← Back to job listings
GE
IT Risk & Compliance Associate
getnet · Spain - Boadilla del Monte, Madrid
About The Role
Risk & Compliance Associate – IT & Cyber Risk
WHAT YOU WILL BE DOING
As a Risk & Compliance Associate specialized in IT & Cyber Risk, you will play a key role in the identification, assessment, and oversight of technology and cybersecurity risks across our platforms, products, and services.
You will act as a second line of defense, providing independent challenge to IT/Cyber , ensuring alignment with internal policies and regulatory requirements.
We need someone like you to help us on the following fronts
- Identify, assess and monitor IT and Cyber risks across systems, platforms, and digital products
- Perform independent risk oversight and challenge over IT, Cybersecurity
- Contribute to the definition and evolution of the IT & Cyber Risk Management Framework, aligned with regulatory requirements (e.g. DORA)
- Define and monitor Key Risk Indicators (KRIs) and support risk appetite frameworks
- Assess risks related to cloud environments, infrastructure, and technology architecture
- Evaluate and challenge controls design and effectiveness, ensuring proper risk mitigation
- Support the identification and management of ICT third-party / vendor risks
- Lead risk assessments (RCSA), control testing and risk reporting activities
- Contribute to operational resilience initiatives. (identification of critical services, mapping of dependencies, testing, etc.)
- Collaborate with internal stakeholders and local units to ensure consistent risk management practices across subsidiaries
- Support internal and external audits and regulatory interactions when required
WHAT WE ARE LOOKING FOR
EXPERIENCE
- +5 years of experience in IT Risk, Cyber Risk or Technology Risk Management, preferably within financial services or regulated environments (payments industry is a plus)
- Proven experience in second line of defence (risk oversight / control functions)
EDUCATION
Required
Bachelor’s degree in Computer Engineering, Telecommunications, Mathematics, Physics, or related fields
SKILLS & KNOWLEDGE
- Knowledge of payments ecosystem, acquiring business and PSD2 is a strong plus
- Strong knowledge of IT & Cyber Risk frameworks and standards (e.g. ISO 27001, NIST, COBIT)
- Strong knowledge of Operational resilience and business continuity frameworks (i.e: DORA) and its implications on IT and Cyber risk management
Experience in
- Risk assessments (RCSA, control frameworks)
- IT controls and cybersecurity practices
- Cloud risk and technology environments
- Familiarity with Third-party risk management with focus on IT, Cyber and resilience
- Strong analytical and problem-solving skills, with the ability to translate technical risks into business impact
- Ability to challenge stakeholders constructively and influence decision-making
- Excellent communication skills (written and verbal), with experience interacting with senior stakeholders
- High level of English
DESIRED CERTIFICATIONS
- CISA, CRISC, CISSP, CISM or similar
- ITIL or other IT governance certifications
Similar roles you might like
See all →UU
Clinic Assistant
USC University of Southern California
Salary not disclosedPosted today
H
Large Format Finance Portfolio Strategy & Planning Partner
hp
Salary not disclosedPosted today
U
IT Strategy & Performance Analyst
Unilabs
Salary not disclosedPosted today
SB
Business Risk Audit Analyst
SCH Banco Santander, S.A.
Salary not disclosedPosted today
8R
Customer Service Coordinator
8270 Rhenus Logistics S.A.U.
Salary not disclosedPosted today
8R
Operativo/a de Carga Directa- (Direct Load Parcial y Completos)
8270 Rhenus Logistics S.A.U.
Salary not disclosedPosted today
8R
Carretillero/a
8270 Rhenus Logistics S.A.U.
Salary not disclosedPosted today
8S
Mozo/a de almacén (Temporal).
8845 Sama Logística Aplicada SL
Salary not disclosedPosted today
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
