Senior Third-Party Cyber Assurance Expert

Reposted 7 Hours Ago
Be an Early Applicant
Madrid, Comunidad de Madrid, ESP
In-Office
Senior level
Fintech • Payments • Financial Services
The Role
Lead a team of IT auditors to conduct onsite inspections of third-party cybersecurity practices and provide actionable insights to improve risk management.
Summary Generated by Built In

At ING Hubs Spain we are looking for a Senior Third-Party Cyber Assurance Expert

Your role and work environment:

At ING Hubs Spain, we are building a new Cybersecurity organization from the ground up.

This is a unique opportunity to join a recently established and fast-growing international Hub, where you will not only contribute to Third-Party Cyber Risk Management activities but also help shape the future capabilities, processes, and culture of the team.

As a Senior Third-Party Cyber Assurance Expert, you will play a key role in protecting ING against cyber risks arising from external suppliers and service providers that support critical business operations across the bank.

This role combines cybersecurity, risk management, technical assessments, supplier assurance, stakeholder management, and international exposure. You will work closely with global CISO teams, suppliers, risk professionals, and senior stakeholders to independently assess cybersecurity risks and drive improvements across ING's third-party ecosystem.

If you are motivated by investigating complex environments, challenging the status quo, identifying cybersecurity risks, and influencing meaningful improvements, this role offers a unique opportunity to make a global impact.

Why is this role exciting?

In this role, you will:

  • Assess the cybersecurity posture of critical suppliers supporting ING globally
  • Work on real-world cybersecurity risks affecting critical business services
  • Perform independent cybersecurity assessments and onsite inspections worldwide
  • Collaborate with technical experts, suppliers, security teams, auditors, and senior stakeholders
  • Contribute to ING's Third-Party Risk Management, Operational Resilience, and DORA objectives
  • Gain international exposure through assessments of providers across different countries and industries
  • Develop expertise across multiple technologies, cloud environments, cybersecurity domains, and regulatory frameworks
  • Join a growing Cybersecurity Hub and help shape its future direction

Your key responsibilities:

As a Senior Third-Party Cyber Assurance Expert, you will:

  • Plan, organize, and execute risk-based cybersecurity assessments and onsite inspections of ING's critical third-party providers.
  • Independently evaluate the design and effectiveness of cybersecurity controls implemented by suppliers.
  • Assess security governance, technology controls, operational resilience capabilities, and risk management practices.
  • Conduct interviews, documentation reviews, field inspections, configuration assessments, and technical security evaluations.
  • Identify cybersecurity risks, control weaknesses, and potential vulnerabilities impacting ING.
  • Analyze findings and translate technical gaps into clear business risks and actionable recommendations.
  • Support the execution and evaluation of security testing activities, including penetration testing and red teaming results where applicable.
  • Produce professional reports and executive-ready dashboards for senior management.
  • Support ING's Third-Party Risk Management and Operational Resilience objectives under DORA and other regulatory frameworks.
  • Collaborate with global security, risk, procurement, architecture, and audit teams.
  • Contribute to continuous improvement initiatives within Third-Party Cyber Risk Management.
  • Stay current on emerging threats, technologies, industry trends, and cybersecurity best practices.

Travel may be required as part of certain assessments, with an estimated travel requirement of approximately 6 to 8 weeks per year.

What are we looking for?

We are looking for cybersecurity professionals who combine strong technical knowledge, risk awareness, critical thinking, and excellent communication skills.

Required qualifications

  • Bachelor's or Master's degree in Computer Science, Information Security, Cybersecurity, IT Engineering, IT Risk Management, IT Audit, or related disciplines.
  • 3-6 years of professional experience in Cybersecurity, IT Audit, Cyber Risk Management, Third-Party Risk Management, Information Security, or similar fields.
  • Strong understanding of cybersecurity technologies and architectures.
  • Experience assessing and evaluating IT and cybersecurity controls.
  • Good understanding of risk management, governance frameworks, and the Three Lines Model.
  • Familiarity with operating systems, networks, databases, identity and access management, cloud technologies, web technologies, software development practices, or containerization technologies.
  • Experience performing audits, cybersecurity assessments, supplier reviews, or risk evaluations.
  • Strong analytical and problem-solving skills.
  • Ability to communicate complex technical topics to technical and non-technical audiences.
  • Excellent stakeholder management and influencing skills.
  • Fluency in English, both written and spoken.
  • Ability to work effectively in multicultural and international environments.

You'll get extra points for

  • Experience within the banking or financial services sector.
  • Experience supporting Operational Resilience or Third-Party Risk Management programs.
  • Experience with penetration testing, red teaming, vulnerability assessments, or technical security testing.
  • Knowledge of:
  • DORA
  • NIST Cybersecurity Framework
  • ISO 27001
  • SOC 2
  • Cloud Security Frameworks
  • NIS2
  • Other EU regulatory frameworks
  • Hands-on experience with tools such as Nessus, Burp Suite, Kali Linux, Wireshark, or similar technologies.
  • Experience with scripting, data analytics, or automation tools.
  • Certifications such as:
  • CISSP
  • CISA
  • CISM
  • CRISC
  • OSCP
  • ISO 27001 Lead Auditor

What do we offer?

The time you spend at work, the challenges you face or the lessons you get are very important, but… What about your personal life? At ING we want your work to fulfill you in every way, and that is why we take care of even the smallest details.

Check out what is waiting for you!

Be flexible my friend.

Our model is all about flexibility and accountability. Keeping both our customers and our colleagues needs in mind, you determine together which days you work at home and which you come to ING MAD to offer your best self. Do your thing.

Restaurant card.

So that thinking about what to have for lunch doesn’t take up your time or your cravings.

Our house will be your home.

In our offices you can find electric mobility solutions, doctor, hairdresser, gym, The Good Service (to help you with your errands) and much more!

Health insurance.

For you and all your family (spouse/partner and children).

Life insurance.

We help you protect what matters most to you.

Flexible remuneration.

In addition, you will enjoy our flexible remuneration model, through a more tax-advantaged way, you will be able to access other services such as nursery, transport card, training aids…

Transport allowance.

It doesn't matter where you live, we’ll help you get to the office.

Pension plan.

You can benefit from our pension plan after 1 month with us!

Discover ING Hubs Spain

We’re building something exciting—and we want you to be part of it.

ING is launching the new member of ING Hubs in Spain, an integral part of ING in charge of designing and delivering important technological and operational solutions to make banking frictionless for our customers. ING Hubs play a key role in our ‘Growing the difference’ strategy to become the best European bank. This will be our sixth global hub, joining a network of over 13,000 professionals in the Philippines, Poland, Romania, Slovakia, Türkiye and Spain.

What makes us different?

We have a tech-first mindset: We’re not just a bank—we’re a tech company that happens to do banking. Our new hub will be a center of excellence for scalable, fast, and secure technology.

We have global impact: You’ll be working on solutions that serve more than 34 million of customers in over 38 countries.

We are agile: ING was the first bank to adopt agile at scale. We continue to evolve with a collaborative, cross-functional way of working.

Sustainability at the heart of what we do: We have a role to play in defining new ways of doing business that align economic growth with positive environmental and social impact.

At ING, we believe in diversity, inclusion, and belonging. We’re proud of our international teams and are committed to creating an environment where everyone can thrive. We value authenticity, collaboration, and continuous learning.

We’re looking for curious minds, bold builders, and passionate problem-solvers. If you’re looking for a place to find new ways to drive efficiency and provide superior customer value, where your ideas matter, and where you can grow with purpose—we’re looking forward to meeting you.

Skills Required

  • Bachelor's or master's degree in Computer Science, IT Engineering, IT Security, IT Risk Management, or IT Audit
  • More than 6+ years of experience in IT Audit
  • Technical knowledge of IT technologies and security
  • Experience in managing a team
  • Performed penetration tests or red teaming exercises
  • Certifications such as CISA, CISSP, OSCP, ISO27001LA
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Amsterdam
65,710 Employees

What We Do

ING is a pioneer in digital banking and on the forefront as one of the most innovative banks in the world. As ING, we have a clear purpose that represents our conviction of people’s potential. We don’t judge, coach, or tell people how to live their lives. However big or small, modest or grand, we empower people and businesses to realise their vision for a better future. We made the promise to make banking frictionless, removing barriers to progress, and make people confident in their financial decisions. As a global bank we have a huge opportunity – and responsibility – to make an impact for the better. We can play a role by financing change, sharing knowledge, and innovating. Being sustainable is in all the choices we make—as a lender, as a partner and through the services we offer our customers

Similar Jobs

SharkNinja Logo SharkNinja

Manager, Media (Spain & Italy)

Beauty • Robotics • Design • Appliances • Manufacturing
In-Office
Madrid, Comunidad de Madrid, ESP
4000 Employees

UL Solutions Logo UL Solutions

Sales Executive

Automotive • Professional Services • Software • Consulting • Energy • Chemical • Renewable Energy
Hybrid
8 Locations
15000 Employees

Braze Logo Braze

Customer Success Manager

Marketing Tech • Mobile • Software
Easy Apply
Remote or Hybrid
Spain
2000 Employees

Ericsson Logo Ericsson

Financial Data & AI Graduate

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Madrid, Comunidad de Madrid, ESP
88000 Employees

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account