
Senior Cyber GRC Specialist - SCFGS
Santander · Boadilla del Monte
Job description
Senior Cyber GRC Specialist - SCFGS Country: Spain Santander Consumer Finance Global Services is looking for a Senior Cyber GRC Specialist based out of Madrid. As a Senior Cyber GRC Specialist, you will support the implementation and oversight of the Cyber Transformation Plan, ensuring alignment with corporate cybersecurity policies, regulatory requirements, and risk management frameworks across the organization. You will act as a key partner to local and global stakeholders, driving governance, risk, compliance, and cybersecurity oversight activities while promoting best practices and continuous improvement. We’re shaping the way we work through innovation, cutting-edge technology, collaboration and the freedom to explore new ideas. To succeed in this role, you will be responsible for: Reporting cybersecurity governance, risk and compliance status to Corporate Security Functions and Second Line of Defense stakeholders. Supervising cybersecurity plans and supporting the definition, monitoring and optimization of cybersecurity budgets across entities. Monitoring compliance with cybersecurity policies, standards, regulatory requirements and internal controls. Defining, maintaining and tracking Key Risk Indicators (KRIs), Technology Health (ToH) maps and cybersecurity performance metrics. Managing and overseeing the Cyber Risk Lifecycle, including risk identification, assessment, mitigation and reporting activities. Coordinating the definition and execution of local Cybersecurity Director Plans, ensuring alignment with global cybersecurity strategies and corporate objectives. Assessing existing cybersecurity governance practices and proposing improvements to strengthen security posture and operational effectiveness. Promoting standardization, harmonization and optimization of cybersecurity services, processes and controls across countries. Identifying, sharing and implementing best practices, lessons learned and synergies among local and global teams. Ensuring the effective implementation of cybersecurity regulations, procedures and standards while maintaining strong collaboration with internal and external stakeholders. WHAT YOU’LL BRINGOur people are our greatest strength. Every individual contributes unique perspectives that make us stronger as a team and as an organization. We’re enabling teams to go beyond by valuing who they are and empowering what they bring. The following requirements represent the knowledge, skills, and abilities essential for success in this role. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Professional ExperienceMinimum 4 years of experience in Cybersecurity Governance, Risk & Compliance (GRC), IT Risk Management, Information Security, Audit or related disciplines (Required). Experience working within regulated environments (Required). Experience coordinating cybersecurity governance activities across multiple stakeholders, business units or geographies (Required). LanguageEnglish – Advanced level (minimum B2; C1 preferred) (Required). Spanish – Professional working proficiency (Preferred). Hard SkillsStrong understanding of cybersecurity threats, vulnerabilities, attack vectors and security control deficiencies (Required). Cybersecurity Governance, Risk and Compliance frameworks, including risk assessments, KRIs, RCSA and cyber metrics (Required). Knowledge of cybersecurity regulations, policies, standards and control environments applicable to financial institutions (Preferred). Experience monitoring and managing cybersecurity audits, findings, remediation plans and recommendations (Preferred). Understanding of cybersecurity budgeting and financial management concepts, including CAPEX and OPEX (Preferred). Experience managing and overseeing cybersecurity vendors, contracts and third-party services (Preferred). Knowledge of Business Continuity, Information Security Office governance and resilience frameworks (Preferred). Professional certifications such as CISSP, CISM, CISA, CEH, CSX or equivalent (Preferred). Experience collaborating with local Information Protection teams and global cybersecurity functions in international organizations (Preferred). Soft SkillsStrong analytical and risk-based thinking. Excellent stakeholder management and communication skills. Governance and compliance-oriented mindset. Ability to influence and drive alignment across multiple teams and geographies. Continuous improvement and problem-solving mindset. Strong organizational skills and attention to detail. Proactive approach to risk identification and remediation. Collaboration and teamwork in complex, matrixed environments. If you want to know more about us, follow us on https://es.linkedin.com/company/banco-santander
Verified and listed by ActiveJobs. Applications are made directly on Santander's own career page — we never sit in the middle.