Chief Information Security Officer

Propertyvalue
Spain
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Software System Penetration Testing Cloud Computing Security Cyber Security Identity and Access Management Intrusion Detection and Prevention PCI Data Security Standards Phishing Software Vulnerability Management Information Technology CIS Benchmarks Devsecops

Job description

Governance - Establish cybersecurity risk management frameworks and policies - Conduct risk assessments, vulnerability management, and penetration testing - Align with standards such as ISO/IEC 27001, NIST, and CIS Controls 4. Compliance & Regulatory Oversight - Ensure compliance with regulations such as GDPR, HIPAA, PCI-DSS, and local cybersecurity laws - Manage audits, certifications, and regulatory reporting - Partner with legal, compliance, and audit teams 5. Incident Response & Resilience - Lead incident response planning, crisis management, and breach handling - Ensure business continuity and disaster recovery readiness - Conduct simulations and tabletop exercises 6. Identity & Access Management (IAM) - Oversee identity governance, access controls, and privileged access management - Ensure secure authentication and authorization mechanisms 7. Third-Party & Cloud Security - Manage vendor and third-party risk assessments - Ensure security across cloud platforms and

Requirements

outsourced services - Establish secure DevSecOps practices 8. Security Awareness & Training - Develop organization-wide security awareness programs - Train employees on cyber risks, phishing, and best practices Qualifications & Experience - Bachelor’s or Master’s degree in Cybersecurity, IT, Computer Science, or related field - 15-20+ years of experience in cybersecurity or IT security roles - 5+ years in senior leadership roles (CISO, Head of Security, etc.) - Strong expertise in security architecture, risk management, and compliance - Professional certifications preferred (CISSP, CISM, CRISC, etc.) Key Competencies - Deep cybersecurity and risk management expertise - Strategic thinking and business alignment - Crisis management and decision-making under pressure - Strong leadership and stakeholder influence - Regulatory and compliance knowledge

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on es.trabajo.org

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

2:39 min

Exposing stored XSS and phishing attacks via markdown

Ramona Schwering Ramona Schwering · World Congress 2026 Europe

Videos

See all

Related articles

See all