Third Party Information Security Operational Risk Analyst

hace 6 días


Madrid, España WTW A tiempo completo

**Description**:
**Secure Partnerships. Strengthen Enterprise Resilience.**

**WTW’s Technology and Cyber Risk, Controls & Regulatory**Engagement function is seeking a skilled **Information Security Operational Risk Analyst**to help manage and oversee **cybersecurity risks related to our third-party vendors.**

In this role, you’ll serve as the vital link between day-to-day operational security monitoring and strategic risk oversight for third-party relationships. You’ll be responsible for **identifying, assessing, and supporting the mitigation of cybersecurity threats**that may arise from **external vendor environments**—contributing directly to the strength and resilience of WTW’s overall risk posture.

If you're analytical, detail-oriented, and passionate about protecting organisations from third-party cyber threats, this is your opportunity to make a meaningful impact in a global environment.

**The Role**

This role will support the ongoing operations of WTW Technology and Cyber Risk and Controls & Regulatory engagement function in:

- Monitoring third-party environments for security incidents, suspicious behavior and policy violations.
- Perform security risk assessments on vendors and service providers based on threat intelligence and business context.
- Collaborate with procurement, legal and risk teams to onboard vendors with appropriate security controls and risk mitigations strategies
- Triage and respond to incidents that have the potential to impact business through third party channels
- Contribute to and improve the risk management framework through incident and operational insights.
- Maintain metrics and reports on vendor risk exposure and control maturity.
- Conduct thorough security assessments of suppliers to identify potential risks and vulnerabilities.
- Collaborate with suppliers to develop and implement risk mitigation plans.
- Monitor and review supplier compliance with information security requirements.
- Provide guidance and support to internal teams on supplier risk management practices.
- Stay up to date with the latest information, security trends, threats, and technologies.
- Report on supplier risk management activities.
- Ensure compliance with relevant regulations, standards, and industry best practices.

At WTW, we trust you to know your work and the people, tools and environment you need to be successful. The majority of our colleagues work in a ”hybrid” style, with a mix of remote, in-person and in office interactions dependent on the needs of the team, role and clients. Our flexibility is rooted in trust and “hybrid”(#LI-Hybrid) is not a one-size-fits-all solution. We understand flexibility is key to supporting an inclusive and diverse workforce and so we encourage requests for all types of flexible working as well as location-based arrangements. Please speak to your recruiter to discuss more.

**Qualifications**:
**The Requirements**
- Strong experience in technology role with proven experience of supplier risk management (for example, in projects, technical SME areas etc.).
- Experience of working within a global financial organization.
- Knowledge and experience of Governance, Risk and Controls framework and related processes.
- Familiarity with third party risk management frameworks (NIST, ISO27036, SIG)
- Experience of implementations using Agile approach and practices.
- Experience of technology, cyber risk and supplier risk management.
- Experience and thorough understanding of technology and cyber controls processes.
- Attention to detail and a pre-emptive approach to identifying and mitigating risks.
- Ability to assess and manage information security risks effectively
- Detail-oriented and capable of delivering at a high level of accuracy.
- Proven ability to prioritize conflicting deadlines and priorities and respond quickly to changing priorities.
- Able to interpret & present data and information in the appropriate format for different audiences.
- Knowledge and understanding of Information Security Frameworks and standards (FFIEC, NIST, ISO etc.)
- Ability to translate technical security findings into business risk impacts
- Proven experience in cybersecurity preferably in SOC or threat response team.
- Ability to work as part of a team or solo.
- Excellent Communication skills, especially written English
- Strong stakeholder management
- The ability to foster and grow relationships, constructive challenges and negotiation skills.
- Experience of working in a live operational environment with an understanding of the impact of policy adherence is desirable.

At WTW, we believe difference makes us stronger. We want our workforce to reflect the different and varied markets we operate in and to build a culture of inclusivity that makes colleagues feel welcome, valued and empowered to bring their whole selves to work every day. We are an equal opportunity employer committed to fostering an inclusive work environment throughout our organisation. We embrace all t



  • Madrid, España Ryanair A tiempo completo

    **Ryanair Holdings plc, Europe’s largest airline group, is the parent company of Buzz, Lauda, Malta Air & Ryanair DAC. Carrying over 154 m guests p.a. on more than 2,400 daily flights from 82 bases, the group connects over 200 destinations in 40 countries on a fleet of over 475 aircraft, with a further 210 Boeing 737’s on order, which will enable the...

  • 3rd Party Risk Manager

    hace 5 días


    Madrid, España Audit & Risk Recruitment A tiempo completo

    Job Title:3rd Party Risk Manager - Internal Audit Location:Madrid, Spain Reports to:Head of Internal AuditCompany Overview: Audit & Risk Recruitment is partnering with a global financial services business undergoing a period of strong growth and transformation. As part of this expansion, the company is strengthening its global Internal Audit team and seeking...

  • 3rd Party Risk Manager

    hace 5 días


    Madrid, España Audit & Risk Recruitment A tiempo completo

    Job Title: 3rd Party Risk Manager - Internal AuditLocation: Madrid, SpainReports to: Head of Internal AuditCompany Overview:Audit & Risk Recruitment is partnering with a global financial services business undergoing a period of strong growth and transformation. As part of this expansion, the company is strengthening its global Internal Audit team and seeking...


  • Madrid, España May Business Consulting A tiempo completo

    ¡Hola! En MBC seguimos creciendo y ahora buscamos un **Third Party Risk Management Analyst** para colaborar en importantes proyectos internacionales del sector financiero. **Sobre MBC**: May Business Consulting es una empresa de consultoría internacional que ofrece asesoría en transformación digital, gestión del cambio, eficiencia y control. Tenemos un...


  • madrid, España Planet group A tiempo completo

    A leading technology company is seeking a Third Party Security Assurance Lead to oversee supplier security governance and risk assessments. You will drive security control assurance activities, manage supplier security schedules, and assess supply chain risks. The ideal candidate will have significant experience in supplier security assurance in a fast-paced...


  • madrid, España Ryanair Ltd. A tiempo completo

    Ryanair Labs are currently recruiting for a Vendor Risk Management Analyst to join Europe’s Largest Airline Group! This is a very exciting time to join Ryanair as we look to expand our operation to 800 aircraft and 300 million guests within the next 10 years. Ryanair Labs is the technology brand of Ryanair. Labs is a state of-the-art digital & IT...


  • Madrid, España Ryanair Ltd. A tiempo completo

    Ryanair Labs are currently recruiting for aPor favor, presente su candidatura sin demora si su perfil encaja bien con este puesto, debido al alto nivel de interés.Vendor Risk Management Analystto join Europe’s Largest Airline Group!This is a very exciting time to join Ryanair as we look to expand our operation to 800 aircraft and 300 million guests within...


  • Madrid, España Planet group A tiempo completo

    Join to apply for the Third Party Security Assurance Lead role at Planet5 days ago Be among the first 25 applicantsAbout UsPlanet is a leading technology company transforming payments by putting customer experience first. We offer integrated solutions that include


  • Madrid, España Google A tiempo completo

    **Minimum qualifications**: - Bachelor's degree in a technical field or equivalent practical experience. - 10 years of experience working in an operational audit role. - Experience working in data center environments, including building and operating infrastructure. - Experience with initiating and executing initiatives in a global environment. **Preferred...


  • Madrid, España OneTrust A tiempo completo

    **Strength in Trust**: At OneTrust, we help businesses around the world to make trust a competitive advantage. Our category-defining enterprise platform enables organizations to operationalize trust across privacy, security, data governance, GRC, third-party risk, ethics, and compliance, and ESG. **The Challenge**: We are looking for a dynamic Information...