We believe that we make a difference every day. To do that, we need committed and engaged employees. Our people are accountable for delivering world-class service and they are passionate about making the world a safer and more secure place. Our teams operate with integrity and respect for one another fueled by an entrepreneurial spirit.
What we look for
An effective communicator, you’ll are a confident team player with a genuine passion to make things happen in a dynamic organization. If you’re ready to take on a wide range of responsibilities and are committed to seeking out new ways to make a difference, this role is for you.
Job purpose
Reporting to the Process Security Risk Team Lead, you will be responsible for developing and executing a comprehensive control framework focused on ensuring that security is maintained throughout business processes. Your role will also support the implementation of our organization’s strategies around process security controls by maintaining and developing new ways of doing things and creating business relationships transversally within Technology and other business units.
The position is expected to work with internal stakeholders and take a lead role in analysing key risks, establish regular dialogue between risk and control owners to identify areas for improvement and develop strategies to enhance security of these business processes.
Main Responsibilities
- Maintain and develop our control framework focused on securing business processes that allow effective monitoring, management and mitigation aligned with business objectives associated to the operations of our organization and our technology.
- Identify potential risks within processes and implement risk mitigation strategies and controls.
- Support to develop standards, procedures, policies and improve our positioning through process improvement, policy automation, and the continuous evolution of capabilities and our control framework.
- Document and report control failures and gaps to stakeholders.
- Provide remediation guidance and sometime drives projects to ensure deployment of mitigation actions or process improvements and prepare management reports to track remediation activities.
Required Qualifications
Minimum qualifications
- Bachelor’s within Information Systems, Information/Cyber Security, Finance, Economics, Law or other relevant study.
- A pragmatic approach developed through hard won experience working in GRC departments and direct experience supporting process to:
o Define, create and execute of control framework. It is key also have experienced in documenting security procedures, policies, and standards.
o Perform assessments and conduct compliance and maturity assessments using international standards and best practices from various industries.
o Ensure that all risks and non-conformities are actively managed, monitored, documented, and mitigated if possible. That means, support to analyze the root causes of operational exceptions as well as to assist in the development and completion of risk mitigation.
o Define and tracking KPIs/KRIs and generating reporting adapted for different levels and stakeholders.
o Perform controls audits and executing remediation plans not only internally but also third party and partners and support the completion of business unit specific risk/control self-assessments.
Work experience in a professional environment preferred, including:
o Demonstrated planning and problem-solving skills.
o Thorough understanding of market structures, including relevant regulatory compliance requirements (SOC 2 , GDPR, etc.).
o Demonstrated experience working on activities related to process improvements.
o Demonstrated experience translating functional requirements to small activities.
o Experience organizing and carrying out risk assessment and compliance projects.
o Ability to successfully support audits (external and internal), compile evidence, and organize audit responses.
o Fluent written and verbal communication skills in English.
o Travel availability.
Preferred qualifications / Personal Characteristics
- Relevant security certification like: CIA, CISA, CRISC, ISO 27001
- Proficient with MS Office, project management, and at least one GRC tool (recommended).
- Familiarity with auditing, monitoring, controlling, and process assessment frameworks.
Veure més
No et perdis res!
Uneix-te a la comunitat de wijobs i rep per email les millors ofertes d'ocupació
Mai no compartirem el teu email amb ningú i no t'enviarem correu brossa
Subscriu-te araDarreres ofertes d'ocupació de Dret i Legal a Madrid
Malthus Darwin
International Agent
NovaWorld Courier
Madrid, ES
AIG
Madrid, ES
Crevel Europe
Madrid, ES
Krell Consulting
Madrid, ES
Compliance Officer
4 de maigFinom
GRUPO VITALIA HOME
Madrid, ES
EXPORT COUNTRY MANAGER
3 de maigCL GRUPO INDUSTRIAL
Madrid, ES
Gestor/a de Mercado - Temporal
3 de maigMahou San Miguel
Madrid, ES
Team Leader F/H
3 de maigWalter Learning
Madrid, ES