CISO
�� Head of Information Security / CISO — Financial Institution (Madrid)
We are looking for a senior professional to lead the information security strategy and governance at a regulated financial institution, playing a key role in DORA compliance and digital operational resilience.
What you'll do:
Define and maintain the information security strategy, policies and governance framework in line with DORA and applicable regulations.
Identify, assess and manage information security and technology risks, including critical providers and outsourced services.
Oversee the implementation of security controls across IT, architecture, data and the secure development lifecycle (DevSecOps, IAM, cloud, API security).
Lead security incident detection, response and recovery, and design the Business Continuity Plan.
Coordinate security audits, penetration testing and annual audits of DORA-critical technology providers.
Establish security requirements for third parties and technology providers.
Promote a security-first culture and run the security awareness training program.
Participate in architecture and product reviews from a security perspective.
What we're looking for:
University degree in Computer Science, Telecommunications, Engineering, Cybersecurity, Risk Management or a related field.
Solid experience in information security and technology risk management, ideally within financial institutions, fintechs, payment institutions or e-money institutions.
Knowledge of applicable regulations: DORA, PSD2/PSD3, NIS2, PCI DSS, GDPR.
Familiarity with frameworks such as ISO 27001/27002 and NIST CSF.
Experience in cybersecurity incident and crisis management.
Ability to communicate technical risks to Senior Management and governing bodies in business terms.
Fluent English.
Valued technical knowledge:
Secure SDLC/DevSecOps, application and API security, AWS/cloud security, IAM, cryptography fundamentals, network security, SAST/DAST/SCA, container and IaC scanning, vulnerability management, Kubernetes, SIEM, incident response and security auditing.
Conditions:
�� Madrid (near Bernabéu) — remote at the start, then hybrid with flexible hours.
��️ Standard vacation policy.
Interview process: technical phone screen → Teams interview → final technical interview with the co-founders.
�� If this sounds like you and you'd like more details, reach out!