> Markdown version of [/jobs/ext/1987712-information-security-manager](https://www.wearedevelopers.com/jobs/ext/1987712-information-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Manager - **Company:** Colibrix One - **Location:** Laza, Spain - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Cloud Computing Security, Cyber Security, Continuous Integration, Disaster Recovery, Identity and Access Management, Payment Service Provider, PCI Data Security Standards, Role-Based Access Control, Phishing, Kubernetes - **Published:** August 8, 2026 - **Apply:** https://www.buscojobs.com.es/information-security-manager-en-laza-ID-365894150 ## About the Role Experience in managing asset and access management systems. Experience in incident management and security governance. Knowledge of business domains, ability to identify security risks and mitigate them. Solid understanding of infrastructure and cloud security (AWS, Kubernetes, CI/CD pipelines). Practical experience in Information Security Awareness: education, simulations. Background in risk management, business continuity, and disaster recovery planning. Experience working with vendors, regulators, and external partners. Proficiency in Security standards: PCI DSS, DORA, SWIFT, ISO, GDPR Nice to have Experience in fintech, banking, or other regulated industries. Participation in certification projects (PCI DSS, ISO, SOC 2). Certifications: CISSP, CISM, CISA, AWS Security Specialty. Experience with FinOps and security cost optimization. Background in building and scaling Security Awareness programs. ## Description Join Colibrix One - Innovating the Future of PaymentsAtColibrix One*, we're building advanced, AI-powered payment technologies that support Payment Service Providers (PSPs), Electronic Money Institutions (EMIs), and neobanks across the EU and the UK. As a fully licensed EMI (FCA reference number ******) and a Principal Member of Mastercard, we offer real-world financial solutions that include:Global card processingDigital wallet infrastructureCross-border merchant accountsAlternative payment methods (APMs)Corporate accounts for legal entitiesWe're a fast-growing team with a passion for innovation, security, and scalability. Our culture values curiosity, collaboration, and impact - and we're looking for talented professionals who are ready to shape the future of fintech.At Colibrix One, your work directly powers the digital economy. If you're eager to solve meaningful challenges and build with purpose, we'd love to hear from you.We're looking for an experiencedInformation Security Managerto lead security policy development, manage risks and incidents, and ensure compliance with standards like PCI DSS, ISO, and GDPR. You'll drive security awareness, oversee access and asset management, and support cloud and infrastructure security across the business.ResponsibilitiesDevelop and enforce security policies: company-wide rules, standards, and proceduresDefine acceptable use rules: corporate devices, data, communication tools.Implement asset management practices: classification, inventory, ownership.Oversee access management: RBAC, periodic reviews, approval workflows.Safeguard data confidentiality: enforce handling rules, prevent leakage, monitor misuse.Drive governance and awareness: security culture, training, phishing campaigns.Prevent insider risks: education, monitoring, process enforcement.Manage security incidents: coordination, escalation, root cause, executive reporting.Assess and manage business risks: finance, HR, sales, operations.Strengthen supply chain security: vendor risk assessments, third-party dependencies, assurance.Maintain and test continuity plans: BCP, DRP, resilience validation.Serve as an interface for PCI DSS, DORA, SWIFT, ISO, GDPR compliance needs.RequirementsExperience in managing asset and access management systems.Experience in incident management and security governance.Knowledge of business domains, ability to identify security risks and mitigate them.Solid understanding of infrastructure and cloud security (AWS, Kubernetes, CI/CD pipelines).Practical experience in Information Security Awareness: education, simulations.Background in risk management, business continuity, and disaster recovery planning.Experience working with vendors, regulators, and external partners.Proficiency in Security standards: PCI DSS, DORA, SWIFT, ISO, GDPRNice to haveExperience in fintech, banking, or other regulated industries.Participation in certification projects (PCI DSS, ISO, SOC 2).Certifications: CISSP, CISM, CISA, AWS Security Specialty.Experience with FinOps and security cost optimization.Background in building and scaling Security Awareness programs.What We Offer:Opportunity to shape the future of fintech solutions within a growing companyCollaborative, horizontal team structure that values your expertise and ideasContinuous learning and development opportunities to enhance your skills and career growthCompetitive salary and benefits packageFlexible work arrangements to support work-life balance* Employment will be offered through one of the group's legal entities - Mellifera Kartiera Ltd, Colibrix Ltd, or Mellifera Operations Ltd - depending on the role, location, and applicable legal framework.Please note that Colibrix One is a brand representing a group of legal entities. The employment contract will be signed with the relevant company within the group (Mellifera Kartiera Ltd, Colibrix Ltd, or Mellifera Operations Ltd) depending on the nature of the position and jurisdictionThis position is offered within the Colibrix one. Employment will be under the appropriate legal entity based on the role and location. ## Related Videos - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)