Security Compliance Product Owner

Liebherr
Madrid, Spain
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Regular working hours
Languages
English, German

Tech stack

Artificial Intelligence Cyber Security Information Security Management System Software Security Information Technology

Job description

  • Compliance Product Ownership & ISF Alignment: Define and own the Compliance Product scope, roadmap, operating model, and KPIs aligned with CIS and GRC strategy. Ensure continuous alignment of ISF components (policies, standards, procedures, control baselines) with regulatory, contractual, and certification requirements.
  • Regulatory Compliance: Maintain a centralized inventory of applicable information and cybersecurity regulations (e.g. NIS2, GDPR, CRA, EU AI Act, defense-related obligations). Perform regulatory applicability assessments and structured compliance gap analyses. Define, track, and report remediation plans for identified compliance gaps. Monitor regulatory changes and ensure timely updates to the ISF.
  • Security standards compliance and certification (ISO/IEC 27001): Govern ISMS and CSMS documentation, readiness, and support in companies’ certification activities, including maintaining required evidence and ensuring delivery during internal and external audits. Track audit findings and corrective actions to closure for areas of responsibility.
  • Customer & Stakeholder Assurance: Support compliance and security assessments from customers, contract security clause reviews, and customer audits. Act as the primary compliance point of contact for CIS product and services teams towards IT, Product Security, Legal, and business stakeholders. Report compliance status, certification progress, risks, and KPIs to leadership.

Requirements

  • Bachelor’s or Master’s degree in Cybersecurity, Computer Science, or related field.
  • 5+ years of working experience in information security, IT Security, compliance or related roles (Information Security Compliance Manager, Information Security Officer, etc).
  • Certifications such as CISSP, CISM, CRISC are a plus.
  • Hands-on or governance experience with ISO/IEC 27001 certification programs.
  • Strong understanding of global cybersecurity regulations (e.g. NIS2, GDPR, CRA).
  • Experience coordinating audits, regulatory assessments, or certification activities.
  • Familiarity with NIST CSF and ISO/IEC 27001 and IEC/62443 governance concepts.
  • Demonstrated ability to manage stakeholders across IT, OT, engineering, and business management in complex environments.
  • Excellent written and verbal communication skills in English and German is a plus.
  • Willingness and ability to travel to Liebherr sites worldwide up to 10% of the time.

Benefits & conditions

  • Competitive compensation and benefits package that recognizes your expertise.
  • Flexible and hybrid working model.
  • Creative freedom and responsibility to shape processes and solutions in our global transformation.
  • Continuous learning and development with tailored training and certification opportunities.
  • Life and accident insurance.
  • Option to include a premium private health insurance package as part of the flexible remuneration.
  • A safe, stable and international workplace within a trusted family business that invests in people.

full_time

Organization Liebherr-Werk Nenzing GmbH

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jobleads.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:03 min

Navigating European software legislation with open regulatory compliance processes

Francisco Carneiro Francisco Carneiro · WWC 2025

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · WWC 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · WWC Europe 2026

Videos

See all

Related articles

See all