Third Party Cybersecurity Risk Management

At adidas, every day is a chance to flip the script. An invitation to take everything we know and re-invent it. Do it better. Never settling for good enough.

 

Every day we get up, invent, adapt, improvise, find new ways to collaborate,
and do the unexpected. We’re creators, makers and doers. Helping athletes make
a difference, not just in their games, but in their lives and in their world.

 

It’s an obsession.

We’ve been doing this for more than 75 years. With an unmatched history and tradition
of creating iconic products, consumer connections and experiences, we’ve been defining
sport culture since the beginning.

 

And we’re never done.

Come be a part of shaping the future together with us.

 

IT STARTS WITH YOU

 

MANAGER INFORMATION SECURITY GOVERNANCE

INFORMATION SECURITY GOVERNANCE

 

PURPOSE:

The role is responsible for all efforts to reach a state of continuous compliance by partnering and engaging with our technology, business, and brand teams to adhere to policies, reduce security risks and maintain compliance in the area of Third Party Mgt. Part of overall duties is to establish, maintain and advance the information security governance framework.

 

KEY ACCOUNTABILITIES:

Third Party Risk Management Process Leadership

  • Own and maintain the Third Party Information Security Risk Management process, including procedures, assessment methodology, templates, playbooks and supporting documentation.
  • Define risk-based assessment criteria, supplier segmentation and prioritization logic based on data sensitivity, service criticality, access type, hosting model and business impact.
  • Drive process improvement initiatives to increase assessment quality and scope, cycle time, stakeholder experience and audit readiness.
  • Coordinate the annual review of the TPRM framework, ensuring alignment with information security policies, enterprise risk management and relevant regulatory expectations.

Third Party Security Assessments

  • Lead and coordinate security due diligence for new and existing third parties, including suppliers, outsourced service providers, technology vendors, cloud providers and strategic partners.
  • Review third party evidence such as security questionnaires, ISO 27001 certificates, SOC reports, penetration test summaries, business continuity documentation, data protection evidence and remediation plans.
  • Assess security risks across relevant control domains including access management, data protection, cloud security, application security, vulnerability management, incident response, business continuity and subcontractor management.
  • Determine residual risk ratings, document assessment outcomes and recommend risk treatment actions aligned to policy and business context.

Third Party Lifecycle Integration

  • Partner with Procurement, Legal, Privacy and business stakeholders to embed security controls into sourcing, onboarding, contracting, renewal, change and exit processes.
  • Provide guidance on minimum information security requirements, contractual security clauses, audit rights, breach notification, subcontractor controls, data return and deletion requirements.
  • Support risk-based contract reviews and supplier negotiations where information security risks are material.
  • Ensure clear handover points between security assessment, contract execution, operational third party management and recurring review cycles.

Risk Treatment, Monitoring & Escalation

  • Track remediation actions, exceptions and risk acceptances to closure, ensuring accountable owners, due dates and evidence are documented.
  • Escalate critical third party risks, overdue remediation or unresolved risk acceptance decisions to appropriate governance forums.
  • Define and operate monitoring activities for higher-risk third paties, including periodic reassessments, trigger-based reviews and review of external assurance or security rating information where applicable.
  • Contribute to third-party incident response and post-incident lessons learned when third party security issues occur.

Reporting, Metrics & Audit Readiness

  • Develop and maintain management reporting on assessment volumes, risk ratings, remediation status, overdue items, cycle times, critical third parties and key risk themes.
  • Prepare concise executive-level updates, dashboards and decision papers for governance committees and senior stakeholders.
  • Maintain assessment records and evidence in a structured and audit-ready manner.
  • Support internal and external audits, regulatory inquiries and assurance reviews related to third-party information security risk.

Tool, Data & Automation Enablement

  • Act as business owner or key user for TPRM module in the GRC tool and support configuration of workflows, forms, reporting and data quality controls.
  • Identify opportunities to automate assessments, evidence collection, reminders, reporting and recurring review triggers.
  • Collaborate with data and technology teams to improve the completeness and reliability of third party risk data.

 

WHAT WE ARE LOOKING FOR:

Professional experience

  • 5+ years of experience in information security, IT risk, cyber risk, third party risk management, audit, compliance or governance.
  • 3+ years of practical experience with supplier security assessments, vendor risk management, GRC processes or operational risk management.
  • Experience working in global, matrixed organizations with cross-functional stakeholders.

Functional knowledge

  • Strong understanding of information security risk management, third-party due diligence and supplier lifecycle controls.
  • Knowledge of common assurance evidence and frameworks such as ISO 27001, SOC reports, NIST Cybersecurity Framework, NIST SP 800-161, GDPR and cloud security good practices.
  • Understanding of contractual security requirements, risk acceptance, remediation tracking and audit evidence expectations.

Skills and behaviours

  • Ability to translate technical security risks into practical business language and actionable recommendations.
  • Strong stakeholder management, communication, facilitation and negotiation skills.
  • Structured, detail-oriented and able to manage multiple priorities in a fast-moving environment.
  • Comfortable using data, dashboards and metrics to drive decisions and process improvement.
  • Ability to influence without direct authority and build trust with senior stakeholders and suppliers.

Tools and methods

  • Experience with GRC or TPRM platforms, workflow tools, supplier repositories and reporting dashboards.
  • Ability to work with assessment questionnaires, control mappings, issue registers and evidence repositories.
  • Experience with process improvement, automation or Lean ways of working is beneficial.

OTHER RESPONSIBILITIES

Enterprise Information Security governance

  • Reviews current and proposed information systems for compliance with the organization’s obligations (including legislation, regulatory, contractual and agreed standards/policies) and adherence to overall strategy.
  • Provides specialist advice to those accountable for governance to correct compliance issues.

 

Information governance

  • Assesses and manages risks around the use of information.
  • Provides reports on the consolidated status of information controls to inform effective decision making.
  • Recommends remediation actions as required.
  • Ensures that information is presented effectively.

 

Information security

  • Provides advice and guidance on security strategies to manage identified risks and ensure adoption and adherence to standards.
  • Obtains and acts on vulnerability information and conducts security risk assessments, business impact analysis and accreditation on complex information systems.
  • Investigates major breaches of security and recommends appropriate control improvements.
  • Contributes to development of information security policy, standards and guidelines.

 

Information assurance

  • Interprets information assurance and security policies and applies these in order to manage risks.
  • Provides advice and guidance to ensure adoption of and adherence to information assurance architectures, strategies, policies, standards and guidelines.
  • Uses testing to support information assurance.
  • Contributes to the development of policies, standards and guidelines.

 

Business risk management

  • Carries out risk assessment within a defined functional or technical area of business.
  • Uses consistent processes for identifying potential risk events, quantifying and documenting the probability of occurrence and the impact on the business.
  • Refers to domain experts for guidance on specialized areas of risk, such as architecture and environment.
  • Co-ordinates the development of countermeasures and contingency plans.

 

Conformance review

  • Conducts formal reviews of activities, processes, products or services.
  • Collects, collates and examines records as part of specified testing strategies for evidence of compliance with management directives, or the identification of abnormal occurrences.
  • Analyses evidence collated and drafts part or all of formal reports commenting on the conformance found to exist in the reviewed part of an information systems environment.

 

Relationship management

  • Implements stakeholder engagement/communications plan.
  • Deals with problems and issues, managing resolutions, corrective actions, lessons learned and the collection and dissemination of relevant information.
  • Collects and uses feedback from customers and stakeholders to help measure effectiveness of stakeholder management.
  • Helps develop and enhance customer and stakeholder relationships.

 

KEY RELATIONSHIPS

  • Global Tech and Product Areas
  • Respective business function (GOPS, Finance, HR, Brand Marketing, Wholesale/Retail)
  • Procurement
  • Legal
  • HR Management
  • Markets

 

WHAT IF I DON’T CHECK ALL THE BOXES? 

It’s ok if some of the technology or terminology mentioned here are new for you. We’ll happily teach you.
At adidas, we’re keen to increase our team’s diversity of backgrounds and skills, and we’re more interested in the work you will produce than that work you’ve already produced in the past. If you’d love to work with us, then we’d love to hear from you.

 

WHAT WE OFFER:

  • You will be part of a company where digital transformation, innovation and continuous improvement are core principles of our culture.
  • You will join a team of talented and passionate quality engineers, with a lot of opportunities to grow and reach your expectations.
  • You will be part of a highly engaged, multinational with international career opportunities.
  • Individual development, training and a tech community.
  • Hybrid Work Setup: enjoy the advantages of a flexible remote work environment (40% Weekly) combined with the amazing onsite facilities and culture.
  • Competitive salary, benefits and valuable discounts on adidas products.

 

Sound good? Apply here and be part of our tomorrow.

Not the right job for you? There are thousands of opportunities at
adidas around the world. Find the one with your name on it.

 

Want to get a behind the scenes look at our offices?

adidas Careers

 

Check out these videos to see what it’s like to work in our
offices around the world!

 

THROUGH SPORT, WE HAVE THE POWER TO CHANGE LIVES

www.careers.adidas-group.com


At adidas, we strongly believe that embedding diversity, equity, and inclusion (DEI) into our culture and talent processes gives our employees a sense of belonging and our brand a real competitive advantage.

– Culture Starts With People, It Starts With You –

By recruiting talent and developing our people to reflect the rich diversity of our consumers and communities, we foster a culture of inclusion that engages our employees and authentically connects our brand with our consumers.

Job Title:  Third Party Cybersecurity Risk Management

TEAM:  Technology
Location:  Zaragoza
State: 
Country/Region:  ES
Contract Type:  Full time
Number:  548906
Date:  Oct 3, 2026