Information Risk Specialist - 2Nd Line Of Defense
Role details
Job location
Tech stack
Job description
OverviewDo you want to play a key role in strengthening the digital resilience of a leading Top Employer in Spain?This position sits at the intersection of technology, security, regulation and business, bringing clarity to complex risk topics and enabling secure, responsible decision?making in areas such as cloud, AI, data protection and emerging technologies.It offers real influence, working closely with technology, security and business teams, with visibility at the senior?management level.ResponsibilitiesShaping how IT security frameworks and standards (ISO ******, COBIT, ISF) are applied and challenged across the organisation.Translating regulations such as GDPR, DORA, EIOPA and the AI Act into practical, actionable guidance.Evaluating whether IT controls, processes and architectures effectively manage real risks.Interpreting insights from penetration tests, vulnerability scans and threat?modelling.Providing independent risk input to major technology projects and change initiatives.Reviewing incidents, remediation plans and audit findings to strengthen resilience.Assessing vendor and third?party risks together with asset owners.Acting as a trusted advisor for management and business teams on information?risk topics.Supporting AI?related initiatives from a risk and governance perspective.Qualifications4+ years of experience in IT Risk, Information Security, IT Audit or similar areas.Strong understanding of security frameworks and regulatory environments.Ability to translate technical cybersecurity risks into clear, business?focused guidance.Confidence working with both technical and non?technical stakeholders.Analytical mindset, curiosity and a proactive approach.English proficiency for collaboration in an international context.BenefitsLife insurance and pension plan.Flexible compensation, telework and meal allowance.Wellness programme, volunteering initiatives and free parking with EV charging.Continuous learning and support for security and risk certifications.In Nationale?Nederlanden we are committed to diversity and inclusion.We offer equal opportunities regardless of race, cultural background, gender, gender identity, religion, national origin, age, disability, marital status, and sexual orientation.#J--Ljbffr
Requirements
4+ years of experience in IT Risk, Information Security, IT Audit or similar areas. Strong understanding of security frameworks and regulatory environments. Ability to translate technical cybersecurity risks into clear, business?focused guidance. Confidence working with both technical and non?technical stakeholders. Analytical mindset, curiosity and a proactive approach. English proficiency for collaboration in an international context.
Benefits & conditions
Life insurance and pension plan. Flexible compensation, telework and meal allowance. Wellness programme, volunteering initiatives and free parking with EV charging. Continuous learning and support for security and risk certifications. In Nationale?Nederlanden we are committed to diversity and inclusion. We offer equal opportunities regardless of race, cultural background, gender, gender identity, religion, national origin, age, disability, marital status, and sexual orientation. #J-*****-Ljbffr