> Markdown version of [/jobs/ext/1615301-security-compliance-product-owner](https://www.wearedevelopers.com/jobs/ext/1615301-security-compliance-product-owner). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Compliance Product Owner - **Company:** Liebherr - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Information Security Management System, Software Security, Information Technology - **Published:** July 11, 2026 - **Apply:** https://www.jobleads.com/es/job/e4c01a8794b910b31c3d8fd54ee041979 ## About the Role * Bachelor's or Master's degree in Cybersecurity, Computer Science, or related field. * 5+ years of working experience in information security, IT Security, compliance or related roles (Information Security Compliance Manager, Information Security Officer, etc). * Certifications such as CISSP, CISM, CRISC are a plus. * Hands-on or governance experience with ISO/IEC 27001 certification programs. * Strong understanding of global cybersecurity regulations (e.g. NIS2, GDPR, CRA). * Experience coordinating audits, regulatory assessments, or certification activities. * Familiarity with NIST CSF and ISO/IEC 27001 and IEC/62443 governance concepts. * Demonstrated ability to manage stakeholders across IT, OT, engineering, and business management in complex environments. * Excellent written and verbal communication skills in English and German is a plus. * Willingness and ability to travel to Liebherr sites worldwide up to 10% of the time. ## Description * Compliance Product Ownership & ISF Alignment: Define and own the Compliance Product scope, roadmap, operating model, and KPIs aligned with CIS and GRC strategy. Ensure continuous alignment of ISF components (policies, standards, procedures, control baselines) with regulatory, contractual, and certification requirements. * Regulatory Compliance: Maintain a centralized inventory of applicable information and cybersecurity regulations (e.g. NIS2, GDPR, CRA, EU AI Act, defense-related obligations). Perform regulatory applicability assessments and structured compliance gap analyses. Define, track, and report remediation plans for identified compliance gaps. Monitor regulatory changes and ensure timely updates to the ISF. * Security standards compliance and certification (ISO/IEC 27001): Govern ISMS and CSMS documentation, readiness, and support in companies' certification activities, including maintaining required evidence and ensuring delivery during internal and external audits. Track audit findings and corrective actions to closure for areas of responsibility. * Customer & Stakeholder Assurance: Support compliance and security assessments from customers, contract security clause reviews, and customer audits. Act as the primary compliance point of contact for CIS product and services teams towards IT, Product Security, Legal, and business stakeholders. Report compliance status, certification progress, risks, and KPIs to leadership. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [Best Companies to Work For in Germany: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/33-best-companies-to-work-for-in-germany-top-25-companies-in-2023)