Una candidatura completa en un minuto: currículum y carta de presentación adaptados, listos para enviar.
PagoNxt is seeking a Risk & Compliance Associate specializing in IT and Cyber Risk. You will identify, assess and oversee technology and cybersecurity risks across platforms, ensuring alignment with internal policies and regulatory requirements.
You will act as the second line of defense, challenging IT/Cyber controls and collaborating with stakeholders to strengthen risk management and resilience across subsidiaries.
As a Risk & Compliance Associate specialized in IT & Cyber Risk, you will play a key role in the identification, assessment, and oversight of technology and cybersecurity risks across our platforms, products, and services.
You will act as a second line of defense, providing independent challenge to IT/Cyber , ensuring alignment with internal policies and regulatory requirements.
We need someone like you to help us on the following fronts:
Identify, assess and monitor IT and Cyber risks across systems, platforms, and digital products
Perform independent risk oversight and challenge over IT, Cybersecurity
Contribute to the definition and evolution of the IT & Cyber Risk Management Framework, aligned with regulatory requirements (e.g. DORA)
Define and monitor Key Risk Indicators (KRIs) and support risk appetite frameworks
Assess risks related to cloud environments, infrastructure, and technology architecture
Evaluate and challenge controls design and effectiveness, ensuring proper risk mitigation
Support the identification and management of ICT third-party / vendor risks
Lead risk assessments (RCSA), control testing and risk reporting activities
Contribute to operational resilience initiatives. (identification of critical services, mapping of dependencies, testing, etc.)
Collaborate with internal stakeholders and local units to ensure consistent risk management practices across subsidiaries
Support internal and external audits and regulatory interactions when required
+5 years of experience in IT Risk, Cyber Risk or Technology Risk Management, preferably within financial services or regulated environments (payments industry is a plus)
Proven experience in second line of defence (risk oversight / control functions)
Required
Bachelor’s degree in Computer Engineering, Telecommunications, Mathematics, Physics, or related fields
Knowledge of payments ecosystem, acquiring business and PSD2 is a strong plus
Strong knowledge of IT & Cyber Risk frameworks and standards (e.g. ISO 27001, NIST, COBIT)
Strong knowledge of Operational resilience and business continuity frameworks (i.e: DORA) and its implications on IT and Cyber risk management
Experience in:
IT controls and cybersecurity practices
Cloud risk and technology environments
Familiarity with Third-party risk management with focus on IT, Cyber and resilience
Strong analytical and problem-solving skills, with the ability to translate technical risks into business impact
Ability to challenge stakeholders constructively and influence decision-making
Excellent communication skills (written and verbal), with experience interacting with senior stakeholders
High level of English
CISA, CRISC, CISSP, CISM or similar
ITIL or other IT governance certifications
The PagoNxt entity advertising the job to which you are applying will process your personal information as data controller to assess your suitability for the position and manage the recruitment process.
If you are applying for a job in the EU, the lawful basis to process your data is the necessity to take steps to assess your suitability for the offered position (art. 6.1b GDPR). If applying outside the EU, the lawful basis is your consent. To exercise your privacy rights (including access, rectification, erasure, restrict processing, portability, object and not being subject to automated decisions or any other required by law), please write to the PagoNxt’s entity Data Protection Officer listed in our privacy notice or send an email to privacy@pagonxt.com. You may also submit a complaint to the relevant supervisory authority.
Please read the details of processing in our Privacy Notice: