Chief Information Security Officer - CISO (based in Crete)
Heraklion International Airport, Crete · Iráklion, Crete, Greece
Apply & track with Apply EdgeInternational Airport of Heraklion, Crete S.A. is currently looking for a:Chief Information Security Officer - CISO (based in Crete)ResponsibilitiesDevelops, implements, and maintains the Airport's information security governance framework, policies, and proceduresEstablishes and continuously improves an ISO/IEC 27001-aligned Information Security Management System (ISMS)Leads security governance initiatives and promotes a strong security culture across the organizationCoordinates management reviews, governance reporting, audits, and certification activitiesMaintains the information security risk management methodology and risk registerFacilitates risk assessments across business functions and critical systemsMonitors mitigation plans and escalates significant residual risksSupports operational resilience and business continuity initiativesLeads cybersecurity governance activities supporting aerodrome certification and continuous compliance with EASA requirements, particularly Part-ISCoordinates inspections, compliance reviews, evidence submissions, and closure of findingsEnsures effective alignment between cybersecurity, aviation safety, and aviation security requirementsServes as the primary point of contact for information security matters with the Hellenic Civil Aviation Authority (HCAA), National Cybersecurity Authority, EASA, and other relevant authoritiesMonitors compliance with NIS2, GDPR security obligations, aviation regulations, and contractual commitmentsMaintains the information-security obligations register and monitors relevant regulatory developmentsCoordinates regulatory submissions, audits, inspections, and follow-up actionsSupports supplier due diligence and third-party security risk managementRequirementsBachelor's degree in IT, Business Administration, Law, or a related discipline, or equivalent relevant professional experienceMaster's degree in IT, Cybersecurity, Risk Management or related discipline will be considered a plusMinimum 5 years of experience in Information Security Governance, Risk & Compliance (GRC), cybersecurity risk management, compliance, or information systems auditingProfessional certifications (e.g. CISSP, CISM, CRISC) will be considered an assetDemonstrated experience establishing, maintaining, or improving an ISO/IEC 27001-based ISMSExperience managing audits, regulatory assessments, and compliance programsStrong understanding of NIS2, GDPR security requirements and enterprise security architecture across IT, Cloud, OT/ICS environmentsExperience within aviation, transport, critical infrastructure, or another highly regulated sectorFamiliarity with EASA Part-IS requirementsCompetenciesStrategic thinking and business awarenessExcellent stakeholder management and communication skillsStrong analytical and problem-solving capabilityAbility to translate complex technical risks into business decisionsHigh integrity, independence, and discretion when handling sensitive or confidential information