
IT Security Coordinator - Hybrid Madrid
- Madrid
- Permanente
- Tiempo completo
- As an IT Security Assessments (Penetration Testing) Coordinator within our Security Compliance Competence Centre, you will be the driving force behind our proactive security testing program.
- You will manage the end-to-end lifecycle of multiple IT Security assessment (e.g. penetration testing) engagements, ensuring our critical applications and infrastructure are resilient against evolving cyber threats.
- Process Management: Managing multiple penetration testing projects concurrently, from initiation and scoping through execution, reporting, and remediation tracking. This includes defining test objectives, timelines, and resource allocation in collaboration with service/application owner and technical experts Stakeholder.
- Engagement: Acting as the central point of contact for all penetration testing activities, coordinating with internal stakeholders (Application Owners, Development Leads, Product Owners) and external security vendors.
- Requirements Gathering: Organizing and leading meetings to gather necessary technical and business context to accurately scope penetration tests, ensuring alignment between business needs, technical constraints, and security best practices.
- Vendor Coordination: Managing relationships with external penetration testing vendors, including facilitating communication, ensuring adherence to timelines and deliverables, and reviewing statements of work.
- Logistics & Preparation: Coordinating pre-engagement activities, such as access provisioning, environment setup, and ensuring all necessary documentation is in place.
- Findings Management: Tracking identified vulnerabilities using our Jira and ServiceNow systems, following up with application and service owners to ensure timely remediation, providing guidance, and answering questions related to findings.
- Expert Liaison: Collaborating closely with our senior security experts to ensure the technical accuracy of test scopes, validate findings, and escalate complex technical issues when necessary.
- Reporting & Communication: Providing regular updates and reports on penetration testing progress, findings, remediation status, and key risk indicators to the Head of Security Compliance Competence Center and other relevant stakeholders.
- English C1