Specialist, Risk Management
- Role
- Security
- Experience
- Mid
Open to ES, GB only. Set where you work from to check your eligibility.
No BS summary
In this role, the Risk Management Specialist III will support and strengthen our risk management and information security programs. You’ll help ensure the organization maintains effective protections across regulatory, contractual, and data privacy requirements while partnering cross-functionally to identify, assess, and mitigate risk.
Core skills
Required skills
Required languages
Summary
In this role, the Risk Management Specialist III will support and strengthen our risk management and information security programs. You’ll help ensure the organization maintains effective protections across regulatory, contractual, and data privacy requirements while partnering cross-functionally to identify, assess, and mitigate risk.
You’ll contribute to key initiatives including information security, vendor and project risk assessments, compliance frameworks (e.g., ISO 27001), and policy development, helping to drive continuous improvement and operational maturity. This role offers the opportunity to build hands-on experience in a collaborative environment while acting as a trusted partner to stakeholders across Lega, ICT, and the broader business.
Requirements
Scope & Responsibilities
Information Security
Supports the deployment and continuous improvement of information security policies, standards, and technical controls
Coordinates Prosci’s ISO 27001:2022 certification and audit activities, including audit scheduling, evidence collection, and external auditor coordination
Administers compliance tooling (e.g., Vanta) to support the information security program and control monitoring
Facilitates ISMS Governance Council activities, including maintaining the enterprise risk register and reporting on risk posture
Conducts information security risk assessments for vendors, projects, and business changes
Tracks, reports, and supports remediation of identified control gaps and audit findings
Defines and monitors information security metrics to measure program effectiveness and progress
Serves as a trusted advisor to stakeholders, partnering cross-functionally to support secure business practices
Data Privacy
Supports the implementation and ongoing management of Prosci’s global data privacy program
Ensures alignment with applicable global privacy regulations (e.g., GDPR, CCPA, PIPEDA, LGPD) and monitors compliance across business practices
Partners with Legal and internal stakeholders to interpret and apply privacy requirements to business operations
Coordinates data subject request (DSR) processes and response activities
Maintains internal privacy policies and external privacy notices
Supports employee privacy training and awareness initiatives
PCI Compliance
Supports the PCI DSS compliance program for outsourced, card-not-present payments under SAQ A scope.
Maintains documentation of PCI scope and ensures ongoing eligibility for SAQ A classification.
Oversees third-party service providers (TPSPs), including maintaining vendor inventories and monitoring compliance status
Supports completion of PCI assessments (SAQ A), including evidence collection, remediation tracking and reporting
Provides guidance and training to internal stakeholders on PCI requirements and secure payment practices
Serves as a point of contact for PCI compliance activities and coordination with internal and external
Client Assurance
Partners with internal stakeholders to understand client security and privacy requirements and expectations
Supports client assurance activities, including responding to security questionnaires and sharing relevant compliance documentation (e.g., ISO certifications)
Risk Evaluation
Supports the development and execution of a structured risk evaluation process for projects and business changes
Reviews initiatives for information security and data privacy risks and escalates findings as appropriate
Provides regular updates to governance forums on risk posture and emerging concerns
Competencies, Skills & Qualifications
Competencies
Communicates Effectively - Strong communication skills Language Requirements: Fluent/Native English
Plans and Aligns
Respond timely to tasks/requests
Ability to work independently and prioritize multiple risks and adapt to needed changes
Balances Stakeholders - Ability to work with all levels of management/team members
Decision Quality
A need to assume responsibility for work
Ability to pull together disparate pieces of information to analyze risk.
Knowledge of and proven ability for attention to detail and strong organizational skills
Analytical thinker
A drive to exceed goals
Qualifications
4 – 7 years’ experience in Risk Management, including knowledge of US/international data privacy regulations, implementation for/maintenance of ISO certification 27001 certification, risk evaluation of new projects and vendors, creation of risk management solutions, review of client DPA and security agreements, and related matters. Bachelor’s degree CIPM Certification
Please note: Only applications and CVs submitted in English will be considered.
#LI-KC1
What you'll do
- Supports the deployment and continuous improvement of information security policies, standards, and technical controls
- Coordinates Prosci’s ISO 27001:2022 certification and audit activities, including audit scheduling, evidence collection, and external auditor coordination
- Administers compliance tooling (e.g., Vanta) to support the information security program and control monitoring
- Facilitates ISMS Governance Council activities, including maintaining the enterprise risk register and reporting on risk posture
- Conducts information security risk assessments for vendors, projects, and business changes
What they require
- 4 – 7 years’ experience in Risk Management, including knowledge of US/international data privacy regulations, implementation for/maintenance of ISO certification 27001 certification, risk evaluation of new projects and vendors, creation of risk management solutions, review of client DPA and security agreements, and related matters.
- Bachelor’s degree
- CIPM Certification
- Strong communication skills
- Ability to work independently and prioritize multiple risks and adapt to needed changes