Banking & InvestmentFull time
14 Sept
CISO
A leading company within the financial services / fintech sector is looking to incorporate a Chief Information Security Officer (CISO) into its team in Madrid.
The position offers the opportunity to join the organisation directly, on a permanent employment contract, and to take ownership of a critical function within an international and highly regulated environment.
The CISO will act as the centre of competence for Information Security and Technology Risk, with a key role in defining the security strategy, strengthening the organisation's security posture and ensuring compliance with the applicable regulatory framework, particularly DORA.
Role
The CISO will operate as the Second Line of Defense for DORA risk management, providing independent oversight of information security and technology risks across the organisation.
Key Responsibilities
Define and maintain the Information Security strategy, policies and governance framework, ensuring alignment with DORA and the applicable regulatory framework.
Identify, assess and manage information security and technology risks, establishing appropriate mitigation measures and controls.
Oversee the protection of payment systems and transactional platforms.
Lead programmes covering vulnerability and threat management, endpoint security, network security, application security and cloud security.
Lead security incident detection, response and recovery capabilities.
Define and maintain the Business Continuity Plan and participate in security incident, continuity and recovery exercises.
Define and oversee security requirements throughout the Secure SDLC, including DevSecOps, IAM, cloud security, secrets management, logging, monitoring, code analysis, vulnerability management and API security.
Establish security requirements for third parties and technology providers, in line with DORA and EBA requirements.
Conduct and coordinate security assessments and audits of critical technology providers.
Map and classify critical systems, applications and data, assessing their criticality and risk exposure.
Coordinate information security audits, penetration tests, technical reviews and resilience exercises, ensuring appropriate follow-up of findings.
Establish security gates and criteria for production changes and verify their implementation.
Participate in architecture and product reviews from an information security perspective.
Challenge and verify the implementation of security requirements by development teams, DevOps, architects, technical leads and third-party providers.
Promote a strong risk-based information security culture across the organisation.
Requirements
University degree in Computer Science, Telecommunications, Engineering, Cybersecurity, Risk Management or a related discipline.
Significant experience in Information Security and Technology Risk Management, ideally within financial institutions, fintech, payment institutions or electronic money institutions.
Strong knowledge of financial and payment regulations, particularly DORA, PSD2/PSD3, NIS2, PCI DSS and GDPR.
Knowledge of security frameworks including ISO 27001/27002 and NIST CSF, as well as risk management methodologies.
Proven experience in cybersecurity incident and crisis management.
Experience managing technology providers, outsourcing arrangements and cloud services.
Ability to communicate complex technical and security risks clearly to Senior Management, governing bodies and other stakeholders, translating them into business and risk implications.
Professional proficiency in English.
Technical Expertise
The successful candidate should have strong practical knowledge of:
Secure SDLC and DevSecOps
Application Security and API Security
AWS / Cloud Security
IAM, secrets management and cryptography fundamentals
Network and infrastructure security
SAST, DAST, SCA, secret scanning, container scanning and IaC scanning
Vulnerability management
Kubernetes and container security
Logging, monitoring and SIEM
Incident Response
Penetration Testing and Information Security Auditing
The role requires sufficient technical depth to independently verify the implementation and effectiveness of key security controls, review technical solutions and challenge the work performed by development, DevOps, architecture and third-party teams.
The ideal candidate will be able to distinguish between formal regulatory compliance and genuinely effective security controls, combining strategic vision and risk management with strong technical judgement.
Location: Madrid ( hybrid position)Contract: Permanent, direct employment with the end client