BBVA Logo

BBVA

Cyber & Third-Party Resilience Specialist

Reposted 9 Days Ago
Be an Early Applicant
In-Office
London, Greater London, England
Senior level
In-Office
London, Greater London, England
Senior level
The role involves assessing third-party cyber risks, supporting operational resilience, coordinating risk assessment activities, and ensuring compliance with regulations.
The summary above was generated by AI
Excited to grow your career?

BBVA is a global company with more than 160 years of history that operates in more than 25 countries where we serve more than 80 million customers. We are more than 121,000 professionals working in multidisciplinary teams with profiles as diverse as financiers, legal experts, data scientists, developers, engineers and designers.

The Cybersecurity UK & CE team is responsible for the implementation and continuous improvement of the CIB Corporate Security programme across the region, working closely with technology, risk, and business stakeholders to deliver practical and proportionate security outcomes.

About the job:

Key Responsibilities:

Third-Party Cyber & IT Risk:

  • Assess third-party suppliers’ capability to manage technology and cyber risk.

  • Support evaluation of residual risk following application of relevant control frameworks.

  • Coordinate and perform due diligence and third-party competency validation for Tier 1 and Tier 2 suppliers prior to contract signature.

  • Support contractual embedding of IT risk requirements, including risk-inclusive clauses.

  • Obtain and assess third-party assurance artefacts (e.g. SOC, ISAE) where required.

  • Track and support remediation of third-party risk findings ahead of contract renewal.

  • Contribute to the development of proportionate exit strategies for critical suppliers.
     

Cyber & Third-Party Resilience:

  • Support cyber-led third-party resilience activities, including dependency mapping and concentration risk assessment.

  • Translate supplier risks into resilience considerations for important business services.

  • Support development of realistic cyber and third-party disruption scenarios.

  • Coordinate with relevant stakeholders to ensure resilience considerations are reflected consistently across plans and artefacts.
     

Cyber Operational Resilience:

  • Support cyber operational resilience activities, including service mapping, scenario coordination, and documentation.

  • Assist with preparation and coordination of resilience exercises and follow-up actions.

  • Contribute to clear, regulator-ready narratives aligned to UK and EU expectations.

  • Support consistency of approach across UK & CE offices, including Milan, Paris, and Frankfurt.

What are we looking for?

Experience:

  • At least 5 years of experience in cyber risk, IT risk, third-party risk, or related disciplines within a regulated environment.

  • Exposure to supplier risk assessment, control assurance, or contractual risk considerations.

  • Some experience or interest in operational resilience, business continuity, or technology disruption scenarios.

  • Comfortable working across Cyber, IT, Risk, Procurement, and business teams.
     

Skills & Knowledge:

  • Cyber-literate, with the ability to understand technology services, dependencies, and common failure modes.

  • Familiarity with IT risk control concepts and third-party assurance artefacts (e.g. SOC, ISAE).

  • Awareness of UK Operational Resilience requirements  (BoE, PRA, FCA), and relevant European regulations (EBA, DORA, GDPR).

  • Able to analyse, document, and explain complex supplier and service relationships.
     

Professional Skills:

  • Strong coordination and stakeholder engagement skills.

  • Clear, structured written communication suitable for risk and regulatory contexts.

  • Organised and detail-oriented, with the ability to track actions across multiple parties.

  • Able to operate independently, exercising sound judgement and escalating appropriately when required.

Qualifications:

  • Degree-level education or equivalent experience.

  • Relevant certifications are advantageous but not required.

  • English proficiency required; Spanish is a plus.

Please note that priority will be given to candidates who are elegible to work in the UK.

Skills:

Business, Control Frameworks, Cyber Risks, Due Diligence, Information Technology (IT) Risk, Legal Practices, Risk Assessments, Supplier Risk Assessment, Third Party Risk Management

Top Skills

It Risk Control Concepts
Third-Party Assurance Artefacts

BBVA London, England Office

1 Canada Square, Canary Wharf, London, United Kingdom, E14 5AB

Similar Jobs

An Hour Ago
Hybrid
London, Greater London, England, GBR
Junior
Junior
Artificial Intelligence • Cloud • Machine Learning • Mobile • Software • Virtual Reality • App development
The Ad Review & Integrity Specialist reviews Snap Ad submissions for compliance, collaborates with Sales, and communicates insights to improve approval processes.
Top Skills: JIRASalesforce
An Hour Ago
Hybrid
City of London, City and County of the City of London, England, GBR
Senior level
Senior level
Fintech • Financial Services
Develop and implement quantitative models for interest rate products, focusing on pricing and risk management, partnering with traders and tech teams.
Top Skills: C++JavaPython
An Hour Ago
In-Office or Remote
London, Greater London, England, GBR
Entry level
Entry level
Cloud • Information Technology • Productivity • Security • Software • App development • Automation
As an Account Executive, you'll be responsible for driving sales and building relationships with enterprise clients at Atlassian, leveraging their collaborative tools for effective team solutions.

What you need to know about the London Tech Scene

London isn't just a hub for established businesses; it's also a nursery for innovation. Boasting one of the most recognized fintech ecosystems in Europe, attracting billions in investments each year, London's success has made it a go-to destination for startups looking to make their mark. Top U.K. companies like Hoptin, Moneybox and Marshmallow have already made the city their base — yet fintech is just the beginning. From healthtech to renewable energy to cybersecurity and beyond, the city's startups are breaking new ground across a range of industries.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account