Senior Associate, Cyber and Digital Risk Management
Company: Santander Holdings USA Inc
Location: Dallas
Posted on: December 1, 2025
|
|
|
Job Description:
Senior Associate, Cyber and Digital Risk Management Country:
United States of America Your Journey Starts Here: Santander is a
global leader and innovator in the financial services industry. We
believe that our employees are our greatest asset. Our focus is on
fostering an enriching journey that empowers you to explore diverse
career opportunities while nurturing your personal growth. We are
committed to creating an environment where continuous learning and
development are prioritized, enabling you to thrive both
professionally and personally. Here, you will find ample
opportunities to connect and collaborate with talented colleagues
from around the world, sharing insights and driving innovation
together. Join us at Santander, where you are supported by a
culture of engagement and a commitment to your success. An exciting
journey awaits, if you are interested in exploring the
possibilities We Want to Talk to You! The Difference You Make: The
Sr. Associate, Cyber & Digital Risk monitors activities to minimize
the company's exposure to information security risks. Activities
may include 2nd line of defense independent assurance over
technical cyber risk analysis, risk identification and remediation.
The incumbent shall support the preservation of digital trust and
ensure that the oversight is adequate to minimize compliance and
regulatory risk by resolving issues and ensuring adherence to
industry good practice frameworks, company and legal standards.
Responsible for ensuring that the company's activities adhere to
the necessary rules and regulations, and that the company complies
with legal/regulatory statutes and jurisdictions, as they relate to
the management of cyber and digital risks. Responsible for
independent risk management and assurance activities over the
assigned business area’s technology footprint covering Information
Security, Cyber Resilience, Cyber Fraud and Data Security (incl.
Retention and Disposal) as part of the second line of defense
Technology Risk Management organization. The incumbent develops and
maintains an effective Information Security Risk oversight program
that enables the assigned business area to comprehensively
identify, assess, mitigate, manage, monitor and report technology
risk, including performing technical risk reviews of identified
domains. This role is established in the second line of defense and
requires collaboration across CISO, Data Office, IT, Operational
Risk, Internal Audit and other relevant functional stakeholders
within the organization in the management of Cybersecurity risks.
An excellent understanding of the evolving regulatory landscape in
the US and EU are vital for success in this role. The day-to-day
focus may vary depending on the requirements of the overall second
line of defense program priorities directed by the Head of
Technology Risk and may include: planned or ad-hoc technical risk
review and challenge, review of Technology or Business initiatives,
Ongoing risk monitoring activities, Risk reporting, development of
technical risk framework and methodologies. The team to support the
oversight of cybersecurity risks will comprise of individuals
aligned against the core coverage areas noted above. This is an
individual contributor role but will require people and stakeholder
management skills to operate effectively in a 2nd line of defense
role in a matrix organization. Key Responsibilities: - Establish
themselves as one of the second line of defense subject matter
experts for key stakeholders in the management of cybersecurity and
technology risks across all operating entities - Identify and
assess cybersecurity risks and participate in the independent and
ongoing risk oversight of key technology components of the firm’s
digital transformation initiatives. - Participate in evaluation of
new products / Business changes / projects and assess related
cybersecurity risks and impact to the technology risk profile -
Participate in the evaluation and management of cybersecurity risks
related to third-party suppliers involved in technology and
business projects - Manage and execute targeted risk reviews
designed to evaluate information security risks and their effective
and sustainable mitigation - Perform review and challenge of first
line of defense information security risk management processes,
data and outcomes (e.g. risk assessments, control evaluations, risk
metrics, mitigation plans, risk acceptances etc.) and support the
development of risk opinions for various levels of management -
Analyze information security / cyber risk data from various sources
(e.g. external events, control deficiencies, risk register etc.) to
identify and measure levels of risk, concentration, trends and
patterns - Contribute to the updating of existing information
security policies and framework or develop new ones that steer the
safe and sound adoption of technologies across the organization -
Monitor external trends and evaluate potential impacts to business
strategy; provide documented analytical insights of the cyber risk
horizon, while ensuring a sound operational and compliance control
environment through establishment of a system of effective and
sustainable internal controls - Be able to analyze, assess and
advise on remediation of regulatory findings, correction of any
inconsistencies and monitors resolution - Prepare information to
enable governance committees / working groups in the management
oversight of cybersecurity and technology risks - Support process
for constructive engagement across the Lines of Defense regarding
differences or conflicts in risk appetite, risk metric
determination or evaluation, issue severity or other areas of
dispute - Initiate timely escalations to the Sr. Director, Cyber &
Digital Risk and to the leadership team What You Bring: To perform
this job successfully, an individual must be able to perform each
essential duty satisfactorily. The requirements listed below are
representative of the knowledge, skill, and/or ability required.
Reasonable accommodations may be made to enable individuals with
disabilities to perform the essential functions. Education: -
Bachelor's Degree in a technical discipline or equivalent work
experience: Computer Science, Information Technology, Information
Systems, Information Security. Required - Master's Degree in
related technical disciplines. Pref - Professional Certifications
in Cybersecurity. Required - Professional Certifications in Cloud
Security (AWS, Azure). Pref Work Experience: - Professional and
practitioner experience of 9 years in one or more areas of
cybersecurity risk management roles in a matrix organization -
Experience in Cybersecurity risk consulting in the financial
services sector, Cyber security audit, Chief Information Security
Office or in a similar second line of defense role is highly
preferred - Experience within a highly regulated environment such
as the financial services industry and knowledge of the current and
evolving regulatory landscape is necessary Skills and Abilities: -
Strong understanding of multiple information security and cyber
risk domains, and knowledge of industry good practice standards -
Experience with execution of technology & cyber risk oversight
programs, preferably in a 2nd or 3rd line of defense - Demonstrated
ability to coordinate oversight activities across different teams -
Knowledge of current and evolving regulatory requirements and
industry best practices in technology and cybersecurity risk
management - Strong experience as a team player, adaptability and
flexibility Technical skills (incl. Tools): - Resilient Security
Architecture - Identity and Access Management - Network / Firewall
Management - Vulnerability and Patch Management - Cloud Security
Architecture - Secure Application Development / Containerization -
Encryption / Tokenization - Data Loss Prevention - Security Logging
and Monitoring - Incident Detection and Response Management -
Offensive Security Competencies and Abilities: - Demonstrated
expertise and track record in information security and cyber risk
management, and ability to perform at an advanced level of
competence. - Strong risk, process, and control validation and/or
assessment skills. - Advanced knowledge of technical risk
management best practices and how to implement them. - A keen sense
of attention to details with a passion for impeccable documentation
while having the ability to multi-task and adapt/adjust to multiple
demands and competing priorities - A high degree of intellectual
curiosity to research, study and assess technical documentation to
support oversight activities - A team player who can coordinate and
drive consensus among different teams and stakeholders having
varying view points - Ability to convey a sense of urgency and
drive issues/projects to closure. - Excellent written and oral
communication skills. - Excellent analytical, organizational and
project management skills. Certifications: - Professional
Certifications in Cybersecurity. Required - Professional
Certifications in Cloud Security (AWS, Azure). Pref It Would Be
Nice For You To Have: - Established work history or equivalent
demonstrated through a combination of work experience, training,
military service, or education. - Experience in Microsoft Office
products. What Else You Need To Know: The base pay range for this
position is posted below and represents the annualized salary
range. For hourly positions (non-exempt), the annual range is based
on a 40-hour work week. The exact compensation may vary based on
skills, experience, training, licensure and certifications and
location. Base Pay Range Minimum: $93,750.00 USD Maximum:
$165,000.00 USD Link to Santander Benefits: Santander Benefits -
2025 Santander OnGoing/NH eGuide (foleon.com) Risk Culture: We
embrace a strong risk culture and all of our professionals at all
levels are expected to take a proactive and responsible approach
toward risk management. EEO Statement: At Santander, we value and
respect differences in our workforce. We actively encourage
everyone to apply. Santander is an equal opportunity employer. All
qualified applicants will receive consideration for employment
without regard to race, color, religion, sex, sexual orientation,
gender identity, national origin, genetics, disability, age,
veteran status or any other characteristic protected by law.
Working Conditions: Frequent minimal physical effort such as
sitting, standing and walking is required for this role. Depending
on location, occasional moving and lifting light equipment and/or
furniture may be required. Employer Rights: This job description
does not list all of the job duties of the job. You may be asked by
your supervisors or managers to perform other duties. You may be
evaluated in part based upon your performance of the tasks listed
in this job description. The employer has the right to revise this
job description at any time. This job description is not a contract
for employment and either you or the employer may terminate your
employment at any time for any reason. What To Do Next: If this
sounds like a role you are interested in, then please apply. We are
committed to providing an inclusive and accessible application
process for all candidates. If you require any assistance or
accommodation due to a disability or any other reason, please
contact us at TAOps@santander.us to discuss your needs. Primary
Location: Coconut Grove, FL, Miami Coconut Grove Corp Other
Locations: Florida-Coconut Grove,Texas-Dallas
Keywords: Santander Holdings USA Inc, Dallas , Senior Associate, Cyber and Digital Risk Management, IT / Software / Systems , Dallas, Texas