ING Hubs Poland logo

Senior Third-Party Cyber Assurance Expert

ING Hubs Poland·Salary not specified

Nice to have's

Penetration TestingRed TeamingVulnerability AssessmentsTechnical Security TestingDORANIST Cybersecurity FrameworkISO 27001SOC 2Cloud Security FrameworksNIS2EU Regulatory FrameworksNessusBurp SuiteKali LinuxWiresharkScriptingData AnalyticsAutomation ToolsCISSPCISACISMCRISCOSCPISO 27001 Lead Auditor

Job description

About the Position

Senior Third-Party Cyber Assurance Expert

At ING Hubs Spain, we are building a new Cybersecurity organization from the ground up. This is a unique opportunity to join a recently established and fast-growing international Hub, where you will not only contribute to Third-Party Cyber Risk Management activities but also help shape the future capabilities, processes, and culture of the team.

As a Senior Third-Party Cyber Assurance Expert, you will play a key role in protecting ING against cyber risks arising from external suppliers and service providers that support critical business operations across the bank.

This role combines cybersecurity, risk management, technical assessments, supplier assurance, stakeholder management, and international exposure. You will work closely with global CISO teams, suppliers, risk professionals, and senior stakeholders to independently assess cybersecurity risks and drive improvements across ING's third-party ecosystem.

If you are motivated by investigating complex environments, challenging the status quo, identifying cybersecurity risks, and influencing meaningful improvements, this role offers a unique opportunity to make a global impact.

Responsibilities

  • Plan, organize, and execute risk-based cybersecurity assessments and onsite inspections of ING's critical third-party providers.
  • Independently evaluate the design and effectiveness of cybersecurity controls implemented by suppliers.
  • Assess security governance, technology controls, operational resilience capabilities, and risk management practices.
  • Conduct interviews, documentation reviews, field inspections, configuration assessments, and technical security evaluations.
  • Identify cybersecurity risks, control weaknesses, and potential vulnerabilities impacting ING.
  • Analyze findings and translate technical gaps into clear business risks and actionable recommendations.
  • Support the execution and evaluation of security testing activities, including penetration testing and red teaming results where applicable.
  • Produce professional reports and executive-ready dashboards for senior management.
  • Support ING's Third-Party Risk Management and Operational Resilience objectives under DORA and other regulatory frameworks.
  • Collaborate with global security, risk, procurement, architecture, and audit teams.
  • Contribute to continuous improvement initiatives within Third-Party Cyber Risk Management.
  • Stay current on emerging threats, technologies, industry trends, and cybersecurity best practices.

Requirements

  • Bachelor's or Master's degree in Computer Science, Information Security, Cybersecurity, IT Engineering, IT Risk Management, IT Audit, or related disciplines.
  • 3-6 years of professional experience in Cybersecurity, IT Audit, Cyber Risk Management, Third-Party Risk Management, Information Security, or similar fields.
  • Strong understanding of cybersecurity technologies and architectures.
  • Experience assessing and evaluating IT and cybersecurity controls.
  • Good understanding of risk management, governance frameworks, and the Three Lines Model.
  • Familiarity with operating systems, networks, databases, identity and access management, cloud technologies, web technologies, software development practices, or containerization technologies.
  • Experience performing audits, cybersecurity assessments, supplier reviews, or risk evaluations.
  • Strong analytical and problem-solving skills.
  • Ability to communicate complex technical topics to technical and non-technical audiences.
  • Excellent stakeholder management and influencing skills.
  • Fluency in English, both written and spoken.
  • Ability to work effectively in multicultural and international environments.

Nice to Have

  • Experience within the banking or financial services sector.
  • Experience supporting Operational Resilience or Third-Party Risk Management programs.
  • Experience with penetration testing, red teaming, vulnerability assessments, or technical security testing.
  • Knowledge of:
    • DORA
    • NIST Cybersecurity Framework
    • ISO 27001
    • SOC 2
    • Cloud Security Frameworks
    • NIS2
    • Other EU regulatory frameworks
  • Hands-on experience with tools such as Nessus, Burp Suite, Kali Linux, Wireshark, or similar technologies.
  • Experience with scripting, data analytics, or automation tools.
  • Certifications such as:
    • CISSP
    • CISA
    • CISM
    • CRISC
    • OSCP
    • ISO 27001 Lead Auditor

We Offer

  • Flexible work model with options to work from home and the office.
  • Restaurant card for convenient lunch options.
  • On-site amenities including electric mobility solutions, doctor, hairdresser, gym, and The Good Service.
  • Health insurance for you and your family.
  • Life insurance to protect what matters most to you.
  • Flexible remuneration model with additional services such as nursery, transport card, and training aids.
  • Transport allowance to help you get to the office.
  • Pension plan available after 1 month with ING.

About the Company

We’re building something exciting-and we want you to be part of it. ING is launching the new member of ING Hubs in Spain, an integral part of ING in charge of designing and delivering important technological and operational solutions to make banking frictionless for our customers. ING Hubs play a key role in our ‘Growing the difference’ strategy to become the best European bank. This will be our sixth global hub, joining a network of over 13,000 professionals in the Philippines, Poland, Romania, Slovakia, Türkiye, and Spain.

We have a tech-first mindset, a global impact, and are agile. Sustainability is at the heart of what we do. We believe in diversity, inclusion, and belonging. We’re proud of our international teams and are committed to creating an environment where everyone can thrive.

We’re looking for curious minds, bold builders, and passionate problem-solvers. If you’re looking for a place to find new ways to drive efficiency and provide superior customer value, where your ideas matter, and where you can grow with purpose-we’re looking forward to meeting you.

© ING Hubs Poland. This job description was sourced from the employer's public career page. TheJob is not the employer — we index the posting and route candidates to the source. All content rights and hiring decisions belong to the employer.

ING Hubs Poland logo
ING Hubs Poland

Financial Services,Banking,Risk Management,Data Analysis,IT Engineering

About the Company ING Hubs Poland is one of ING's global competence centres. It designs and delivers technological, operational, and risk solutions to simplify banking. The best experts work on these projects. Products, Services & Tech Stack Core Solutions: Technological, operational, and risk solutions for banking. Technologies & Frameworks: Not specified in the provided text. Project Scope & Target Clients Client Base: Not specified in the provided text. Engineering Scale: Not specified in the provided text.

More at ING Hubs Poland

All 153 roles

Popular searches