Vendor Cyber Risk Remediation Analyst

Deloitte

 

Can you imagine taking part in the transformation of leading national and international organizations?

At Deloitte, we are committed to making an impact on society, our clients, and our people.

 

 

As part of the Global Cyber Risk team, the Vendor Cyber Risk Remediation Analyst reports into the Vendor Remediation/Third‑Party Risk function and supports Deloitte’s global program to evaluate, manage and remediate vendor cybersecurity issues.

In this role you will lead remediation efforts for vendor cybersecurity findings, validate remediation evidence, monitor corrective actions, and coordinate risk treatment decisions with vendors, business stakeholders and security teams across the multi‑firm environment. You will maintain accurate remediation records in the TPRM/GRC platform, produce actionable metrics and dashboards, and contribute to process improvements that mature our vendor cyber risk program.

The team

Deloitte Global Cybersecurity protects and enables the firm worldwide through risk‑based security programs, standards and centralized operations. We operate in a collaborative, global environment where continuous improvement, strong governance and cross‑functional partnership deliver impact.

📍Madrid

 

Key responsibilities

  • Lead end‑to‑end remediation of vendor cybersecurity findings: evaluate remediation plans, validate evidence, and monitor commitments through closure or documented risk treatment.
  • Coordinate with vendors, procurement, privacy, legal, business stakeholders and security teams to ensure remediation ownership, risk decisions and supporting rationale are recorded.
  • Maintain remediation workflows and vendor risk records in the TPRM/GRC platform (e.g., ServiceNow); produce operational reports and dashboards for leadership.
  • Oversee higher‑risk vendors: drive timely remediation, monitor for incidents and perform follow‑up due diligence.
  • Support the vendor continuous monitoring program: assess alerts, identify changes in vendor security posture and initiate remediation actions.
  • Review assurance artifacts (questionnaires, audit/penetration test reports, certifications) to evaluate vendor control effectiveness.
  • Contribute to program maturation through process improvements, automation, governance, guidance and training.

 

What we’re looking for

  • 3+ years’ experience in information security, third‑party risk management, IT audit, controls or remediation management.
  • Experience supporting assurance programs: control assessments, risk identification, corrective action planning and remediation.
  • Strong technical knowledge of security risks and controls across cloud, SaaS, infrastructure, data security and application resilience.
  • Capability to evaluate assurance documentation and frameworks such as ISO 27001, SOC 2, SIG/CAIQ and NIST/COBIT.
  • Experience assessing complex vendor solutions (API integrations, cloud‑native services, generative AI platforms) and understanding of AI/ML‑related risks.
  • Strong analytical and communication skills; ability to manage multiple findings, deadlines and stakeholder dependencies.
  • Professional proficiency in English. Bachelor’s degree in cybersecurity, IT, risk management or related field, or equivalent experience.

Preferred

  • Experience in global vendor/TPRM programs, ServiceNow or other GRC/TPRM platforms.
  • Experience developing remediation metrics, dashboards, procedures or training.
  • Relevant certifications such as CISA, CRISC, CISSP, CISM or similar.

 

 

What is it like to work at Deloitte?

🤩 High-impact projects offering long-term growth and continuous learning opportunities.

☯️ Hybrid and flexible working model, with flexible hours and a healthy balance between remote work and collaboration in our offices or at client sites.

⚽ A positive and collaborative work environment, with team-building activities, cultural and sports events throughout the year.

🧘‍♀️ Holistic wellbeing, supported by our physical, mental, and financial health programs, including on-site medical services.

🤲 Social impact, with access to a wide range of national and international volunteering initiatives and pro bono projects where you can contribute your time and talent.

🗣️ A strong feedback culture and continuous learning, within an inclusive environment that promotes equal opportunities and personalized development plans. You may even see yourself at Deloitte University in Paris.

🤝 Exclusive benefits, including a comprehensive benefits portfolio and a flexible compensation plan.

 

Next steps:

If what you have read resonates with you, here is what comes next:

  • Apply to the position by clicking “Apply now” and completing your profile.
  • If your experience matches the role, our Talent team will contact you to get to know you better.

 

Start your journey with Deloitte. We will guide you through each stage of the process until your onboarding.


Deloitte

Deloitte es una Firma de servicios profesionales firmemente comprometida con la igualdad de oportunidades. En este sentido, la Firma aceptará y tramitará solicitudes de todos los sectores de la sociedad, no discriminando por motivos de sexo, expresión de género, raza, religión o creencias, origen étnico o nacional, discapacidad, enfermedad o condición de salud, predisposición genética a sufrir patologías, edad, ciudadanía, estado civil, orientación o identidad sexual, situación socioeconómica o cualquier otra condición o circunstancia personal o social.
Ubicación:  Madrid
Tipo de puesto:  Profesionales con experiencia
Línea de servicio:  T&T
Req Id:  49707