IT / CYBER RISK COE MANAGER
Country: Spain
Responsibilities
You will be part of Digital Risk Global CoE, delivering support services to entities.
- Engage with Internal/External partners (2LoD Cyber Risk teams, CISOs, 1LoD Integral CISO functions, CIO, CTO, T&O, and Internal Audit) and ensure CoE process adheres to all relevant policy, process, standards, and guidelines.
- Lead cross‑functional collaboration, align diverse client needs and drive effective decision‑making and prioritisation concerning scope of work, requirements and product deliverables.
- Standardise the CoE Process and implement QA for the delivery.
- PMO functions: Project monitoring and coordination.
- Review and challenge risk and control assessments resulting from CISO / CIO self‑assessment.
- Conduct targeted reviews on global platforms, risks or projects, assessing IT/cyber risk impacts and required controls from design to go‑live.
- Monitor and challenge IT, Cyber risk metrics (KRIs).
- Determine and report completeness, consistency and quality of data including their sources and thresholds.
- Prepare and analyse monthly information risk management report.
- Lend support to local entities to resolve waiver requests by providing an informed opinion.
- Lend support to local entities for operational resilience programme (DORA) activities.
- Prepare clear, decision‑ready governance reporting for committees and working groups; escalation of issues with urgency and evidence.
Professional Experience
3–5 years of experience related to IT / Cyber Security Risk Management, Cyber GRC or IT / Security Audit. (required)
Education
- Bachelor’s in Computer Science, Engineering or related. (required)
- Professional certifications strongly valued: CISA, CISM, CRISC and/or CISSP. (required)
- Master’s a plus. (preferred)
Languages
- Fluent English is mandatory (C1). (required)
Hard Skills
- Knowledge of ICT Risk frameworks such as NIST, CIS, FFIEC, FAIR, ISO2, ISO31.
- Knowledge of Cybersecurity systems: IAM, network & firewall management, vulnerability/patch management, cloud security architecture, secure SDLC & containerization, encryption/tokenization, DLP, security logging & monitoring, incident detection & response, and offensive security understanding.
- Skills and strategic thinking to review risk profiles and prioritise actions.
- Capacity to leverage existing information to determine independent controls assessments.
- Ability to support and suggest control enhancements.
Soft Skills
- Effective communication.
- Accuracy and attention to detail.
- Critical thinking.
- Interpersonal relationships.
- Problem solving.
- Takes ownership.
- Optimism regarding uncertainty.
Travel
Possibility of making occasional trips to the geographies where Banco Santander is present (e.g. Portugal, UK, Brazil or Mexico).