Information Security Risk Manager
hace 14 horas
Estepona
ppMultiSafepay is a leading payment service provider, offering omnichannel and advanced payment solutions to businesses across Europe. We are innovative and fast-growing, building powerful solutions that transform the way our clients do business. We focus on delivering real solutions to their challenges and always stay ahead of the curve. In short, we are a true FinTech. /p pWe're on a mission to make payments simple, secure, and accessible for every business. With powerful in-house technology and deep expertise, our modular platform brings online, in-person, and cross-border payments together in one place — giving merchants the flexibility to scale on their own terms. Through a partnership-first approach, we tackle complexity head‑on, keep payments running smoothly, and boost success rates. It's how we level the playing field for businesses of all sizes and ambitions. /p pWe are looking for an Information Security Risk Manager to act as the primary operational owner of MultiSafepay's ICT Risk Management Framework within the second line of defence. In this role, you will be responsible for the day-to-day execution, monitoring, and reporting of ICT risk and information security activities in line with DORA, ISO 27001, and PCI DSS requirements. You will own the Eramba GRC platform, the ISMS policy suite, and the ICT risk register, providing technical ICT risk input to the Head of Risk Compliance for board‑level reporting. /p h3What you'll be doing: /h3 ul liMaintaining and developing the ICT risk register, executing the RCSA cycle for ICT risk domains, and monitoring key ICT controls including KRI dashboard management /li liOwning the ISMS policy suite in line with ISO 27001, DORA, and MultiSafepay document standards, and coordinating security monitoring oversight from a 2LoD perspective /li liSupporting DORA Chapter II obligations including ICT incident classification and major incident reporting, and monitoring the external threat landscape to translate developments into 2LoD risk signals /li liLeading PCI DSS 2LoD governance as primary owner of PCI DSS v4.0 compliance oversight, coordinating PCI-3DS as a separate project stream, and acting as primary contact for QSA and internal stakeholders /li liOwning the Eramba GRC platform including data structure, user access, and module configuration, and driving its rollout to new modules and processes as the ICT risk framework matures /li liProviding second line of defence oversight of ICT third‑party risk, acting as primary liaison for the annual EY IT audit, and supporting the annual Ant Group IT risk reporting cycle /li /ul h3What you'll need: /h3 ul li5-8 years of experience in ICT risk management, information security, or a related discipline within a highly regulated financial institution /li liDemonstrable experience with DORA (ICT risk management chapter), ISO/IEC 27001, and PCI DSS v4.0 /li liHands‑on experience with a GRC platform such as Eramba or equivalent, including RCSA execution, control monitoring, and KRI reporting /li liA Bachelor's or Master's degree in Information Security, Computer Science, Risk Management, or an equivalent field /li liStrong ability to translate complex technical risks into clear reporting for non‑technical stakeholders, with a structured, process‑oriented working style /li liAbility to constructively challenge first line of defence stakeholders on ICT risk and security topics /li liStrong written and verbal communication skills in English /li /ul h3Nice to have: /h3 ul liRelevant certifications such as ISO 27001 Lead Implementer, CISM, or CRISC /li liPCI DSS certification or demonstrable practical experience /li /ul h3What you'll get from us: /h3 ul liA competitive salary and benefits package /li liFree Spanish classes and optional afterwork sports activities /li liOpportunities for professional growth /li liA diverse role within a dedicated international team of enthusiastic colleagues /li /ul /p #J-18808-Ljbffr