Third Party Assurance Supervisor
Guarda esta oferta y sigue tu búsqueda
Crea una cuenta gratis para guardar empleos, crear alertas y volver a esta oferta desde tu panel.
Al continuar, aceptas nuestros Términos & Política de Privacidad.
At ING Hubs Spain, we are building a new Cybersecurity organization from the ground up.
This is a unique opportunity to join a recently established and fast-growing international Hub, where you will not only contribute to Third-Party Cyber Risk Management activities but also help shape the future capabilities, processes, and culture of the team.
As a Third-Party Cyber Assurance Supervisor , you will play a key role in protecting ING against cyber risks arising from external suppliers and service providers that support critical business operations across the bank.
This role is fun and non-routine, it combines cybersecurity, risk management, technical assessments, supplier assurance, stakeholder management, and international exposure. You will work closely with global CISO teams, suppliers, risk professionals, and senior Management to independently assess cybersecurity risks and drive improvements across ING’s third-party ecosystem.
If you are motivated by investigating complex environments, challenging the status quo, identifying cybersecurity risks, and influencing meaningful improvements across different industries, this role offers a unique opportunity to make a global impact.
Why is this role exciting?
In this role, you will:
- Assess the cybersecurity posture of critical suppliers supporting ING globally.
- Lead, shape and drive inspections across the ING supply chain.
- Work on real-world cybersecurity risks affecting critical business services.
- Perform independent cybersecurity and physical data centre technical assessments.
- Collaborate with technical experts, suppliers, security teams, auditors, and senior stakeholders.
- Contribute to ING’s Third-Party Risk Management, Operational Resilience, and DORA objectives.
- Gain international exposure through assessments of providers across different countries and industries.
- Develop expertise across multiple technologies, cloud environments, cybersecurity domains, and regulatory frameworks.
- Coach new team members.
- Join a growing Cybersecurity Hub and help shape its future direction.
Your key responsibilities:
As a Third-Party Cyber Assurance Supervisor, you will:
- Lead, plan, organize, and execute risk-based cybersecurity assessments and onsite inspections of ING’s critical third-party providers.
- Together with your team, independently evaluate the design and effectiveness of cybersecurity controls implemented by suppliers.
- Assess security governance, technology controls, operational resilience capabilities, and risk management practices.
- Conduct interviews, documentation reviews, field inspections, configuration assessments, and technical security evaluations.
- Identify cybersecurity risks, control weaknesses, and potential vulnerabilities impacting ING.
- Inspect data centres supporting critical services, including the physical security, environmental controls, power path, antifire systems, etc.
- Analyze findings and translate technical gaps into clear business risks and actionable recommendations.
- Support the execution and evaluation of security testing activities, including penetration testing and red teaming results where applicable.
- Produce professional reports and executive-ready dashboards for senior management.
- Support ING’s Third-Party Risk Management and Operational Resilience objectives under DORA and other regulatory frameworks.
- Collaborate with global security, risk, procurement, operations, and audit teams.
- Contribute to continuous improvement initiatives within Third-Party Cyber Risk Management.
- Stay current on emerging threats, technologies, industry trends, and cybersecurity best practices.
- Identify and implement automation opportunities through agentic artificial intelligence.
Travel may be required as part of certain assessments, with an estimated travel requirement of approximately 6 to 8 weeks per year.
What are we looking for?
We are looking for cybersecurity professionals who combine strong technical knowledge, risk awareness, critical thinking, and excellent communication skills.
Required qualifications
- Bachelor’s or Master’s degree in Computer Science, Information Security, Cybersecurity, IT Engineering, IT Risk Management or IT Audit.
- 7-9 years of professional experience in Cybersecurity, IT Audit, Cyber Risk Management, Third-Party Risk Management, Information Security, or similar fields.
- Strong understanding of cybersecurity technologies and architecture.
- You have a strong knowledge of IT processes and standards, market best practices (COBIT, ISO 27001, ISO 22001, etc.).
- Good understanding of risk management, governance frameworks, and the Three Lines Model. <