Position
At ING Hubs Spain we are looking for a CAS IT Audit Supervisor to join our Tech Hub Spain Team in Global Corporate Audit Services.
Responsibilities
- Lead and execute IT audits worldwide, with special focus on ING Italy, Spain and Romania, including third‑party providers that support critical processes.
- Organise audit projects, coordinate with senior management, plan fieldwork, and assess the control environment through interviews, documentation review, field inspections, configuration assessments, and technical testing (including penetration tests and/red‑team exercises).
- Produce audit findings and reports that help ING improve its security control environment and mitigate identified risks.
- Manage audit schedules, deliver results to management, and communicate recommendations to stakeholders.
- Travel may be required, with an estimated 8–10 weeks per year.
Qualifications
- Bachelor’s or Master’s degree in Computer Science, IT Engineering, IT Security, IT Risk Management or IT Audit.
- Technical (security) knowledge of key IT layers – operating systems, network infrastructure, database management systems, web technologies, mobile operating systems; plus at least one specialty area such as cloud technologies, programming/development, identity and access management, containers (Docker), or web/mobile applications.
- More than five years’ experience in IT Audit with sound knowledge of IT risk management, governance and the three‑lines‑of‑defence model.
- Proven track record of leading end‑to‑end audits, including planning, execution and reporting.
- Experience performing penetration tests or red‑team exercises.
- Strong knowledge of IT processes and standards – COBIT, ISO 27001, ISO 22001, etc.
- Effective communication skills in English (both written and spoken); experience working in multicultural environments.
- Ability to lead both technical and process audits, manage conflicts, organize fieldwork, and meet deadlines.
- Preferred: familiarity with banking industry regulations such as PSD2, EBA guidelines or DORA.
- Preferred: hands‑on experience in IT administration, operations or development.
- Preferred: experience with vulnerability assessment and pentesting tools, data analytics tools or scripting.
Benefits
Flexible remuneration model with tax‑advantaged benefits that allow access to services such as nursery, transport card, and training aids.