Senior Information Security Manager

Ebury
Madrid, Spain
6 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Artificial Intelligence Cyber Security Cyber Laws Information Security Management System RSA Archer Platform

Job description

Ebury helps ambitious businesses unlock global growth, and we take the same approach with our people.We encourage innovation and movement, collaboration and problem?solving, and foster an environment where everyone can feel they belong, are valued, supported and empowered to succeed.If you’re a collaborator who wants to help transform how businesses operate globally, get in touch - we’d love to discuss how Ebury can accelerate your career so you can shape the future.Senior Information Security Manager Ebury Madrid Office - Hybrid: 4 days in the office, 1 day working from home per week Ebury is seeking a high?caliber Information Security & GRC Manager to spearhead our global governance, risk, and compliance initiatives.This role is for a seasoned professional who thrives on owning programs rather than just executing tasks.You will act as the primary architect of our security frameworks, ensuring our ISMS is audit?ready and serves as a strategic enabler for Ebury’s global expansion.You will be the bridge between technical security requirements and business risk, providing expert guidance on complex regulatory landscapes.This is an opportunity to be a strategic part of an experienced infosec team at a high?growth fintech scale?up.What you’ll do Governance & Compliance (BAU) GRC Strategy & Architecture : Design, implement, and mature our global GRC framework, collaborating with other teams to align it with ISO **, NIST, GDPR, and DORA.Risk Management Lifecycle : Own the risk assessment process - you will lead the quantification and communication of risk to business stakeholders to drive informed decision?making.Audit Ownership : Lead and manage external audits as the primary liaison.This includes overseeing the remediation of findings and ensuring we remain continuously compliant across multiple jurisdictions.TPRM Leadership : Mature our Third?Party Risk Management program.You will define the standards for vendor security and ensure high?impact partners meet Ebury’s rigorous risk appetite.Regulatory Horizon Scanning : Proactively monitor the evolving fintech regulatory landscape (e.g., EU AI Act, NIS2, regional cyber laws) and design the roadmaps to ensure Ebury remains ahead of the curve.Strategic Projects & Process Maturation GRC Automation : Lead the selection and full?scale implementation of automated GRC platforms to establish automation and robustness in GRC operations.Strategic Advisory : Act as a high?level consultant for new product launches and international expansions, ensuring “Security by Design” is baked into strategic business moves.Cultural Leadership : Design and champion advanced security awareness programs that focus on shifting organizational behavior through metrics?driven insights.What you’ll need 5+ years of experience in Information Security, GRC, or Risk Management roles Strong knowledge of information security standards and regulations (ISO **, SOC 2, GDPR, FCA/DORA, NIST, etc.) Analytical skills: Ability to assess a “Security Exception”, experience with regulatory audits and working with financial regulators.Hands?on experience implementing risk management processes, control frameworks, and security metrics.Familiarity with GRC or risk platforms (e.g. One Trust).Team player with exceptional communication and stakeholder management skills.Industry certifications such as CISSP, CRISC, CISA, or ISO **.Lead Implementer/Auditor are preferred.Why Ebury?Competitive Starting Salary with an annual discretionary bonus that truly rewards your performance from day one.Dedicated Mentorship : Learn directly from experienced managers who are invested in your success.Cutting?Edge Technology : Leverage state?of?the?art tailor?made tools and systems that enable you to perform at your best.Clear, Accelerated Career Progression : Defined pathways to leadership and specialist roles within Ebury.Dynamic & Supportive Culture : Work in a collaborative environment where teamwork and personal growth are prioritized.Generous Benefits Package : Access competitive benefits tailored to your location, which typically include health care and social benefits.Central Madrid Office : A fantastic location with excellent transport links.#J-**-Ljbffr

Requirements

Cultural Leadership : Design and champion advanced security awareness programs that focus on shifting organizational behavior through metrics?driven insights. What you’ll need 5+ years of experience in Information Security, GRC, or Risk Management roles Strong knowledge of information security standards and regulations (ISO **, SOC 2, GDPR, FCA/DORA, NIST, etc.) Analytical skills: Ability to assess a “Security Exception”, experience with regulatory audits and working with financial regulators. Hands?on experience implementing risk management processes, control frameworks, and security metrics. Familiarity with GRC or risk platforms (e.g. One Trust). Team player with exceptional communication and stakeholder management skills. Industry certifications such as CISSP, CRISC, CISA, or ISO **. Lead Implementer/Auditor are preferred.

Benefits & conditions

Competitive Starting Salary with an annual discretionary bonus that truly rewards your performance from day one. Dedicated Mentorship : Learn directly from experienced managers who are invested in your success. Cutting?Edge Technology : Leverage state?of?the?art tailor?made tools and systems that enable you to perform at your best. Clear, Accelerated Career Progression : Defined pathways to leadership and specialist roles within Ebury. Dynamic & Supportive Culture : Work in a collaborative environment where teamwork and personal growth are prioritized. Generous Benefits Package : Access competitive benefits tailored to your location, which typically include health care and social benefits. Central Madrid Office : A fantastic location with excellent transport links. #J-*****-Ljbffr

About the company

Madrid, EspaĂąa

Ebury helps ambitious businesses unlock global growth, and we take the same approach with our people. We encourage innovation and movement, collaboration and problem?solving, and foster an environment where everyone can feel they belong, are valued, supported and empowered to succeed. If you’re a collaborator who wants to help transform how businesses operate globally, get in touch - we’d love to discuss how Ebury can accelerate your career so you can shape the future.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder ¡ LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ WWC 2022

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 ¡ WWC Europe 2026

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger ¡ LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar ¡ WWC 2023

Videos

See all

Related articles

See all