> Markdown version of [/jobs/ext/1948316-senior-information-security-manager](https://www.wearedevelopers.com/jobs/ext/1948316-senior-information-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Manager - **Company:** Ebury - **Location:** Madrid, Spain - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Security Management System, RSA Archer Platform - **Published:** August 6, 2026 - **Apply:** https://www.buscojobs.com.es/senior-information-security-manager-en-madrid-ID-365296064 ## About the Role * 5+ years in Information Security, GRC, or Risk Management * Strong knowledge of ISO *****, SOC 2, GDPR, FCA/DORA, NIST * Analytical with experience in regulatory audits and engaging financial regulators * Hands-on risk management, controls, and security metrics * Familiarity with GRC platforms (e.g., OneTrust) * Team player with excellent communication and stakeholder management * Industry certifications such as CISSP, CRISC, CISA, or ISO ***** Lead Implementer/Auditor preferred ## Description Experteer Overview In this role you will lead global governance, risk, and compliance initiatives to make the ISMS auditable and a strategic enabler for Ebury's international growth.You bridge security requirements with business risk, guiding regulatory compliance across jurisdictions.You own the GRC program, steer audits, and drive security by design in new products.This is a senior, impact-focused position within a fast-growing fintech team.Compensaciones / Beneficios* GRC Strategy u**** Architecture: design and mature the global GRC framework aligned with ISO *****, NIST, GDPR, and DORA* Risk Management Lifecycle: lead risk assessments and communicate risk to stakeholders for informed decisions* Audit Ownership: manage external audits and remediation across multiple jurisdictions* TPRM Leadership: shape vendor security standards and ensure high-impact partners meet risk appetite* Regulatory Horizon Scanning: monitor fintech regs and roadmap compliance* GRC Automation: select and implement automated GRC platforms* Strategic Advisory: provide security-by-design guidance for new product launches and international growth* Cultural Leadership: run security awareness programs with metrics-driven insightsResponsabilidades* 5+ years in Information Security, GRC, or Risk Management* Strong knowledge of ISO *****, SOC 2, GDPR, FCA/DORA, NIST* Analytical with experience in regulatory audits and engaging financial regulators* Hands-on risk management, controls, and security metrics* Familiarity with GRC platforms (e.g., OneTrust)* Team player with excellent communication and stakeholder management* Industry certifications such as CISSP, CRISC, CISA, or ISO ***** Lead Implementer/Auditor preferredRequisitos principales* Competitive starting salary with discretionary bonus* Dedicated mentorship* Cutting-edge technology and tools* Clear career progression paths* Dynamic and supportive culture* Generous location-based benefits ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Communicate efficiently with Software Architecture Diagrams](https://www.wearedevelopers.com/videos/379-communicate-efficiently-with-software-architecture-diagrams) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Spanish Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/353-spanish-business-culture-and-etiquette) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette)