
Information Security Risk Management Specialist
Liebherr Group
full-time
Posted on:
Location Type: Hybrid
Location: Madrid • Spain
Visit company websiteExplore more
Tech Stack
About the role
- supports the implementation and continuous operation of our Information Security Risk Management Product
- Responsible for identifying, documenting, assessing, and tracking information security risks across the Liebherr group of companies
- Deliver insights through executive-level dashboards and reports
- Maintain and update the risk registers, tracking ownership, mitigation plans, residual risk, and status
- Drive risk management data completeness, accuracy, and traceability of risk decisions
- Collaborate with IT and business representatives, and technology experts to capture and validate risk information
- Conduct qualitative and or quantitative risk assessments for Liebherr companies and from reported security issues
- Track mitigation and treatment plans, monitor implementation progress, and flag delays or unresolved risks
- Develop and maintain security risk management dashboards and reports using business intelligence tools
- Track and report key risk indicators (KRIs), key performance indicators (KPIs), and risk treatment effectiveness
- Contribute to process improvement initiatives for risk assessment and treatment workflows
Requirements
- Bachelor’s or Master’s degree in Cybersecurity, Computer Science, or related field
- 3+ years of working experience in information security, IT security, risk management or related roles
- Certifications such as CISSP, CISM, CRISC are a plus
- Understanding of NIST SP 800-39, NIST CSF, and ISO/IEC 27005 risk management concepts
- Experience in regulated industries (e.g., manufacturing, defense)
- Experience with creating and maintaining risk registers, reporting tools, and producing risk management risk indicators, metrics and reports
- Demonstrated ability to manage stakeholders across IT, OT, engineering, and business management in complex environments
- Good analytical and communication skills to explain risk findings to both technical and non-technical stakeholders
- Fluency in English (written and spoken) is a must; skills in German would be an advantage.
Benefits
- Competitive compensation and benefits package that recognizes your expertise
- Flexible and hybrid working model
- Creative freedom and responsibility to shape processes and solutions in our global transformation
- Continuous learning and development with tailored training and certification opportunities
- Meal vouchers
- Life and accident insurance
- Option to include a premium private health insurance package as part of the flexible remuneration
- A safe, stable and international workplace within a trusted family business that invests in people
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
information securityrisk managementrisk assessmentsrisk registersbusiness intelligence toolskey risk indicatorskey performance indicatorsrisk treatment effectivenessprocess improvementdata completeness
Soft Skills
analytical skillscommunication skillsstakeholder managementcollaborationproblem-solving
Certifications
CISSPCISMCRISC