Key Responsibilities
Log and track proposed security risk exceptions in the risk management tool.
Gather and validate all necessary information from requestors, ensuring completeness and accuracy of required fields.
Engage and communicate with Team Leads within both the business and Cybersecurity teams.
Proactively follow up with requestors as due dates for risk exceptions approach.
Create and deliver monthly exception reports and ad-hoc reports as required.
Convert overdue security risk exceptions into documented risks and escalate them to relevant stakeholders.
Document and register proposed risks in the Cyber Risk Register.
Gather and analyze data from various stakeholders to assess the impact and likelihood of identified risks.
Develop and document risk mitigation strategies, capturing stakeholder input and potential solutions.
Prepare and present detailed risk presentations using the MMS risk template.
Communicate assessment findings with Risk Owners and coordinate next steps.
Escalate significant risk acceptance proposals to Vice Presidents and the Chief Information Security Officer (CISO) for review and approval.
Produce and deliver monthly risk assessment reports to the CISO, including ad-hoc reports as necessary.
Track and follow up with risk requestors as due dates approach.
Engage in security maturity and Controls testing processes.
Organize interviews with control owners and document results
Collect and review the evidence provided by the control owners
Identify and assign the correct maturity level for each control
Deliver report of the results
Coordinate with KPI owners to gather monthly Key Performance Indicator (KPI) data.
Update the KPI Register with newly collected data and ensure the accuracy of the records.
Identify and highlight KPIs that show concerning trends or are blocked.
Create and distribute monthly KPI reports to stakeholders, emphasizing key areas that require management attention.
Collaborate with the procurement team and other internal stakeholders to ensure that all vendors meeting TPRM criteria are reviewed and assessed accordingly.
Prepare and distribute weekly and monthly TPRM reports, summarizing completed assessments and identified risks.
Track and follow up on identified risks with vendors and internal teams to ensure timely resolution.
Develop, produce, and deliver regular reports to various stakeholders, including the CISO and executive leadership, summarizing risk trends, KPIs, and third-party risks.
Support the Risk Management team in creating ad-hoc reports and presentations as requested.
Ensure clear and concise communication of risk exceptions, risks, and recommendations.
Maintain strong working relationships with individuals and groups involved in managing cybersecurity risks across the organization.
Education, Training and Previous Experience
Candidates will be evaluated primarily on their ability to demonstrate the competencies required to be successful in the role, as described above. For reference, the typical work experience and educational background of candidates in this role are as follows:
Business and Technical Experience
Knowledge and Skills
MediaMarktSaturn Technology is working to make Europe’s number-one consumer electronics retailer thetechnology leader in its industry. To this end, several hundred developers, UX designers and system architectsusing state-of-the-art technology work hand in hand with business owners in agile teams to develop customer-focused technology solutions for more than 6 million customers every day in 13 countries.
Within the Global Technology division, you are part of a strong cross-functional team of software engineers,data scientists and analytics experts to drive the development of our global product data management. Withinthe team and in close collaboration with the business product owner, you will design and develop data andanalytics solutions on our cloud-based technology platform to support our business in product datamanagement.
Technology Hub located in Barcelona, is one of the service units of MediaMarktSaturn Technology to deliver adequate staffing and engineering skills for the agreed deliveries of the global deployment plan for the entire group.
The Cybersecurity Risk Analyst will play a critical role in supporting the organization’s cybersecurity risk management program. This position will be responsible for identifying, documenting, assessing, and reporting on security risks across the enterprise. The role includes managing risk exceptions, conducting risk assessments, and ensuring that third-party vendors comply with the organization's risk management policies. The ideal candidate will be detail-oriented and able to communicate effectively with stakeholders across the business, cyber security, and other teams. The ideal candidate will be willing to learn and improve while striving for the best performance outcome.
?Location: Barcelona, El Prat De Llobregat
Media Markt Saturn Th Services Barcelona
Department: HQ - IT
Entrylevel: Professional Level
Type of Employement: Full Time
Working Hours: 40
Persona: Job Requisition Tech Employee
Recruiter: Joaquin Pardo
Recruiter: Joaquin Pardo Muro