Senior Information Security Manager

Ebury
Madrid, Spain
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Cyber Security Information Security Management System RSA Archer Platform

Job description

Experteer Overview In this role you will lead global governance, risk, and compliance initiatives to make the ISMS auditable and a strategic enabler for Ebury’s international growth.You bridge security requirements with business risk, guiding regulatory compliance across jurisdictions.You own the GRC program, steer audits, and drive security by design in new products.This is a senior, impact-focused position within a fast-growing fintech team.Compensaciones / Beneficios* GRC Strategy u** Architecture: design and mature the global GRC framework aligned with ISO **, NIST, GDPR, and DORA Risk Management Lifecycle: lead risk assessments and communicate risk to stakeholders for informed decisions* Audit Ownership: manage external audits and remediation across multiple jurisdictions* TPRM Leadership: shape vendor security standards and ensure high-impact partners meet risk appetite* Regulatory Horizon Scanning: monitor fintech regs and roadmap compliance* GRC Automation: select and implement automated GRC platforms* Strategic Advisory: provide security-by-design guidance for new product launches and international growth* Cultural Leadership: run security awareness programs with metrics-driven insightsResponsabilidades* 5+ years in Information Security, GRC, or Risk Management* Strong knowledge of ISO **, SOC 2, GDPR, FCA/DORA, NIST Analytical with experience in regulatory audits and engaging financial regulators* Hands-on risk management, controls, and security metrics* Familiarity with GRC platforms (e.g., OneTrust)* Team player with excellent communication and stakeholder management* Industry certifications such as CISSP, CRISC, CISA, or ISO *** Lead Implementer/Auditor preferredRequisitos principales* Competitive starting salary with discretionary bonus* Dedicated mentorship* Cutting-edge technology and tools* Clear career progression paths* Dynamic and supportive culture* Generous location-based benefits

Requirements

  • 5+ years in Information Security, GRC, or Risk Management
  • Strong knowledge of ISO *****, SOC 2, GDPR, FCA/DORA, NIST
  • Analytical with experience in regulatory audits and engaging financial regulators
  • Hands-on risk management, controls, and security metrics
  • Familiarity with GRC platforms (e.g., OneTrust)
  • Team player with excellent communication and stakeholder management
  • Industry certifications such as CISSP, CRISC, CISA, or ISO ***** Lead Implementer/Auditor preferred

Benefits & conditions

  • Competitive starting salary with discretionary bonus
  • Dedicated mentorship
  • Cutting-edge technology and tools
  • Clear career progression paths
  • Dynamic and supportive culture
  • Generous location-based benefits

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · WWC 2023

Videos

See all

Related articles

See all