Business Information Security Officer

GT Global Talent
Guntín, Spain
20 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English

Tech stack

Cyber Security RSA Archer Platform

Job description

Leading multinational company specialized in the management of critical infrastructure and energy logistics (oil & gas), with an international presence.The company operates in highly regulated, distributed and operationally critical environments, with a culture built around operational excellence, safety, sustainability and people development.As part of the evolution of its global cybersecurity operating model, we are looking for a Business Information Security Officer (BISO) to act as the primary cybersecurity representative for one of their business areas.Reporting directly to the CISO, this role will work closely with, IT, Operations, Compliance, Legal and external service providers.ROLE PROPOUSE: Lead the cybersecurity function for one of their business areas, ensuring the effective implementation of the company’s cybersecurity strategy within an international, multi-site and highly regulated environment.MISSION: Act as the main cybersecurity point of contact for the business, ensuring effective risk management, regulatory compliance and alignment between the global cybersecurity strategy and business operational needs, contributing to a secure and resilient operation.RESPONSABILITIES · Cybersecurity Leadership: Act as the primary cybersecurity representative, ensuring the effective implementation of corporate cybersecurity policies, standards and strategy across an international and multi-site environment.· Governance, Risk & Compliance: Identify and manage cybersecurity risks, coordinate remediation plans, oversee control effectiveness and ensure compliance with regulatory requirements and cybersecurity standards.· Strategic Initiatives Coordination: Lead and coordinate cybersecurity programmes and initiatives, ensuring effective execution, follow-up and alignment with business priorities.· Business & Stakeholder Engagement: Work closely with Business, IT, Operations, Compliance and Legal teams to embed cybersecurity into strategic projects and transformation initiatives.· Audits, Reporting & Governance: Participate in audits, compliance reviews and governance forums, providing executive reporting on cybersecurity risks, controls and initiatives.· Third-Party Risk Management: Oversee cybersecurity risks associated with external providers and critical third parties, ensuring compliance with the organisation’s security requirements.· Continuous Improvement: Contribute to the development of cybersecurity capabilities, operating models and strategic roadmaps aligned with the needs of the business.REQUIREMENTS · Education: University degree in Engineering, Technology, Cybersecurity, Risk Management, Business Administration or a related discipline.· Experience: Proven experience in Cybersecurity Governance, Risk & Compliance (GRC), Business Information Security, Risk Management or similar functions, including risk management, audits, compliance programmes and interaction with senior stakeholders.· International Exposure: Experience within international, distributed and highly regulated environments, ideally in transportation, energy, critical infrastructure or logistics sectors.· Frameworks & Regulations: Strong knowledge of cybersecurity standards and frameworks such as ISO **, NIS2 and other relevant industry regulations.· Languages: High level of English with the ability to work effectively in international environments.Additional languages will be considered a plus.· Preferred Certifications: CISSP, CISM, CRISC, ISO ** Lead Implementer / Lead Auditor or equivalent certifications.· Additional Knowledge: Experience or knowledge in Operational Resilience, OT/ICS Security, Third-Party Risk Management, Cybersecurity Programme Governance, GRC platforms, audits, due diligence, RFPs or corporate transformation initiatives.Skills Strategic mindset combined with a strong execution-oriented approach.Ability to influence and engage effectively with senior stakeholders.Capability to operate autonomously in complex international environments.Pragmatic, collaborative and results-driven approach.Strong coordination skills across teams, suppliers and cross-functional initiatives.WE OFFER A highly visible role with real influence on the cybersecurity strategy of an international and business-critical operation.Participation in global initiatives and collaboration with multidisciplinary teams across multiple countries and operational environments.Competitive compensation package and corporate benefits aligned with the experience and responsibilities of the position.

Requirements

· Experience: Proven experience in Cybersecurity Governance, Risk & Compliance (GRC), Business Information Security, Risk Management or similar functions, including risk management, audits, compliance programmes and interaction with senior stakeholders. · International Exposure: Experience within international, distributed and highly regulated environments, ideally in transportation, energy, critical infrastructure or logistics sectors. · Frameworks & Regulations: Strong knowledge of cybersecurity standards and frameworks such as ISO **, NIS2 and other relevant industry regulations. · Languages: High level of English with the ability to work effectively in international environments. Additional languages will be considered a plus. · Preferred Certifications: CISSP, CISM, CRISC, ISO ** Lead Implementer / Lead Auditor or equivalent certifications. · Additional Knowledge: Experience or knowledge in Operational Resilience, OT/ICS Security, Third-Party Risk Management, Cybersecurity Programme Governance, GRC platforms, audits, due diligence, RFPs or corporate transformation initiatives. Skills Strategic mindset combined with a strong execution-oriented approach. Ability to influence and engage effectively with senior stakeholders. Capability to operate autonomously in complex international environments. Pragmatic, collaborative and results-driven approach. Strong coordination skills across teams, suppliers and cross-functional initiatives.

Benefits & conditions

WE OFFER A highly visible role with real influence on the cybersecurity strategy of an international and business-critical operation. Participation in global initiatives and collaboration with multidisciplinary teams across multiple countries and operational environments. Competitive compensation package and corporate benefits aligned with the experience and responsibilities of the position.

About the company

Guntín, Lugo, España

Leading multinational company specialized in the management of critical infrastructure and energy logistics (oil & gas), with an international presence. The company operates in highly regulated, distributed and operationally critical environments, with a culture built around operational excellence, safety, sustainability and people development.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:02 min

Navigating DORA compliance and executive liability in security

Michele Zuccala Michele Zuccala +4 · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:17 min

Governing enterprise IT as a global automotive CIO

Katrin Lehmann Katrin Lehmann +1 · Coffee With Developers

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · World Congress 2023

Videos

See all

Related articles

See all