Inetum
Inetum

IT & Cybersecurity Risk Manager

Madrid, Spain·Competitive·Hybrid·Mid·Permanent·English: Required

Added 4 days ago

Need a visa?The advert says visa sponsorship isn't available for this role.

What you'll do

  • IT Risk Management:
    • Functional administrator of the GRC platform for Cetelem, providing tool support
    • Ensuring the quality of IT risk assessments across all IT risks
    • IT risk assessment for non-Cyber and non-IT Continuity risks: compliance, obsolescence, governance, etc.
    • Methodological support for IT risk management and assessment.
    • With the objective of controlling and centralizing all IT risk for the entity, interaction with all PF Spain areas, both business and ITG, to help them define and manage the IT risks they are exposed to. This involves modeling, formalizing, and assessing risks (classification, impacted assets, probability and impact, etc.) as well as deciding on risk responses (mitigation, acceptance, etc.). At the corporate level, interaction also occurs with PF Central for all risks that, due to their characteristics, must be known and approved by a higher entity.
  • Cybersecurity Program Management and Coordination with the various IT areas, serving as the single point of contact with PF Central. Acting as the first line of defense and interacting with the various IT departments, managing with them the implementation of the IT controls defined by the entity, collecting the necessary evidence to demonstrate their implementation and effectiveness, while also evaluating the quality of the evidence presented. In the event of control deviations, ensuring that action plans are defined to enable their correct execution:
    • Program management
    • Single point of contact for assessors for all types of follow-up or any information requests
    • Management of PF Spain's dependencies with other intra-group providers
    • Management of dependencies for PF entities for which we provide services
    • Check & Challenge of the situation with the IT Risk areas
  • Management and coordination of indicator campaigns (Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs)) for the IT area, both with the areas and with PF Central. Managing the collection of all KPIs and KRIs related to Cybersecurity, IT Continuity, and Cross-Cutting IT Risk for the entity, as well as interaction with PF Central. In cases of deviation from defined indicator limits, collecting action plans to ensure a return to normalcy

Various activity reports for the area: CODIR, CIO dashboard, Cyber panorama, Entity Panorama, PMS Dashboard, etc.

  • Coordination/preparation of various IT Risk committees, both local and those of PF entities where we provide local information: DORA committees, Cyber panorama, Lateral Movement, etc.
  • Coordination for the preparation of the area's budgets/projects and communication with IT and PF Central financial management.
  • Support for the tasks of the Entity's Permanent Control framework. Acting as the first line of defense and interacting with the various IT departments, managing with them the implementation of the IT controls defined by the entity, collecting the necessary evidence to demonstrate their implementation and effectiveness, while also evaluating the quality of the evidence presented. In the event of control deviations, ensuring that action plans are defined to enable their correct execution.
  • Coordination for the execution of the medium-term IT strategic plan.
  • Single point of contact for IT Risk for any IT audits the area may undergo.

Education & certifications

Preferred technical degree in: Computer Engineering, Software Engineering, Cybersecurity, etc.

A second degree in Business Administration (ADE) will be valued.

We provide you with access to a wide training catalog in technological skills and certifications tailored to the demands of projects and clients. Language training, where you can choose from 12 options. Training in personal skills within the professional sphere. Access to other additional platforms such as Udemy and OpenWebinars.

Languages

  • Medium-high level of English, with the ability to participate in meetings where they may be the organizer, thus requiring a certain agility in oral expression and comprehension.
  • French is desirable.

What you'll get

We offer a flexible compensation package, allowing you to choose different products and model how to distribute them yourself: health insurance, meal vouchers, childcare, transportation card, and training. Additionally, we provide access to corporate group benefits: discounts on various products and services.

Visa & relocation

The contract will be permanent, with flexible office hours and the possibility of teleworking to best balance your personal and professional life. We provide stability and an excellent work environment, made up of the best professionals in the field of Information Management (IIM).

About the company & team

Inetum is a European leader in digital services. The Inetum team, made up of 28,000 consultants and specialists, strives every day to generate a digital impact on businesses, public sector entities, and society. Inetum's solutions aim to contribute to the performance and innovation of its clients, as well as the common good.

Present in 19 countries with a dense network of sites, Inetum partners with major software publishers to tackle the challenges of digital transformation with proximity and flexibility.

Driven by its ambition for growth and scale, Inetum generated sales of €2.5 billion in 2023.

🏆 Top Employer Europe 2025

Tools

Advanced knowledge of Microsoft Office applications, with special attention to Excel.

Certifications

Desirable certifications:

  • ISO 27001 Lead Auditor or ISO 27001 Lead Implementer
  • Certified Information Security Manager (CISM)
  • Certified in Risk and Information Systems Controls (CRISC)

Knowledge

  • ISO 27002: Code of practice for information security controls
  • ISO 31000: Risk management
  • NIST Cybersecurity Framework
  • In general, regulations applicable to the IT area in our environment: GDPR, DORA, PCI DSS, etc.
  • Without being technical, a high-level understanding of the tools/solutions applicable to mitigating IT cybersecurity risk and their link to ISO 27002 and other safeguard catalogs.
  • IT plans, project management, and budgeting

Other skills

While not seeking a senior profile, the candidate must be able to perform their tasks autonomously without requiring continuous supervision.

Additional information

We offer an attractive career path based on experience and personal potential, within a continuously evolving company with solid growth.

This job was automatically translated to English, .

About the company

Inetum

Inetum

Company

View company profile
International company
28000 employees
Apply at Inetum