Santander Consumer Finance Global Services is looking for a Senior Cyber GRC Specialist based out of Madrid.
As a Senior Cyber GRC Specialist, you will support the implementation and oversight of the Cyber Transformation Plan, ensuring alignment with corporate cybersecurity policies, regulatory requirements, and risk management frameworks across the organization. You will act as a key partner to local and global stakeholders, driving governance, risk, compliance, and cybersecurity oversight activities while promoting best practices and continuous improvement.
We’re shaping the way we work through innovation, cutting-edge technology, collaboration and the freedom to explore new ideas. To succeed in this role, you will be responsible for:
- Reporting cybersecurity governance, risk and compliance status to Corporate Security Functions and Second Line of Defense stakeholders.
- Supervising cybersecurity plans and supporting the definition, monitoring and optimization of cybersecurity budgets across entities.
- Monitoring compliance with cybersecurity policies, standards, regulatory requirements and internal controls.
- Defining, maintaining and tracking Key Risk Indicators (KRIs), Technology Health (ToH) maps and cybersecurity performance metrics.
- Managing and overseeing the Cyber Risk Lifecycle, including risk identification, assessment, mitigation and reporting activities.
- Coordinating the definition and execution of local Cybersecurity Director Plans, ensuring alignment with global cybersecurity strategies and corporate objectives.
- Assessing existing cybersecurity governance practices and proposing improvements to strengthen security posture and operational effectiveness.
- Promoting standardization, harmonization and optimization of cybersecurity services, processes and controls across countries.
- Identifying, sharing and implementing best practices, lessons learned and synergies among local and global teams.
- Ensuring the effective implementation of cybersecurity regulations, procedures and standards while maintaining strong collaboration with internal and external stakeholders.
WHAT YOU’LL BRING
Our people are our greatest strength. Every individual contributes unique perspectives that make us stronger as a team and as an organization. We’re enabling teams to go beyond by valuing who they are and empowering what they bring.
The following requirements represent the knowledge, skills, and abilities essential for success in this role. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Professional Experience
- Minimum 4 years of experience in Cybersecurity Governance, Risk & Compliance (GRC), IT Risk Management, Information Security, Audit or related disciplines (Required).
- Experience working within regulated environments (Required).
- Experience coordinating cybersecurity governance activities across multiple stakeholders, business units or geographies (Required).
- English – Advanced level (minimum B2; C1 preferred) (Required).
- Spanish – Professional working proficiency (Preferred).
- Strong understanding of cybersecurity threats, vulnerabilities, attack vectors and security control deficiencies (Required).
- Cybersecurity Governance, Risk and Compliance frameworks, including risk assessments, KRIs, RCSA and cyber metrics (Required).
- Knowledge of cybersecurity regulations, policies, standards and control environments applicable to financial institutions (Preferred).
- Experience monitoring and managing cybersecurity audits, findings, remediation plans and recommendations (Preferred).
- Understanding of cybersecurity budgeting and financial management concepts, including CAPEX and OPEX (Preferred).
- Experience managing and overseeing cybersecurity vendors, contracts and third-party services (Preferred).
- Knowledge of Business Continuity, Information Security Office governance and resilience frameworks (Preferred).
- Professional certifications such as CISSP, CISM, CISA, CEH, CSX or equivalent (Preferred).
- Experience collaborating with local Information Protection teams and global cybersecurity functions in international organizations (Preferred).
- Strong analytical and risk-based thinking.
- Excellent stakeholder management and communication skills.
- Governance and compliance-oriented mindset.
- Ability to influence and drive alignment across multiple teams and geographies.
- Continuous improvement and problem-solving mindset.
- Strong organizational skills and attention to detail.
- Proactive approach to risk identification and remediation.
- Collaboration and teamwork in complex, matrixed environments.
If you want to know more about us, follow us on https://es.linkedin.com/company/banco-santander
Skills Required
- At least 4 years of experience in Cybersecurity Governance, Risk and Compliance, IT Risk Management, Information Security, Audit, or related disciplines.
- Experience working within regulated environments.
- Experience coordinating cybersecurity governance activities across multiple stakeholders, business units, or geographies.
- Advanced English proficiency at minimum B2 level; C1 preferred.
- Professional working proficiency in Spanish.
- Strong understanding of cybersecurity threats, vulnerabilities, attack vectors, and security control deficiencies.
- Knowledge of cybersecurity Governance, Risk and Compliance frameworks, including risk assessments, KRIs, RCSA, and cyber metrics.
- Knowledge of cybersecurity regulations, policies, standards, and control environments applicable to financial institutions.
- Experience monitoring and managing cybersecurity audits, findings, remediation plans, and recommendations.
- Understanding of cybersecurity budgeting and financial management concepts, including CAPEX and OPEX.
- Experience managing and overseeing cybersecurity vendors, contracts, and third-party services.
- Knowledge of Business Continuity, Information Security Office governance, and resilience frameworks.
- Professional certification such as CISSP, CISM, CISA, CEH, CSX, or equivalent.
- Experience collaborating with local Information Protection teams and global cybersecurity functions in international organizations.
- Strong analytical and risk-based thinking.
- Excellent stakeholder management and communication skills.
- Governance and compliance-oriented mindset.
- Ability to influence and drive alignment across multiple teams and geographies.
- Continuous improvement and problem-solving mindset.
- Strong organizational skills and attention to detail.
- Proactive approach to risk identification and remediation.
- Collaboration and teamwork in complex, matrixed environments.
Santander Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Santander and has not been reviewed or approved by Santander.
-
Retirement Support — A dollar‑for‑dollar 401(k) match up to 6% of eligible pay and immediate vesting are highlighted as core strengths, supporting long‑term savings. This is reinforced by company‑paid disability and life/AD&D coverage that bolster financial security.
-
Leave & Time Off Breadth — Paid time off typically ranges from 18–30 days in the U.S. with 11 paid holidays, plus dedicated volunteer and development time; the UK features a minimum of 25 days with buy/sell options. Some roles also use self‑managed PTO, offering additional flexibility depending on team norms.
-
Parental & Family Support — U.S. parental benefits include 8 weeks paid for all parents and a total of 16 weeks paid for birth mothers, with flexibility for reduced hours around childbirth. Caregiver leave and dependent‑care programs add further family support.
Santander Insights
What We Do
Banco Santander (SAN SM, STD US, BNC LN) is a leading commercial bank, founded in 1857 and headquartered in Spain and one of the largest banks in the world by market capitalization. The group’s activities are consolidated into five global businesses: Retail & Commercial Banking, Digital Consumer Bank, Corporate & Investment Banking (CIB), Wealth Management & Insurance and Payments (PagoNxt and Cards). This operating model allows the bank to better leverage its unique combination of global scale and local leadership. Santander aims to be the best open financial services platform providing services to individuals, SMEs, corporates, financial institutions and governments. The bank’s purpose is to help people and businesses prosper in a simple, personal and fair way. Santander is building a more responsible bank and has made a number of commitments to support this objective, including raising €220 billion in green financing between 2019 and 2030. In the first quarter of 2024, Banco Santander had €1.3 trillion in total funds, 166 million customers, 8,400 branches and 211,000 employees.









