Chief Information Security Officer (CISO)

Seven Education
Municipality of Madrid, Spain
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English, Spanish, German

Job location

Remote
Municipality of Madrid, Spain

Tech stack

Software as a Service
Cloud Computing
Cloud Computing Security
Computer Security
RSA Archer Platform

Job description

  • Define and lead a group-wide strategy for information security, data privacy, and adjacent AI governance across multiple entities, countries, and products
  • Further develop and scale an existing ISO 27001 setup into a consistent, group-wide operating model, standardizing policies, controls, evidence, and reporting on a shared platform
  • Build a practical operating model that balances group-wide standards with local realities across a decentralized software environment
  • Establish and strengthen GDPR/privacy capabilities, including policies, records of processing activities, standard processes, and credible external documentation
  • Embed security and privacy into Product, Engineering, and Cloud Operations, ensuring standards are reflected in development, platform, and operational practices
  • Act as a senior counterpart for customer and commercial processes, including security and privacy questionnaires, RFQs, customer DPO requests, and compliance-related communication
  • Build governance, awareness, and training structures across the group, while providing clear visibility, priorities, and risk guidance to executive leadership
  • Provide direction and structure to a small existing setup covering both information security and data privacy, and shape the future evolution of the function, including effective collaboration with external partners such as the external DPO

Requirements

  • Proven experience leading information security and data privacy in an international, multi-entity software, SaaS, or cloud environment
  • A strong track record of standardizing security and privacy across decentralized organizations and translating executive expectations into pragmatic operating models
  • Hands-on experience operating ISO 27001-certified environments, including audit readiness, control frameworks, evidence management, and ideally GRC platforms such as Drata, Vanta, or similar tools
  • Strong practical understanding of SaaS and cloud security, with experience embedding security into Product, Engineering, and Cloud Operations rather than running it as a separate function
  • Solid GDPR/privacy expertise in software or platform businesses, including customer-facing communication, compliance documentation, questionnaires, and DPO-related processes
  • The ability to work credibly and pragmatically with customers, prospects, and internal stakeholders in privacy-sensitive or regulated environments, ideally including public-sector contexts
  • A builder mindset, with experience scaling existing setups, developing lean teams, and influencing senior stakeholders through clarity, prioritization, and execution
  • Excellent English skills; German and Spanish are a plus

About the company

Seven Education (formerly Sdui Group) develops a smart, AI-powered platform that helps schools and educational institutions work more efficiently. Our products reduce administrative workload, improve communication and enable teachers, institutions, and decision-makers to focus on what matters most: learning, growth and people. As a European EdTech group with 350+ employees, we build intuitive and scalable solutions used widely across the education landscape. Every day, they help create clarity, streamline workflows and strengthen collaboration. We build with courage, ownership and meaningful collaboration - and we stay inspired by the real impact our products create for the people at the heart of education. Our ambition is clear: to become Europe's leading EdTech brand., * Purpose & Social Impact: Working in education means making a real difference. At Seven Education, you contribute to improving the daily work of schools and shaping the future of education for a better tomorrow. * Flexibility & Hybrid Work: We work in a hybrid setup that combines flexibility with collaboration. This includes flexible working hours, the option to work remotely and a regular onsite presence to support teamwork and connection. Working hours are shorter on Fridays. * We Take Care of Our People: Your well-being matters to us. In case of sick leave, we cover 100% of your salary from day one. * Learning & Development: We support your personal and professional growth through development opportunities, learning initiatives and the chance to grow within an international software group. * Team & Collaboration: You will be part of a collaborative and supportive team environment. We believe great teams are built through trust, connection and shared experiences, and we actively create space for this in everyday work. * Ownership & Growth: We combine a start-up mindset with the stability and ambition of a growing European group. You will have the opportunity to take responsibility, contribute your ideas and actively shape our future together. * Time Off & Everyday Perks: You receive 23 days of paid vacation per year. Coffee, tea and cold drinks are available in our offices, and we value spending time together beyond day-to-day work.

Apply for this position