The English-language job board for Spain

IT Risk & Cybersecurity Manager

Hybrid in Madrid·Full-time·Added 26 days ago

Inetum

87 open roles

Overview

Job details

  • Permanent contract

    Full-time hours.

  • Hybrid

    Office and home days — the ad has the split.

Requirements

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Work in English

    English is required, per the ad.

  • Be near Madrid for hybrid days

    No relocation package mentioned.

  • University degree

    “Titulación técnica preferiblemente de grado en: Ingeniería de computación, ingeniería de software, ciberseguridad, etc.” — per the ad.

This job was automatically translated to English.

Pay & benefits

What you'll get

We provide you with access to a wide training catalog in technological skills and certifications tailored to the demands of projects and clients. Language training, where you can choose from 12 options. Training in personal skills within the professional sphere. Access to other additional platforms such as Udemy and OpenWebinars.

We offer a flexible compensation package, allowing you to choose different products and model how to distribute them yourself: health insurance, meal vouchers, childcare, transportation card, and training. Additionally, we provide access to corporate group benefits: discounts on various products and services.

The contract will be permanent, with flexible office hours and the possibility of teleworking to best balance your personal and professional life. We provide stability and an excellent work environment, made up of the best professionals in the field of Information Management (IIM).

We offer an attractive career path based on experience and personal potential, within a continuously evolving company with solid growth.

Requirements

Education & certifications

Preferred technical degree in: Computer Engineering, Software Engineering, Cybersecurity, etc.

A second degree in Business Administration (ADE) will be valued.

Languages

  • Medium-high level of English, with the ability to participate in meetings where they may be the organizer, thus requiring a certain agility in oral expression and comprehension.
  • French is desirable.

The role

What you'll do

  • IT risk management:  
    • Functional Administrator of the GRC platform for one of our clients in the Insurance sector,  tool support
    • Guarantee the quality of IT risk assessments across all IT risks
    • IT risk assessment for non-Cyber and non-IT continuity risks: compliance, obsolescence, governance, etc.
    • Methodological support for IT risk management and assessment.
    • With the objective being the control and centralization of all the entity's IT risk, interaction occurs with all areas of PF Spain, whether business or ITG, to help them define and manage the IT risks to which they are subject. This involves both the modeling, formalization, and assessment of risks (classification, impacted assets, probability and impact, etc.)  as well as the decision on action regarding the risk (mitigation, acceptance, etc.). At a corporate level, interaction also occurs with PF Central for all those risks which, due to their characteristics, must be known and approved by a higher entity.
  • Cybersecurity Program Management and Coordination with the various IT areas, serving as the single point of contact with PF Central. Acting as the first line of defense and interacting with the various IT departments, managing with them the implementation of the IT controls defined by the entity, collecting the necessary evidence to demonstrate their implementation and effectiveness, while also evaluating the quality of the evidence presented. In the event of control deviations, ensuring that action plans are defined to enable their correct execution:
    • Program management
    • Single point of contact for assessors for all types of follow-up or any information requests
    • Management of PF Spain's dependencies with other intra-group providers
    • Management of dependencies for PF entities for which we provide services
    • Check & Challenge of the situation with the IT Risk areas
  • Management and coordination of indicator campaigns (Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs)) for the IT area, both with the areas and with PF Central. Managing the collection of all KPIs and KRIs related to Cybersecurity, IT Continuity, and Cross-Cutting IT Risk for the entity, as well as interaction with PF Central. In cases of deviation from defined indicator limits, collecting action plans to ensure a return to normalcy

Various activity reports for the area: CODIR, CIO dashboard, Cyber panorama, Entity Panorama, PMS Dashboard, etc.

  • Coordination/preparation of various IT Risk committees, both local and those of PF entities where we provide local information: DORA committees, Cyber panorama, Lateral Movement, etc.
  • Coordination for the preparation of the area's budgets/projects and communication with IT and PF Central financial management.
  • Support for the tasks of the Entity's Permanent Control framework. Acting as the first line of defense and interacting with the various IT departments, managing with them the implementation of the IT controls defined by the entity, collecting the necessary evidence to demonstrate their implementation and effectiveness, while also evaluating the quality of the evidence presented. In the event of control deviations, ensuring that action plans are defined to enable their correct execution.
  • Coordination for the execution of the medium-term IT strategic plan.
  • Single point of contact for IT Risk for any IT audits the area may undergo.

Tools

Advanced knowledge of Microsoft Office applications, with special attention to Excel.

Knowledge

Desirable certifications:

  • ISO 27001 Lead Auditor or ISO 27001 Lead Implementer
  • Certified Information Security Manager (CISM)
  • Certified in Risk and Information Systems Controls (CRISC)
  • ISO 27002: Code of practice for information security controls
  • ISO 31000: Risk management
  • NIST Cybersecurity Framework
  • In general, regulations applicable to the IT area in our environment: GDPR, DORA, PCI DSS, etc.
  • Without being technical, a high-level understanding of the tools/solutions applicable to mitigating IT cybersecurity risk and their link to ISO 27002 and other safeguard catalogs.
  • IT plans, project management, and budgeting

While not seeking a senior profile, the candidate must be able to perform their tasks autonomously without requiring continuous supervision.

About Inetum

Inetum is a global digital services and consulting company that provides technology solutions to businesses and public sector organizations. With a workforce of over 27,000 employees across more than 26 countries, the company specializes in areas such as cloud infrastructure, cybersecurity, application development, and digital transformation services. Inetum operates across various industries, including finance, healthcare, energy, and public administration, offering end-to-end IT services from consulting to managed operations.

In Spain, Inetum has a significant presence with multiple offices and a large team of IT professionals. The company is known for its collaborative work culture and focus on innovation, making it an attractive employer for international tech talent. Inetum actively hires for roles in software development, SAP consulting, Salesforce, and infrastructure management, offering opportunities for career growth and exposure to large-scale projects. For international professionals, Inetum provides a multicultural environment and the chance to work on diverse, high-impact initiatives across Europe and beyond.

Founded
2000
Employees
20,000–30,000
Headquarters
Paris, France
In Spain
Madrid, Barcelona
Website
inetum.com

Good to know if you are moving

  • Inetum has a large presence in Spain with offices in Madrid, Barcelona, and other cities, offering numerous opportunities for IT professionals.
  • The company works on international projects, providing exposure to global clients and cross-border teams.
  • Inetum offers roles in high-demand areas such as SAP, Salesforce, DevOps, and cybersecurity, which are valuable for career advancement.
  • The company provides a multicultural work environment, with employees from various nationalities and backgrounds.
  • Inetum supports professional development through training and certification programs, helping employees stay current with emerging technologies.

In their own words

About the company & team

Inetum is a European leader in digital services. The Inetum team, made up of 28,000 consultants and specialists, strives every day to generate a digital impact on businesses, public sector entities, and society. Inetum's solutions aim to contribute to the performance and innovation of its clients, as well as the common good.

Present in 19 countries with a dense network of sites, Inetum partners with major software publishers to tackle the challenges of digital transformation with proximity and flexibility.

Driven by its ambition for growth and scale, Inetum generated sales of €2.5 billion in 2023.

🏆 Top Employer Europe 2025

All open roles at Inetum

Location

Inetum · Madrid

Loads Google Maps, which may set its own cookies.

WhatsApp
Hybrid in MadridNo Spanish needed
Madrid

Pentester

Inetum2d ago
Hybrid in MadridNo Spanish needed
Hybrid in Bilbao
Hybrid in Barcelona
MadridFluent Spanish

Senior AI Consultant

Inetum1d ago
Hybrid in Madrid
Hybrid in Barcelona
Madrid

Senior .NET Developer

Inetum4d ago
Hybrid in Pamplona
Hybrid in Bilbao
See all 87 jobs