Information Security Manager Ii

BBVA
BBVA
Madrid, SpainOn-siteCompetitiveAdded 12 days ago
🇪🇸 Translated from Spanish

This job was originally posted in Spanish and automatically translated to English. You'll most likely need Spanish to apply.

Job Description

Excited to grow your career?

BBVA is a global company with more than 160 years of history that operates in more than 25 countries where we serve more than 80 million customers. We are more than 121,000 professionals working in multidisciplinary teams with profiles as diverse as financiers, legal experts, data scientists, developers, engineers and designers.

Learn more about the area:

The PROTECT unit aims to improve the security level of BBVA's different areas and technologies globally by detecting risks and threats and offering preventive mitigation solutions.

About the job:

The person joining this role will have the following main functions:

  • Performing tasks related to ethical hacking of applications, networks, and systems.

  • Performing or supporting security analyses and pentesting tests for any type of environment and/or platform.

  • Improving the procedures, frameworks, and functions of the current service to provide continuous improvement and ensure service delivery according to defined SLAs.

  • Collaborating in the necessary management during activities carried out by the pentester team.

  • Collaborating in all aspects related to the development and evolution of the Global Ethical Hacking unit, participating and contributing improvement ideas for the service.

  • Collaborating in the service transition to move from a reactive approach (scan and report) to a continuous one, prioritizing vulnerabilities based not only on their CVSS criticality, but on threat intelligence (CTI) and the actual exposure of the bank's assets.

In addition to the above, they will also be responsible for:

  • Participating in the execution of ethical hacking exercises on an occasional basis.

  • Supporting the review of deliverables and verification of SLA compliance.

  • Improving the procedures, frameworks, and functions of the entire service to offer continuous improvement and ensure service delivery according to defined SLAs. Performing periodic "Quality Assurance" (QA) on provider reports, identifying if repetitive findings that could be automated are being reported, if critical assets are being omitted, or if PoCs could cause disruptions.

  • Ensuring that the service information or knowledge base is correctly documented.

  • Tracking the status of reported vulnerabilities.

  • Ensuring the review of all assets within BBVA's perimeter, leading the inclusion of new modules that allow the detection of the latest emerging vulnerabilities.

  • Promoting the automation of tasks to make processes more efficient.

  • Participating in the design of vulnerability campaigns for the group's external and internal assets.

  • Periodically reviewing whether the technological tools used by the provider (commercial scanners, custom tools) remain cutting-edge or if it is necessary to adopt new technologies to maintain service quality.

  • Providing evidence of the identification and remediation of exploitable vulnerabilities to internal and external auditors, ensuring compliance with financial regulations (DORA, NIS2, PSD2, PCI-DSS, Bank of Spain/ECB circulars).

We are looking for a person with the following skills:

  • Technical knowledge in cybersecurity strongly oriented towards the offensive side (Hacking, Red Team, Vulnerabilities, etc.)

  • Demonstrated ability to analyze, evaluate, and interpret complex sets of information and data with a solid understanding and application of analytical techniques.

  • Ability to lead teams and operations with humanity, closeness, and empathy toward the team, fostering teamwork without egos or envy. ● Critical and lateral thinking, with the capacity for abstraction and the ability to consider all possible options.

  • Proactivity, initiative, and self-motivation, with a capacity for innovation, creativity, curiosity, and non-conformity.

  • Data-driven decision-making ability.

  • Organizational and management skills; ability to initiate, coordinate, and prioritize responsibilities and follow up on tasks until completion.

  • Good verbal and written communication skills, with writing ability and knowledge in designing and delivering presentations.

  • Passion for what they do and a desire to learn, with proactivity and a drive to continuously improve the service provided.

  • No fear of failure, no fear of risk, the ability to make mistakes and accept them, as well as helping others in such cases.

Requirements:

  • Degree/Bachelor's/Master's in any of the branches of interest for the position: telecommunications or computer science

  • More than 3 years of professional experience in Cybersecurity, preferably focused on offensive security such as Ethical Hacking, vulnerability analysis, Red Team.

  • Professional experience managing a multidisciplinary team oriented toward cybersecurity and in the evaluation of SLAs, KPIs, and deliverable quality.

  • Demonstrated ability to analyze, evaluate, and interpret complex sets of information and data with a solid understanding and application of analytical techniques.

  • Writing and synthesis skills at both technical and executive levels, with the ability to explain the risk of a Zero-Day or a critical flaw to executives or business areas without using excessively technical jargon.

  • Organizational and management skills; ability to initiate, coordinate, and prioritize responsibilities and follow up on tasks until completion.

  • Required English level: B1 (B2 desirable)

  • Previous experience in the banking sector will be valued, understanding the typical architecture (legacy systems, mainframe, transactional architectures, Swift environments).

Technical Capabilities:

  • Knowledge and at least 3 years of experience in application analysis, infrastructure analysis, intrusion testing, and vulnerability management, being able to read and understand a proof of concept (PoC) or an exploit.

  • Knowledge of the main information security standards applicable to Ethical Hacking (OWASP, OWASP Mobile, MITRE ATT&CK, PTES, OSSTMM, ...), mastery of CVSS (and its context limitations), as well as knowing how to perform information searches in both open (OSINT) and private sources.

  • Knowledge and handling of integration and ticketing tools (JIRA) as well as unified vulnerability management (Tenable, Qualys, Gestvul, ...)

  • Knowledge of the main clouds (AWS, GCP, Azure, ...) as well as artificial intelligence platforms (Gemini, OpenAI, ...)

  • Knowledge of cybersecurity and financial regulations (DORA, NIS2, PCI-DSS, SOX ...) and main information security standards (ISO, NIST ...).

  • Certifications related to offensive cybersecurity (OCSP, OSEP, OSCE, CRTO, GWAPT, GCPN, CEH ...) and management and risk certifications (CISM, CISSP, CRISC ...) will be valued.

Skills:

Client Orientation, Empathy, Ethics, Innovation, Proactive Thinking
View original advert (Spanish)

Excited to grow your career?

BBVA is a global company with more than 160 years of history that operates in more than 25 countries where we serve more than 80 million customers. We are more than 121,000 professionals working in multidisciplinary teams with profiles as diverse as financiers, legal experts, data scientists, developers, engineers and designers.

Learn more about the area:

La unidad de PROTECT tiene como objetivo mejorar el nivel de seguridad de los diferentes ámbitos y tecnologías de BBVA a nivel global; detectando riesgos y amenazas y ofreciendo soluciones preventivas de mitigación.

About the job:

La persona que se incorpore al rol tendrá cómo funciones principales:

  • Realización de tareas relacionadas con hacking ético de aplicaciones, redes y sistemas.

  • Realizar o apoyar en los análisis de seguridad y pruebas de pentesting de cualquier tipo de entorno y/o plataforma.

  • Mejorar los procedimientos, marcos y funciones del servicio actual con el fin de ofrecer una mejora continua y asegurar las entregas del servicio acorde a los SLAs definidos.

  • Colaborar en las gestiones necesarias durante las actividades realizadas por el equipo de pentester.

  • Colaborar en todos los aspectos relacionados con el desarrollo y evolución de la unidad de Global Ethical Hacking, participando y aportando ideas de mejora en el servicio.

  • Colaborar en la transición del servicio, para pasar de un enfoque reactivo (escanear y reportar) a uno continuo, priorizando las vulnerabilidades basándose no solo en su criticidad CVSS, sino en la inteligencia de amenazas (CTI) y la exposición real de los activos del banco.

Adicionalmente a lo anterior, también se encargará de:

  • Participar en la ejecución de ejercicios de hacking ético, de forma eventual.

  • Apoyar en la revisión de los entregables y verificación de cumplimiento de SLAs.

  • Mejorar los procedimientos, marcos y funciones de todo el servicio, con el fin de ofrecer una mejora continua y asegurar las entregas del servicio acorde a los SLAs que se definan. Realizando "Quality Assurance" (QA) periódico sobre los informes del proveedor. Identificando si se están reportando hallazgos repetitivos que podrían automatizarse, si se están omitiendo activos críticos, o si las PoCs pueden causar disrupciones.

  • Velar porque la información o base de conocimiento del servicio se encuentre correctamente documentada.

  • Realizar un seguimiento del estado de las vulnerabilidades reportadas.

  • Asegurar la revisión de todos los activos en perímetro de BBVA, liderando la inclusión de nuevos módulos que permitan detectar las últimas vulnerabilidades que aparecen.

  • Promover la automatización de tareas para eficientar los procesos.

  • Participar en el diseño de campañas de vulnerabilidades en los activos externos e internos del grupo.

  • Revisar periódicamente si las herramientas tecnológicas que utiliza el proveedor (escáneres comerciales, herramientas custom) siguen siendo punteras o si es necesario adoptar nuevas tecnologías para mantener la calidad del servicio.

  • Proporcionar evidencias de la identificación y remediación de vulnerabilidades explotables a auditores internos y externos, asegurando el cumplimiento de normativas financieras (DORA, NIS2, PSD2, PCI-DSS, circulares del Banco de España/BCE).

Buscamos una persona con las siguientes skills:

  • Conocimientos técnicos en ciberseguridad muy orientados hacia la parte ofensiva (Hacking, Red Team, Vulnerabilidades, etc.)

  • Capacidad demostrada para analizar, evaluar e interpretar conjuntos complejos de información y datos con una sólida comprensión y aplicación de técnicas analíticas.

  • Capacidad de liderazgo de equipos y operaciones, con humanidad, cercanía y empatía hacia el equipo, que fomente el trabajo en equipo sin egos ni envidias. ● Pensamiento crítico y lateral, con capacidad de abstracción y de poder mirar todas las opciones posibles.

  • Proactividad, iniciativa y automotivación, con capacidad de innovación, creatividad, curiosidad e inconformismo.

  • Capacidad de toma de decisiones basada en datos.

  • Habilidades organizativas y de gestión; capacidad para iniciar, coordinar y priorizar responsabilidades y dar seguimiento a las tareas hasta su finalización.

  • Buenas dotes de comunicación verbal y escrita, con capacidad de redacción, y con conocimientos en diseño y exposición de presentaciones.

  • Pasión por lo que se hace y con ganas de aprender, con proactividad y ganas de mejorar continuamente el servicio prestado.

  • Sin temor a fracasar, sin temor al riesgo, con capacidad de equivocarse y aceptar errores, así como ayudar a otro en dicho caso.

Requisitos:

  • Titulación/Grado/Master en cualquiera de las ramas de interés para el puesto: telecomunicaciones o informática

  • Experiencia profesional de más de 3 años en materia de Ciberseguridad, preferiblemente enfocada a la seguridad ofensiva como Hacking Ético, análisis de vulnerabilidades, Red Team.

  • Experiencia profesional gestionando algún equipo multidisciplinar orientado a la ciberseguridad y en la evaluación de SLAs, KPIs y calidad de entregables.

  • Capacidad demostrada para analizar, evaluar e interpretar conjuntos complejos de información y datos con una sólida comprensión y aplicación de técnicas analíticas.

  • Capacidad de redacción y síntesis tanto a nivel técnico como ejecutivo. Teniendo capacidad para explicar el riesgo de un Zero-Day o un fallo crítico a directivos o áreas de negocio sin usar jerga excesivamente técnica.

  • Habilidades organizativas y de gestión; capacidad para iniciar, coordinar y priorizar responsabilidades y dar seguimiento a las tareas hasta su finalización.

  • Nivel de Inglés requerido: B1 (deseable B2)

  • Se valorará experiencia previa en el sector bancario, entendiendo la arquitectura típica (sistemas legacy, mainframe, arquitecturas transaccionales, entornos Swift).

Capacidades Técnicas:

  • Conocimientos y experiencia de al menos 3 años en análisis de aplicaciones, análisis de infraestructura y test de intrusión y gestión de vulnerabilidades. siendo capaz de saber leer y comprender una prueba de concepto (PoC) o un exploit.

  • Conocimientos de los principales estándares en seguridad de la información de aplicación a Ethical Hacking (OWASP, OWASP Mobile, MITRE ATT&CK ,PTES, OSSTMM,...), dominio de CVSS (y sus limitaciones de contexto), así como saber realizar búsquedas de información tanto en fuentes abiertas (OSINT) como privadas.

  • Conocimiento y manejo de herramientas de integración y ticketing (JIRA) así como de gestión unificada de vulnerabilidades (Tenable, Qualys, Gestvul,...)

  • Conocimientos de las principales nubes (AWS, GCP, Azure,..) así como en plataformas de inteligencia artificial (Gemini, OpenAI,...)

  • Conocimientos de regulaciones de ciberseguridad y ámbito financiero (DORA, NIS2, PCI-DSS, SOX...) y principales estándares en seguridad de la información (ISO, NIST...).

  • Se valorarán las certificaciones relacionadas con la ciberseguridad ofensiva (OCSP, OSEP, OSCE, CRTO, GWAPT, GCPN, CEH ...) y certificaciones de gestión y riesgos (CISM, CISSP, CRISC ...)

Skills:

Client Orientation, Empathy, Ethics, Innovation, Proactive Thinking
Need a visa? No sponsorship mentioned here. Browse visa jobs