IT Risk & Compliance Associate

Posted 17 Days Ago
Be an Early Applicant
Boadilla del Monte, Madrid, Comunidad de Madrid, ESP
In-Office
Senior level
Artificial Intelligence • Fintech • Payments • Financial Services
The Role
Oversee IT and cybersecurity risks as a second-line risk function. Responsibilities include risk assessments, control testing, KRI monitoring, risk appetite support, cloud and architecture risk evaluation, third-party risk management, operational resilience, audit support, and regulatory alignment. The role requires translating technical risks into business impact, challenging stakeholders, and contributing to IT and cyber risk frameworks in a regulated environment.
Summary Generated by Built In

Risk & Compliance Associate – IT & Cyber Risk


WHAT YOU WILL BE DOING


As a Risk & Compliance Associate specialized in IT & Cyber Risk, you will play a key role in the identification, assessment, and oversight of technology and cybersecurity risks across our platforms, products, and services.

You will act as a second line of defense, providing independent challenge to IT/Cyber , ensuring alignment with internal policies and regulatory requirements.


We need someone like you to help us on the following fronts:

  • Identify, assess and monitor IT and Cyber risks across systems, platforms, and digital products

  • Perform independent risk oversight and challenge over IT, Cybersecurity

  • Contribute to the definition and evolution of the IT & Cyber Risk Management Framework, aligned with regulatory requirements (e.g. DORA)

  • Define and monitor Key Risk Indicators (KRIs) and support risk appetite frameworks

  • Assess risks related to cloud environments, infrastructure, and technology architecture

  • Evaluate and challenge controls design and effectiveness, ensuring proper risk mitigation

  • Support the identification and management of ICT third-party / vendor risks

  • Lead risk assessments (RCSA), control testing and risk reporting activities

  • Contribute to operational resilience initiatives. (identification of critical services, mapping of dependencies, testing, etc.)

  • Collaborate with internal stakeholders and local units to ensure consistent risk management practices across subsidiaries

  • Support internal and external audits and regulatory interactions when required


WHAT WE ARE LOOKING FOR


EXPERIENCE

  • +5 years of experience in IT Risk, Cyber Risk or Technology Risk Management, preferably within financial services or regulated environments (payments industry is a plus)

  • Proven experience in second line of defence (risk oversight / control functions)


EDUCATION


Required

  • Bachelor’s degree in Computer Engineering, Telecommunications, Mathematics, Physics, or related fields


SKILLS & KNOWLEDGE

  • Knowledge of payments ecosystem, acquiring business and PSD2 is a strong plus

  • Strong knowledge of IT & Cyber Risk frameworks and standards (e.g. ISO 27001, NIST, COBIT)

  • Strong knowledge of Operational resilience and business continuity frameworks (i.e: DORA) and its implications on IT and Cyber risk management

  • Experience in:

  • Risk assessments (RCSA, control frameworks)

  • IT controls and cybersecurity practices

  • Cloud risk and technology environments

  • Familiarity with Third-party risk management with focus on IT, Cyber and resilience

  • Strong analytical and problem-solving skills, with the ability to translate technical risks into business impact

  • Ability to challenge stakeholders constructively and influence decision-making

  • Excellent communication skills (written and verbal), with experience interacting with senior stakeholders

  • High level of English


DESIRED CERTIFICATIONS

  • CISA, CRISC, CISSP, CISM or similar

  • ITIL or other IT governance certifications

Skills Required

  • More than 5 years of experience in IT Risk, Cyber Risk, or Technology Risk Management
  • Experience in second-line risk oversight or control functions
  • Bachelor's degree in Computer Engineering, Telecommunications, Mathematics, Physics, or a related field
  • Knowledge of IT and cybersecurity risk frameworks and standards, including ISO 27001, NIST, or COBIT
  • Knowledge of operational resilience and business continuity frameworks, including DORA
  • Experience with risk assessments, RCSA, and control frameworks
  • Experience with IT controls and cybersecurity practices
  • Experience with cloud risk and technology environments
  • Familiarity with third-party risk management focused on IT, cybersecurity, and resilience
  • Strong analytical, problem-solving, communication, and stakeholder-influence skills
  • High level of English
  • Knowledge of the payments ecosystem, acquiring business, and PSD2
  • CISA, CRISC, CISSP, CISM, or similar certification
  • ITIL or other IT governance certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
2,300 Employees
Year Founded: 2003

What We Do

Getnet is a global financial technology company and leading AI payments provider in Latin America and Iberia. Part of PagoNxt (Santander Group), it offers a high-tech, secure payment platform and gateway solutions, including processing and fraud prevention tools. Getnet empowers merchants of all sizes—from small entrepreneurs to large corporations—to simplify their payment landscape and grow through innovative, frictionless digital payment experiences.

Similar Jobs

Mastercard Logo Mastercard

Account Manager

Blockchain • Fintech • Payments • Consulting • Cryptocurrency • Cybersecurity • Quantum Computing
Hybrid
Madrid, Comunidad de Madrid, ESP
38800 Employees

Pfizer Logo Pfizer

Senior Manager, HTA, Value and Evidence (HV&E), Genitourinary Cancer

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
30 Locations
121990 Employees
139K-232K Annually

Cloudflare Logo Cloudflare

Account Manager

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
Spain
4400 Employees

Pfizer Logo Pfizer

MSR Oncology Genitourinary tumors(Cataluña)

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office
5 Locations
121990 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees
Vega Thumbnail
Artificial Intelligence • Automotive • Insurance • Transportation
US
43 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account