Senior IT Risk Officer

Hace 4 días

Bellprat, Cataluña, España Eurofins Jornada completa

Eurofins Scientific is an international life sciences company, providing a unique range of analytical testing services to clients across multiple industries, to make life and our environment safer, healthier and more sustainable. From the food you eat, to the water you drink, to the medicines you rely on, Eurofins laboratories work with the biggest companies in the world to ensure the products they supply are safe, their ingredients are authentic, and labelling is accurate.



Solicitar este puesto es sencillo. Desplácese hacia abajo y haga clic en "Solicitar" para ser considerado para esta posición.

Eurofins is dedicated to delivering testing services that contribute to the health and safety of society and the planet, and to its corporate responsibility to protect the environment and ensure diversity, equity, and inclusion across the entire network of Eurofins companies.


Job Description

As aSenior IT Risk Officer, you will play a key role in identifying, assessing and reducing IT and cybersecurity risks across Eurofins' European businesses.


You will independently perform IT risk assessments across laboratories, business units and IT environments, working closely with IT, security and business teams.


This role requires asolid technical understanding of IT infrastructure and cybersecurity, combined with strong risk assessment, communication and stakeholder management skills.


In addition to IT risk assessments, you will contribute to broader security and resilience initiatives, including phishing campaigns and IT resilience exercises.


The position requires frequent travel across Europe, approximately35–50% of the time.


Your main responsibilities will include:



  • Independently planning and conductingIT and cybersecurity risk assessmentsacross laboratories, regional infrastructure and central IT services.
  • Assessing technical and organizational controls covering areas such asnetwork security, identity and access management, endpoint security, vulnerability management, cloud, logging and monitoring, backup and IT resilience.
  • Identifying technical weaknesses and evaluating their potential impact on business operations.
  • Challenging existing technical implementations and security controls where necessary.
  • Translating technical findings intoclear business risks and pragmatic recommendations.
  • Producing high-quality reports and presenting assessment results to technical teams and management.
  • Following up on agreed remediation actions and evaluating whether identified risks have been adequately addressed.
  • Contributing to the continuous improvement of IT risk assessment methodologies.
  • Maintaining strong relationships with IT, security and business stakeholders.

Qualifications

We are looking for anindependent, technically curious and pragmatic professionalwho is comfortable investigating complex IT environments and challenging established practices when necessary.


You should have:



  • 3–7 years of relevant experiencein cybersecurity, information security, IT risk, IT audit or a related technical IT control function.
  • Experience performingIT risk assessments, security assessments or technical IT audits.
  • A good understanding of risk management and cybersecurity principles.
  • strong general technical understandingof areas such as networking, firewalls, Active Directory / Entra ID, IAM/MFA, endpoint security, vulnerability management, Windows/Linux infrastructure, cloud security, SIEM/logging, backup and disaster recovery.
  • The ability to understand technical architectures, identify realistic security risks and discuss them credibly with infrastructure and security engineers.
  • Strong analytical skills and the ability to distinguish significant risks from theoretical or low-impact issues.
  • Excellent written and verbal communication skills inEnglish, with the ability to communicate technical risks to both technical and non-technical audiences.
  • Strong stakeholder management and negotiation skills.
  • Awillingness to travel frequently across Europe.

Knowledge ofNIS2, EU data protection requirements and common cybersecurity frameworksis considered an advantage.


Education and certifications


A university degree inComputer Science, Cybersecurity, Information Systems, Engineering or another relevant field, or equivalent professional experience.


Relevant certifications such asCISSP, CISM, CISA, CRISC, ISO 27001 or equivalentare an advantage but not mandatory.


Additional Information

We support your development Do you feel you don’t