Risk and Communications Senior Analyst

2 semanas atrás


Coimbra, Portugal Group Information Security Tempo inteiro

**Job Title: Group Information Security Risk and Communications Senior Analyst**

**Location: Hybrid working**

**Salary: Competitive base salary + benefits**

**Working Hours: 40 hours per week Monday - Friday**

**Job Status: Permanent**

**_Who we are _**

Constellation Automotive Group is Europe's largest vertically integrated digital car marketplace, combining leading digital brands across C2B, B2B, and B2C segments, with an annual Gross Merchandise Value exceeding £20 billion.

The Constellation Technology Team provides technology products and services in various domains, including technology operations, cybersecurity, and engineering, across the UK and Europe.

We are excited to expand our team at our brand-new Tech Hub in Coimbra, where you will have a unique opportunity to influence the development and culture of this innovative hub.

**About The Role**

As a Group Information Security Risk & Communications Senior Analyst, you’ll play a key role in helping to build and embed a Distributed Information Security Management Risk Management framework across Constellation Automotive Group. You’ll work closely with different business areas to support their compliance with customer, regulatory, and internal policy requirements.

Reporting to the Group Information Security Risk & Communications Manager as part of the wider Group Information Security Policy, Risk and Compliance team, this role is central to promoting a culture of risk awareness and accountability. We’re looking for someone with hands-on experience in running and improving Information Security Risk Management processes—ideally in digital and cloud-first environments. You’ll need a good mix of technical understanding and business insight, along with the confidence to build strong, trusted relationships across teams and with external partners.

**Key responsibilities include**:

- Helping to continuously improve our digital and cloud-first Information Security Management System (ISMS), designed to meet certification standards such as ISO/IEC 27001, NIST, and other relevant global frameworks—ensuring it is well-communicated, understood, and adopted across the Group.
- Contributing to the evolution of Group information security policies, standards and guidelines that enable business and customer success by building trust through security.
- Working closely with business and technology leaders to drive adoption of information risk policies, encouraging a culture of shared accountability for risk.
- Contributing to the design and improvement of automated risk management processes that enable fast, informed, and safe decision-making.
- Supporting the enhancement of our risk measurement framework, aligning with international standards such as ISO/IEC 27000 and NIST SP800, and helping to embed this framework as a common standard for assessing and automating information security risk across both business and technology teams.
- Working with risk owners to ensure timely assessment, approval and remediation of risks, and helping them demonstrate clear evidence of mitigation to customers, stakeholders, and regulators.
- Contributing to the design and improvement of automated Supplier Security Assurance processes that enable sensible decisions to be made about which suppliers we trust with our data and systems.
- Support the development and delivery of information and cyber security training and awareness.
- Support the delivery of routine Phishing Simulations and follow-up education.
- Act as a communication ambassador for Group Information Security, ensuring that all messages and policies issued from the Group Information Security team are framed through a business risk lens.
- Day to day contributions to the performance of the Policy, Risk and Compliance team’s Operational Objectives, KPIs and continuous performance of process excellence.

**About You**
- Degree level education or equivalent experience, ideally in cyber security, technology, computing or a related field.
- Practitioner knowledge of relevant legislation and regulation such as Data Protection Act (DPA), GDPR and Payment Card Industry Data Security Standard (PCI DSS).
- Practitioner knowledge of industry best practice and frameworks such as ISO27001, NIST SP800 and the principles of enterprise risk management and governance techniques.
- Have obtained or be studying for a professional security management qualification, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA) or other relevant credentials.
- Qualification/certifications from Cloud providers such as AWS, MS Azur etc.

**_Our policy is to employ the best qualified people and provide equal opportunity for the advancement of employees including promotion and training and not to discriminate against any person because of gender, race, ethnicity, age, sexual orientation, religion, belief or disability._



  • Coimbra, Portugal Constellation Automotive Group Tech Hub Tempo inteiro

    A leading automotive technology company in Coimbra is seeking a Group Information Security Risk and Communications Senior Analyst to influence risk management and compliance across the organization. This role requires a degree in a relevant field and a strong knowledge of security regulations and frameworks such as ISO/IEC 27001. The ideal candidate will...


  • Coimbra, Portugal Phiture Tempo inteiro

    **Senior Business Analyst** **About the job**: - ** Underwriting & Investment Support**: - Develop and enhance pricing models for secured, unsecured, and REO assets - Support investment decisions by providing investment recommendations and risk assessment. - Monitor and analyse the performance of portfolios under management - Prepare and review...

  • Portfolio Risk Manager

    1 semana atrás


    Coimbra, Portugal STAG Fund Management Tempo inteiro

    A leading fund management company in Portugal is seeking a Risk Manager to join their team. This entry-level position focuses on enhancing risk management practices across their portfolio of funds. Responsibilities include identifying and mitigating investment risks, conducting risk assessments, and preparing reports for senior management. The ideal...

  • Analyst

    Há 4 dias


    Coimbra, Portugal Cision Tempo inteiro

    Cision employs the brightest, most passionate people in the tech industry. We’d love for you to join our growing team! We invest in our people through training and professional development while supporting you along the way—all so you can meet your career goals. To us, the most important measure of our success is yours. The Analyst is responsible for...


  • Coimbra, Portugal Group Information Security Tempo inteiro

    **Job Title: Group InfoSec Digital Security Assurance Analyst** **Location: Hybrid working** **Salary: Competitive base salary + benefits** **Working Hours: 40 hours per week Monday - Friday** **Job Status: Permanent** **About The Role**: As a senior assurance analyst, you will lead the creation of processes that will align Assurance BAU with internal...


  • Coimbra, Portugal CRITICAL Software Tempo inteiro

    About Critical Ventures: Critical Ventures is a leading investor focused on deep-tech early-stage ventures with proprietary technologies for software in the areas of cybersecurity, mobility systems and software, IoT, Digitalization and automation, Artificial Intelligence, Machine learning and Decentralized tech, Human2Machine interfaces and Medical Software....


  • Coimbra, Portugal Damia Group Tempo inteiro

    A leading consulting firm is seeking a Senior Business Analyst with over 6 years of professional experience. This role emphasizes strong stakeholder communication and collaboration with tech teams. Candidates must have experience with Digital Asset Management and fluency in English (B2). The position offers a hybrid work model, requiring presence in Coimbra,...

  • Senior Test Analyst

    1 semana atrás


    Coimbra, Portugal Exalto Consulting Tempo inteiro

    Senior Manual Software Tester - 100% Remote - B2B / Autónomo - 3 month initial contract - £200 per day We are seeking a highly skilled and experienced Senior Software Tester, with strong manual testing skills, to join our client's dynamic and innovative software development team. You will play a critical role in ensuring the quality and reliability of...


  • Coimbra, Portugal Canonical Tempo inteiro

    In security risk management we're looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security risk management team is the primary owner of the strategy and practices of how we identify, track and reduce our security risk across everything we do. To support...

  • Senior Business Analyst: DAM

    2 semanas atrás


    Coimbra, Portugal We Are META Tempo inteiro

    Seeking a Senior Business Analyst: Rhino, are you there? At WE ARE META, we focus on finding the perfect match between our Rhinos and our clients. - Expand your network: As a consultant at We Are META, you’ll have access to a network of national and international partners across diverse sectors of the tech industry. - Enjoy our perks: When you join the...