Apply Edge Start your job search

Chief Information Security Officer

Antal International · Madrid, Community of Madrid, Spain

Apply & track with Apply Edge

About the CompanyOur client is a regulated fintech company operating in Spain, currently strengthening its Information Security and Technology Risk function under the DORA framework.About the RoleThe CISO acts as the center of competence for Information Security and Technology Risk.The role is to make sure the organization’s technology, systems, data, software, suppliers, and operations are secure, resilient, and compliant with DORA, covering everything from risk and governance to cybersecurity operations, incident response, third parties, and secure software development.ResponsibilitiesSecurity strategy & governance: Define and maintain the information security strategy, policies, standards, and governance framework in line with DORA, EBA, and other regulations.Risk management: Identify and assess cybersecurity and technology risks, including risks from IT systems, critical suppliers, outsourced services, and new products, and ensure appropriate controls are in place.Security controls: Oversee security controls across IT, applications, infrastructure, data, architecture, cloud, networks, endpoints, and payment/transaction systems.Cybersecurity operations: Ensure effective vulnerability management, threat management, monitoring, and protection of networks, applications, endpoints, and cloud environments.Incident response & resilience: Lead security incident detection, response, recovery, and business continuity activities, including testing and exercises.Secure software development: Ensure security is embedded throughout the software development lifecycle, covering DevSecOps, IAM, API security, secrets, logging, code analysis, cloud security, and vulnerability management.Third-party risk: Define security requirements for technology providers and outsourced services and conduct annual audits of DORA-critical providers.Critical systems & data: Identify and classify critical systems, applications, and data, and assess their operational and security risks.Audits & testing: Coordinate security audits, penetration tests, technical reviews, and resilience exercises, and ensure findings are properly addressed.Security awareness: Maintain employee and contractor security training and promote a strong, risk-based security culture.Change & architecture oversight: Establish security requirements for production changes and review new architectures, products, and implementations from a security perspective.Security assurance: Verify that development, DevOps, architecture, technical teams, and third parties actually implement the required security controls.QualificationsUniversity degree in Computer Science, Telecommunications, Engineering, Cybersecurity, Risk Management or an equivalent discipline.Significant experience in information security and technology risk management, preferably within financial institutions, fintech companies, payment institutions or electronic money institutions.Knowledge of regulations applicable to financial and payment institutions, including DORA, PSD2/PSD3, NIS2, PCI DSS, GDPR and information security requirements applicable to payment services.Knowledge of frameworks such as ISO 27001/27002, NIST CSF and risk management methodologies.Experience in cybersecurity incidents and crisis management.Experience managing technology providers and cloud services.Ability to communicate technical risks to Senior Management, governing bodies and supervisory authorities in business and risk terms.Proficiency in English.Required SkillsLeadership and strong cross-functional influencing skills.Strategic vision and a strong risk-oriented mindset.Ability to make effective decisions in crisis situations.Strong prioritization and executive communication skills.Independence and sound professional judgement.Preferred SkillsStrong knowledge and practical understanding of the following areas is required:Secure SDLC and DevSecOps.Application security and API security.AWS/cloud security; IAM, secrets management and cryptography fundamentals; network security and infrastructure security.SAST, DAST, SCA (Software Composition Analysis), secret scanning, container scanning and IaC scanning (Infrastructure as Code).Vulnerability management; Kubernetes and container security.Incident response.Penetration testing and information security auditing.ConditionsHybrid working model