Information Security Specialist

Jobgether
Málaga, Spain
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Artificial Intelligence Cloud Computing Security Cyber Security PCI Data Security Standards Information Security Management System

Job description

This position is posted by Jobgether on behalf of a partner company. We are currently looking for a Information Security Specialist in Spain.In this role, you will join a high-performing security team focused on protecting sensitive data, strengthening compliance frameworks, and continuously improving security operations in a fast-growing, globally distributed environment. You will play a key role in shaping and maintaining a strong security posture, balancing strategic governance with hands-on execution. Working closely with cross-functional teams, you will help bridge regulatory requirements and daily technical operations. This position offers broad exposure across compliance, risk management, and incident response initiatives. You will contribute directly to business trust, operational resilience, and regulatory excellence. The environment is collaborative, innovative, and fully remote, enabling flexibility, ownership, and impact at scale.Accountabilities:Lead and maintain the Information Security Management System, ensuring ongoing alignment with industry standards and internal policiesDrive and manage compliance programs including SOC 2 Type II, ISO **, and NIS2, preparing and supporting audits end-to-endTranslate regulatory and compliance requirements into actionable technical and operational security controlsAssess systems, processes, and infrastructure against security frameworks and best practicesParticipate actively in risk management initiatives, incident response activities, and continuous security improvementProvide expertise and support during customer and partner due diligence processesContribute to AI security governance and collaborate closely with engineering, product, and operational teamsRequirements:Proven professional experience in information security, governance, risk, and complianceStrong knowledge of compliance frameworks such as SOC 2, ISO **, NIS2, PCI-DSS, with hands-on audit experienceAbility to interpret regulatory standards and implement effective technical security controlsSolid experience in security risk assessment, control design, and risk mitigation strategiesExcellent communication, collaboration, and stakeholder management skillsExperience in incident management, cloud security, or AI governance is considered a plusRelevant security certifications such as CISSP, CISA, CISM, or ISO ***** Lead Auditor or Implementer are advantageousComfortable working in remote, asynchronous, and globally distributed environmentsBenefits:Competitive salary package aligned with global market standardsFully remote work environment with flexible working hoursFlexible paid time off policy16 weeks of paid parental leaveMental health and wellbeing support servicesStock options and long-term incentive opportunitiesLearning and development budgetHome office setup budget and IT equipmentBudget for local coworking spaces or in-person team eventsWhy Apply Through Jobgether?We use anAI-powered matching processto ensure your application is reviewed quickly, objectively, and fairly against the role’s core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.We appreciate your interest and wish you the best!Why Apply Through Jobgether?Data Privacy Notice:By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.#LI-CL1We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Requirements

Proven professional experience in information security, governance, risk, and compliance Strong knowledge of compliance frameworks such as SOC 2, ISO **, NIS2, PCI-DSS, with hands-on audit experience Ability to interpret regulatory standards and implement effective technical security controls Solid experience in security risk assessment, control design, and risk mitigation strategies Excellent communication, collaboration, and stakeholder management skills Experience in incident management, cloud security, or AI governance is considered a plus Relevant security certifications such as CISSP, CISA, CISM, or ISO ** Lead Auditor or Implementer are advantageous Comfortable working in remote, asynchronous, and globally distributed environments

Benefits & conditions

Competitive salary package aligned with global market standards Fully remote work environment with flexible working hours Flexible paid time off policy 16 weeks of paid parental leave Mental health and wellbeing support services Stock options and long-term incentive opportunities Learning and development budget Home office setup budget and IT equipment Budget for local coworking spaces or in-person team events Why Apply Through Jobgether? We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role’s core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:46 min

Core terminology and audiences for interpretable artificial intelligence

Karol Przystalski · LIVE

4:19 min

Differences between mobile infrastructure and application layer security

Moataz Nabil Moataz Nabil · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all