Chief Information Security Officer (CISO)
Seven Education
Municipality of Madrid, Spain
2 days ago
Role details
Contract type
Permanent contract Employment type
Full-time (> 32 hours) Working hours
Regular working hours Languages
English, Spanish, GermanJob location
Remote
Municipality of Madrid, Spain
Tech stack
Software as a Service
Cloud Computing
Cloud Computing Security
Computer Security
RSA Archer Platform
Job description
- Define and lead a group-wide strategy for information security, data privacy, and adjacent AI governance across multiple entities, countries, and products
- Further develop and scale an existing ISO 27001 setup into a consistent, group-wide operating model, standardizing policies, controls, evidence, and reporting on a shared platform
- Build a practical operating model that balances group-wide standards with local realities across a decentralized software environment
- Establish and strengthen GDPR/privacy capabilities, including policies, records of processing activities, standard processes, and credible external documentation
- Embed security and privacy into Product, Engineering, and Cloud Operations, ensuring standards are reflected in development, platform, and operational practices
- Act as a senior counterpart for customer and commercial processes, including security and privacy questionnaires, RFQs, customer DPO requests, and compliance-related communication
- Build governance, awareness, and training structures across the group, while providing clear visibility, priorities, and risk guidance to executive leadership
- Provide direction and structure to a small existing setup covering both information security and data privacy, and shape the future evolution of the function, including effective collaboration with external partners such as the external DPO
Requirements
- Proven experience leading information security and data privacy in an international, multi-entity software, SaaS, or cloud environment
- A strong track record of standardizing security and privacy across decentralized organizations and translating executive expectations into pragmatic operating models
- Hands-on experience operating ISO 27001-certified environments, including audit readiness, control frameworks, evidence management, and ideally GRC platforms such as Drata, Vanta, or similar tools
- Strong practical understanding of SaaS and cloud security, with experience embedding security into Product, Engineering, and Cloud Operations rather than running it as a separate function
- Solid GDPR/privacy expertise in software or platform businesses, including customer-facing communication, compliance documentation, questionnaires, and DPO-related processes
- The ability to work credibly and pragmatically with customers, prospects, and internal stakeholders in privacy-sensitive or regulated environments, ideally including public-sector contexts
- A builder mindset, with experience scaling existing setups, developing lean teams, and influencing senior stakeholders through clarity, prioritization, and execution
- Excellent English skills; German and Spanish are a plus
About the company
Seven Education (formerly Sdui Group) develops a smart, AI-powered platform that helps schools and educational institutions work more efficiently. Our products reduce administrative workload, improve communication and enable teachers, institutions, and decision-makers to focus on what matters most: learning, growth and people.
As a European EdTech group with 350+ employees, we build intuitive and scalable solutions used widely across the education landscape. Every day, they help create clarity, streamline workflows and strengthen collaboration. We build with courage, ownership and meaningful collaboration - and we stay inspired by the real impact our products create for the people at the heart of education. Our ambition is clear: to become Europe's leading EdTech brand., * Purpose & Social Impact: Working in education means making a real difference. At Seven Education, you contribute to improving the daily work of schools and shaping the future of education for a better tomorrow.
* Flexibility & Hybrid Work: We work in a hybrid setup that combines flexibility with collaboration. This includes flexible working hours, the option to work remotely and a regular onsite presence to support teamwork and connection. Working hours are shorter on Fridays.
* We Take Care of Our People: Your well-being matters to us. In case of sick leave, we cover 100% of your salary from day one.
* Learning & Development: We support your personal and professional growth through development opportunities, learning initiatives and the chance to grow within an international software group.
* Team & Collaboration: You will be part of a collaborative and supportive team environment. We believe great teams are built through trust, connection and shared experiences, and we actively create space for this in everyday work.
* Ownership & Growth: We combine a start-up mindset with the stability and ambition of a growing European group. You will have the opportunity to take responsibility, contribute your ideas and actively shape our future together.
* Time Off & Everyday Perks: You receive 23 days of paid vacation per year. Coffee, tea and cold drinks are available in our offices, and we value spending time together beyond day-to-day work.