Apply Edge Start your job search

Chief Information Security Officer Europe

Gracia101 Talent Solutions · Barcelona, Catalonia, Spain

Apply & track with Apply Edge

BARCELONA BASED ROLE. The Regional CISO is a senior leadership role responsible for defining and driving the regional Information & Cyber Security agenda, in partnership with the Group CISO, Group Operational CISO and Regional CIO.The role ensures that cybersecurity risks are effectively identified, assessed and managed, while maintaining the confidentiality, integrity and availability of business, customer, partner and employee information. The CISO works closely with executive management to establish appropriate risk levels and ensure security investments and priorities support business objectives.Key ResponsibilitiesDefine and execute the regional cybersecurity strategy, governance and risk management framework.Build strong relationships with Regional Management, Country Managers and Business Leaders, ensuring cybersecurity risks, priorities and investments are understood and supported.Establish clear security accountability, risk ownership and decision-making across the region and subsidiaries.Lead regional cybersecurity initiatives through collaboration, influence and matrix management across multiple countries.Provide pragmatic, risk-based security recommendations aligned with business objectives and operational requirements.Coordinate regional response to major cybersecurity incidents and crisis situations, working closely with Group Security.Ensure compliance with internal security policies and external legal, regulatory and contractual requirements.Lead and coordinate ISO 27001 and other relevant security certification and audit activities.Drive continuous improvement of security policies, processes, technologies and practices in line with industry standards and best practices.Promote security awareness and a strong risk management culture across the region.Ensure security is embedded throughout the IT service lifecycle, including Security Operations, Architecture and Assurance.Support customer and business engagements on cybersecurity matters, including audits and security questionnaires.Harmonize security practices across countries and subsidiaries, including in the context of M&A.Lead and develop a high-performing regional Information Security team, fostering talent, innovation and continuous improvement.Report cybersecurity risks, performance and key initiatives to regional management and governance committees.Education & ExperienceEngineering or equivalent degree.6–10 years of experience in IT management and/or cybersecurity leadership roles.Strong knowledge of information security, cybersecurity risk management and standards such as ISO 27001.Experience with security technologies including IAM, firewalls, IDS/IPS, SIEM, cloud and remote-working environments.Strong understanding of project and change management methodologies.CISSP, CISM, CISA, ISO 27001 Lead Implementer or equivalent certification is highly desirable.Proven experience working in international, multicultural and matrix organizations.Fluent English; French is a plus.