ironquill.tech/board

$ cat jobs/lead-analyst-security-strategy-assurance-outsystems-cc184f953205.json

Lead Analyst, Security Strategy & Assurance

outsystems·EU·Portugal·senior
Apply on himalayas → Get AI match score →
There are NO limits to your career: come shape the future and be part of a truly unique global culture at OutSystems ! About This Role This role offers an excellent opportunity to manage and mature two critical programmes within the OutSystems Security function. As a Lead Analyst, you will guide our Third-Party Risk Management (TPRM) strategy and facilitate enterprise risk activities that shape how we manage risk across our vendor ecosystem. Operating with significant autonomy, you will define the scope for cross-functional initiatives, bridge gaps between current practices and desired outcomes, and mentor colleagues. If you have deep expertise in vendor risk , excel at translating complex goals into structured programmes , and want to make a lasting impact on our security posture, we would like to meet you. Key Responsibilities Lead the TPRM Programme: Define our TPRM strategy, including risk tiering, assessment frameworks, and monitoring cadences for critical vendors. Embed Security by Design: Partner with Digital, Procurement, Legal, and Engineering teams to integrate risk requirements into vendor selection and contracting. Manage Enterprise Risk: Evolve the division's risk register, facilitating workshops with business leaders to identify emerging risks and validate controls. Ensure Audit Readiness: Act as the primary point of contact for internal and external audits, supporting certifications such as ISO 27001, SOC 2, and regional frameworks. Optimise Operations: Architect improvements in evidence collection, risk tracking, and GRC tooling to reduce manual effort and build scalable operating procedures. Monitor the Landscape: Assess the applicability of emerging regulatory requirements (e.g., DORA, NIS2, GDPR) and translate them into actionable programme changes. Qualifications & Requirements Education & Experience: Bachelor’s degree in Information Security or a related field, alongside 7–10 years of experience in risk management or compliance (with 3–4 years f