC 2/ISAE ****, OWASP; proven experience executing cyber risk oversight programs in 2LoD/3LoD.How you workStrong risk judgment and documentation quality; ability to coordinate across teams, influence constructively, and drive issues to closure in a matrixed, international setting.BenefitsReal impact on the cyber resilience of a global bank. International exposure and complex, high?stakes projects within SCIB. Access to training and certifications; inclusive culture with strong risk ownership. Flexibility that works - hybrid working models, flexible hours.EEO StatementLocal Compliance: Santander is proud of being an organization where there are equal opportunities regardless of age, gender, disability, civil status, race, religion or sexual orientation. We are committed to providing an inclusive and accessible application process for all candidates.#J-**-Ljbffr
Requirements
Professional Experience ~5-8 years in cybersecurity risk, technology risk, cyber audit or 2LoD/3LoD roles in financial services or other highly regulated environments. (Required) Education: Bachelorâs in Computer Science, Engineering or related. (Required) Masterâs a plus. (Preferred) Professional certifications strongly valued: CISA, CISM, CRISC, CISSP; plus cloud security (AWS/Azure/GCP). (Required) Languages: Fluent English. (Required) Technical expertise (not all required, but many): IAM, network & firewall management, vulnerability/patch management, cloud security architecture, secure SDLC & containerization, encryption/tokenization, DLP, security logging & monitoring, incident detection & response, and offensive security understanding. Frameworks & practices: NIST CSF, ISO *****, COBIT, SOC 2/ISAE **, OWASP; proven experience executing cyber risk oversight programs in 2LoD/3LoD. How you work Strong risk judgment and documentation quality; ability to coordinate across teams, influence constructively, and drive issues to closure in a matrixed, international setting.
Benefits & conditions
Real impact on the cyber resilience of a global bank. International exposure and complex, high?stakes projects within SCIB. Access to training and certifications; inclusive culture with strong risk ownership. Flexibility that works - hybrid working models, flexible hours. EEO Statement Local Compliance: Santander is proud of being an organization where there are equal opportunities regardless of age, gender, disability, civil status, race, religion or sexual orientation. We are committed to providing an inclusive and accessible application process for all candidates. #J-*****-Ljbffr
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.buscojobs.com.esGood distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Spanish Business Culture and Etiquette
What Are The Top Skills Required For Azure Developers?
5 Best Emerging Tech Cities in Europe
Best Paying Jobs in Technology