Vendor Risk Analyst - AQUANIMA Country: Spain
AQUANIMA is looking for a VENDOR RISK ANALYST, based in our BOADILLA DEL MONTE (Madrid) office.
WHY YOU SHOULD CONSIDER THIS OPPORTUNITYAt Santander, we are key players in the transformation of the financial sector. Do you want to join us?
At Aquanima, we provide a valuable service to our customers. We are part of the Santander Group and we seek to achieve maximum efficiency for the Group and for external clients through the management of purchasing processes.
Our ultimate and main objective is to maximize savings for our clients, offering our expertise in purchasing across various expense categories in the countries where we have a presence.
In addition, our capabilities allow us to offer other value-added services such as supplier management and contract management.
We are a strategic partner to our customers and suppliers, creating long-term relationships and helping them achieve greater efficiency in their day-to-day operations.
Santander is proud to be an organization that promotes equal opportunities regardless of gender identity, culture, and disability.
Our mission is to contribute to helping more people and businesses prosper. We embrace a strong risk culture, and all professionals at all levels are expected to take a proactive and responsible approach toward risk management.
WHAT YOU WILL BE DOINGAs a Vendor Risk Analyst, you will be responsible for certifying and managing Vendors regarding IT/Cyber and Contingency risks:
Review and challenge of inherent risk scoring of critical services.Certificate critical services/vendors, establish and monitor remediation plans, and issue a residual risk rating.Reporting and collaboration with local CISO and Business Continuity teams regarding risk assessment results and continuous improvement of risk methodology.Helping with periodic reporting to local Cost/Risk areas and respective committees.EXPERIENCEMinimum years of work experience in Cybersecurity/IT Risk/IT audit areas.
EDUCATIONBachelors or Equivalent in Computer Science, Telecommunications engineering, or similar - Cybersecurity/IT Risk/Audit industry certifications (such as CISA, ISO/IEC, CompTIA Security+, CISP, SSCP, CSX Cybersecurity Fundamentals, etc.).
SKILLS & KNOWLEDGEKnowledge of information technology and security certifications and frameworks such as ISAE (SOC), NIST CSF, ISO, ISO, COBIT.Knowledge of IT Audit practices, IT Risk Management, Business Continuity Management, Vulnerability Management, Security testing methodologies (OWASP, OSSTMM).Communication and oral expression in English and Spanish.OTHER INFORMATIONA fluent English level is a must.A strong candidate will also be able to manage multiple tasks simultaneously and be an enthusiastic team player.Effective communication and excellent writing skills.Problem-solving approach.
#J-18808-Ljbffr