ActiveJobs
Adidas

Zaragoza Third Party Cybersecurity Risk Management Aragon

Adidas

Full-timeOn-sitePosted 6 October 2026
Apply on Company Site →

Job description

At adidas, every day is a chance to flip the script. An invitation to take everything we know and re-invent it. Do it better. Never settling for good enough. Every day we get up, invent, adapt, improvise, find new ways to collaborate, and do the unexpected. We’re creators, makers and doers. Helping athletes make a difference, not just in their games, but in their lives and in their world. It’s an obsession. We’ve been doing this for more than 75 years. With an unmatched history and tradition of creating iconic products, consumer connections and experiences, we’ve been defining sport culture since the beginning. And we’re never done. Come be a part of shaping the future together with us. IT STARTS WITH YOU MANAGER INFORMATION SECURITY GOVERNANCE INFORMATION SECURITY GOVERNANCE PURPOSE: The role is responsible for all efforts to reach a state of continuous compliance by partnering and engaging with our technology, business, and brand teams to adhere to policies, reduce security risks and maintain compliance in the area of Third Party Mgt. Part of overall duties is to establish, maintain and advance the information security governance framework. KEY ACCOUNTABILITIES: Third Party Risk Management Process Leadership Own and maintain the Third Party Information Security Risk Management process, including procedures, assessment methodology, templates, playbooks and supporting documentation. Define risk-based assessment criteria, supplier segmentation and prioritization logic based on data sensitivity, service criticality, access type, hosting model and business impact. Drive process improvement initiatives to increase assessment quality and scope, cycle time, stakeholder experience and audit readiness. Coordinate the annual review of the TPRM framework, ensuring alignment with information security policies, enterprise risk management and relevant regulatory expectations. Third Party Security Assessments Lead and coordinate security due diligence for new and existing third parties, including suppliers, outsourced service providers, technology vendors, cloud providers and strategic partners. Review third party evidence such as security questionnaires, ISO 27001 certificates, SOC reports, penetration test summaries, business continuity documentation, data protection evidence and remediation plans. Assess security risks across relevant control domains including access management, data protection, cloud security, application security, vulnerability management, incident response, business continuity and subcontractor management. Determine residual risk ratings, document assessment outcomes and recommend risk treatment actions aligned to policy and business context. Third Party Lifecycle Integration Partner with Procurement, Legal, Privacy and business stakeholders to embed security controls into sourcing, onboarding, contracting, renewal, change and exit processes. Provide guidance on minimum information security requirements, contractual security clauses, audit rights, breach notification, subcontractor controls, data return and deletion requirements. Support risk-based contract reviews and supplier negotiations where information security risks are material. Ensure clear handover points between security assessment, contract execution, operational third party management and recurring review cycles. Risk Treatment, Monitoring & Escalation Track remediation actions, exceptions and risk acceptances to closure, ensuring accountable owners, due dates and evidence are documented. Escalate critical third party risks, overdue remediation or unresolved risk acceptance decisions to appropriate governance forums. Define and operate monitoring activities for higher-risk third paties, including periodic reassessments, trigger-based reviews and review of external assurance or security rating information where applicable. Contribute to third-party incident response and post-incident lessons learned when third party security issues occur. Reporting, Metrics & Audit Readiness Develop and maintain management reporting on assessment volumes, risk ratings, remediation status, overdue items, cycle times, critical third parties and key risk themes. Prepare concise executive-level updates, dashboards and decision papers for governance committees and senior stakeholders. Maintain assessment records and evidence in a structured and audit-ready manner. Support internal and external audits, regulatory inquiries and assurance reviews related to third-party information security risk. Tool, Data & Automation Enablement Act as business owner or key user for TPRM module in the GRC tool and support configuration of workflows, forms, reporting and data quality controls. Identify opportunities to automate assessments, evidence collection, reminders, reporting and recurring review triggers. Collaborate with data and technology teams to improve the completeness and reliability of third party risk data. WHAT WE ARE LOOKING FOR: Professional experience 5+ years of experience in information security, IT risk, cyber risk, third party risk management, audit, compliance or governance. 3+ years of practical experience with supplier security assessments, vendor risk management, GRC processes or operational risk management. Experience working in global, matrixed organizations with cross-functional stakeholders. Functional knowledge Strong understanding of information security risk management, third-party due diligence and supplier lifecycle controls. Knowledge of common assurance evidence and frameworks such as ISO 27001, SOC reports, NIST Cybersecurity Framework, NIST SP 800-161, GDPR and cloud security good practices. Understanding of contractual security requirements, risk acceptance, remediation tracking and audit evidence expectations. Skills and behaviours Ability to translate technical security risks into practical business language and actionable recommendations. Strong stakeholder management, communication, facilitation and negotiation skills. Structured, detail-oriented and able to manage multiple priorities in a fast-moving environment. Comfortable using data, dashboards and metrics to drive decisions and process improvement. Ability to influence without direct authority and build trust with senior stakeholders and suppliers. Tools and methods Experience with GRC or TPRM platforms, workflow tools, supplier repositories and reporting dashboards. Ability to work with assessment questionnaires, control mappings, issue registers and evidence repositories. Experience with process improvement, automation or Lean ways of working is beneficial. OTHER RESPONSIBILITIES Enterprise Information Security governance Reviews current and proposed information systems for compliance with the organization’s obligations (including legislation, regulatory, contractual and agreed standards/policies) and adherence to overall strategy. Provides specialist advice to those accountable for governance to correct compliance issues. Information governance Assesses and manages risks around the use of information. Provides reports on the consolidated status of information controls to inform effective decision making. Recommends remediation actions as required. Ensures that information is presented effectively. Information security Provides advice and guidance on security strategies to manage identified risks and ensure adoption and adherence to standards. Obtains and acts on vulnerability information and conducts security risk assessments, business impact analysis and accreditation on complex information systems. Investigates major breaches of security and recommends appropriate control improvements. Contributes to development of information security policy, standards and guidelines. Information assurance Interprets information assurance and security policies and applies these in order to manage risks. Provides advice and guidance to ensure adoption of and adherence to information assurance architectures, strategies, policies, s

Verified and listed by ActiveJobs. Applications are made directly on Adidas's own career page — we never sit in the middle.