Jobs and Careers
SA

Senior Associate, Cyber and Digital Risk Management

Santander
United Statesfull_timeVerifiedPosted 18 Nov 2025
💰 $165,000/yr($93,750/yr$165,000/yr)

About the role

Senior Associate, Cyber and Digital Risk Management

Country: United States of America

Your Journey Starts Here:

Santander is a global leader and innovator in the financial services industry. We believe that our employees are our greatest asset. Our focus is on fostering an enriching journey that empowers you to explore diverse career opportunities while nurturing your personal growth. We are committed to creating an environment where continuous learning and development are prioritized, enabling you to thrive both professionally and personally. Here, you will find ample opportunities to connect and collaborate with talented colleagues from around the world, sharing insights and driving innovation together. Join us at Santander, where you are supported by a culture of engagement and a commitment to your success.

An exciting journey awaits, if you are interested in exploring the possibilities We Want to Talk to You!

The Difference You Make:


The Sr. Associate, Cyber & Digital Risk monitors activities to minimize the company's exposure to information security risks. Activities may include 2nd line of defense independent assurance over technical cyber risk analysis, risk identification and remediation. The incumbent shall support the preservation of digital trust and ensure that the oversight is adequate to minimize compliance and regulatory risk by resolving issues and ensuring adherence to industry good practice frameworks, company and legal standards. Responsible for ensuring that the company's activities adhere to the necessary rules and regulations, and that the company complies with legal/regulatory statutes and jurisdictions, as they relate to the management of cyber and digital risks.

Responsible for independent risk management and assurance activities over the assigned business area’s technology footprint covering Information Security, Cyber Resilience, Cyber Fraud and Data Security (incl. Retention and Disposal) as part of the second line of defense Technology Risk Management organization.

The incumbent develops and maintains an effective Information Security Risk oversight program that enables the assigned business area to comprehensively identify, assess, mitigate, manage, monitor and report technology risk, including performing technical risk reviews of identified domains.

This role is established in the second line of defense and requires collaboration across CISO, Data Office, IT, Operational Risk, Internal Audit and other relevant functional stakeholders within the organization in the management of Cybersecurity risks. An excellent understanding of the evolving regulatory landscape in the US and EU are vital for success in this role.

The day-to-day focus may vary depending on the requirements of the overall second line of defense program priorities directed by the Head of Technology Risk and may include: planned or ad-hoc technical risk review and challenge, review of Technology or Business initiatives, Ongoing risk monitoring activities, Risk reporting, development of technical risk framework and methodologies.

The team to support the oversight of cybersecurity risks will comprise of individuals aligned against the core coverage areas noted above. This is an individual contributor role but will require people and stakeholder management skills to operate effectively in a 2nd line of defense role in a matrix organization.

Key Responsibilities:

  • Establish themselves as one of the second line of defense subject matter experts for key stakeholders in the management of cybersecurity and technology risks across all operating entities
  • Identify and assess cybersecurity risks and participate in the independent and ongoing risk oversight of key technology components of the firm’s digital transformation initiatives.
  • Participate in evaluation of new products / Business changes / projects and assess related cybersecurity risks and impact to the technology risk profile
  • Participate in the evaluation and management of cybersecurity risks related to third-party suppliers involved in technology and business projects
  • Manage and execute targeted risk reviews designed to evaluate information security risks and their effective and sustainable mitigation
  • Perform review and challenge of first line of defense information security risk management processes, data and outcomes (e.g. risk assessments, control evaluations, risk metrics, mitigation plans, risk acceptances etc.) and support the development of risk opinions for various levels of management
  • Analyze information security / cyber risk data from various sources (e.g. external events, control deficiencies, risk register etc.) to identify and measure levels of risk, concentration, trends and patterns
  • Contribute to

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Santander

View company profile →