¡Activa las notificaciones laborales por email!

Cybersecurity Compliance & Security posture - SDS

Banco Santander SA

Madrid

Híbrido

EUR 45.000 - 65.000

Jornada completa

Hoy
Sé de los primeros/as/es en solicitar esta vacante

Descripción de la vacante

A prominent financial services institution in Madrid is seeking a Cybersecurity Engineer with at least 4 years of experience. You will lead vulnerability management efforts, develop compliance tools, and implement security frameworks in both cloud and on-premises environments. Strong technical background and hybrid work conditions with travel opportunities are offered. Ideal candidates should have a relevant degree and security certifications.

Servicios

Career plan with growth
Competitive salary and bonus
Financial benefits (e.g., favorable loan terms, pension plan)
Continuous technical training

Formación

  • 2–3 years of IT / Cybersecurity experience, preferably in Public Cloud.
  • Certifications in security (CISA, CSX, CEH, CISSP, OSCP) and cloud platforms.

Responsabilidades

  • Lead and implement vulnerability management and hardening strategies.
  • Develop automations, scripts, and utilities for compliance processes.
  • Support compliance by implementing market-standard control frameworks.
  • Collaborate on compliance initiatives across on-premises and public cloud.

Conocimientos

IT / Cybersecurity experience
Development tools and languages
Self-learning
DevSecOps mindset
Strong English communication

Educación

Degree or professional training in information technology and cybersecurity

Herramientas

Python
PowerShell
Bash
PowerBI
Terraform
Descripción del empleo
Overview

Cybersecurity Compliance & Security posture - SDS Country: Spain. Santander Digital Services (SDS), the technology and operations arm of Santander, is building a team of cybersecurity professionals to support risk, compliance and security posture across cloud and on‑premises environments. We are looking for an engineer of cybersecurity for our offices in Boadilla del Monte with at least 4 years of experience in cybersecurity.

Our team operates with Agile and DevSecOps methodologies, embracing top technologies and a strong focus on business value and user experiences. We offer opportunities to work on high‑impact projects within a global financial services environment.

Responsibilities
  • Lead and implement the strategy for vulnerability management and hardening across the group, in the Global – Risk Control & Assurance team, covering multiple areas of work.
  • Develop automations, scripts and utilities to support Compliance, Hardening and SSDLC processes.
  • Develop a platform for reporting hardening and SSDLC non‑compliances, and create a framework to help entities prioritize and resolve findings.
  • Support Compliance and Hardening processes by supervising and implementing market‑standard control frameworks (e.g., CIS, CSA, NIST) with centralized Compliance tools for both Public Cloud and On‑Prem environments.
  • Develop and implement detective/preventive controls (validations with CSPM and Compliance tools, validations in IaC, Config Rules, Azure Policies, Google Policies) using risk‑based approaches.
  • Collaborate with CTO Architecture teams and other Cybersecurity towers to coordinate compliance and SSDLC initiatives across on‑premises and public cloud environments.
  • Participate in PoCs and evaluations of new cloud compliance and monitoring technologies.
  • Show interest in developing technical and management capabilities with a view to growing within the team.
  • Assist in Cloud governance mechanisms for entities by designing security metrics and reports related to the processes mentioned above.
Qualifications and Requirements
  • 2–3 years of IT / Cybersecurity experience, preferably in Public Cloud.
  • Degree or professional training in information technology and cybersecurity.
  • Certifications and training in security (CISA, CSX, CEH, CISSP, OSCP) and cloud platforms (Security Fundamentals, Security Architecture in Google Cloud Platform, AWS, Azure).
  • Certifications, training or knowledge of development tools and languages (Python, PowerShell, Bash, PowerBI, Terraform, etc.).
  • Strong English knowledge for analyzing technical documentation and intermediate English for meetings with partners in other countries.
  • Ability to self‑learn, with a DevSecOps mindset and a focus on implementing security controls using a development‑oriented approach.
Experience and Working Style
  • Hybrid work model (some days remote, others in the office) with flexible hours.
  • Travel opportunities to collaborate with teams in other countries and international assignments within different units and countries.
  • Continuous technical and innovative training to stay up to date and advance your work.
  • Career plan with growth and reward for effort and performance; competitive salary and bonus; financial benefits (e.g., favorable loan terms, pension plan, life insurance) and social benefits.
How to Learn More

If this sounds like you, follow us or visit our website to learn more about Santander Digital Services.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra un archivo en formato PDF, DOC, DOCX, ODT o PAGES de hasta 5 MB.