Empleo / Getnet

Getnet

IT Risk & Compliance Associate

Ubicación
Madrid
Publicada
hace 2 sem.

Qué piden

ImprescindibleISO 27001NISTCOBITRCSAOperational ResilienceDORA

ValorableCISACRISCCISSPCISMITILPagosPSD2

Idiomasinglés C1

La oferta

Risk & Compliance Associate – IT & Cyber Risk WHAT YOU WILL BE DOING As a Risk & Compliance Associate specialized in IT & Cyber Risk, you will play a key role in the identification, assessment, and oversight of technology and cybersecurity risks across our platforms, products, and services. You will act as a second line of defense, providing independent challenge to IT/Cyber , ensuring alignment with internal policies and regulatory requirements. We need someone like you to help us on the following fronts: - Identify, assess and monitor IT and Cyber risks across systems, platforms, and digital products - Perform independent risk oversight and challenge over IT, Cybersecurity - Contribute to the definition and evolution of the IT & Cyber Risk Management Framework, aligned with regulatory requirements (e.g. DORA) - Define and monitor Key Risk Indicators (KRIs) and support risk appetite frameworks - Assess risks related to cloud environments, infrastructure, and technology architecture - Evaluate and challenge controls design and effectiveness, ensuring proper risk mitigation - Support the identification and management of ICT third-party / vendor risks - Lead risk assessments (RCSA), control testing and risk reporting activities - Contribute to operational resilience initiatives. (identification of critical services, mapping of dependencies, testing, etc.) - Collaborate with internal stakeholders and local units to ensure consistent risk management practices across subsidiaries - Support internal and external audits and regulatory interactions when required WHAT WE ARE LOOKING FOR EXPERIENCE - +5 years of experience in IT Risk, Cyber Risk or Technology Risk Management, preferably within financial services or regulated environments (payments industry is a plus) - Proven experience in second line of defence (risk oversight / control functions) EDUCATION Required - Bachelor’s degree in Computer Engineering, Telecommunications, Mathematics, Physics, or related fields SKILLS & KNOWLEDGE - Knowledge of payments ecosystem, acquiring business and PSD2 is a strong plus - Strong knowledge of IT & Cyber Risk frameworks and standards (e.g. ISO 27001, NIST, COBIT) - Strong knowledge of Operational resilience and business continuity frameworks (i.e: DORA) and its implications on IT and Cyber risk management - Experience in: - Risk assessments (RCSA, control frameworks) - IT controls and cybersecurity practices - Cloud risk and technology environments - Familiarity with Third-party risk management with focus on IT, Cyber and resilience - Strong analytical and problem-solving skills, with the ability to translate technical risks into business impact - Ability to challenge stakeholders constructively and influence decision-making - Excellent communication skills (written and verbal), with experience interacting with senior stakeholders - High level of English DESIRED CERTIFICATIONS - CISA, CRISC, CISSP, CISM or similar - ITIL or other IT governance certifications