> Markdown version of [/jobs/ext/2764888-information-security-manager](https://www.wearedevelopers.com/jobs/ext/2764888-information-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Manager - **Company:** Colibrix One - **Location:** Barcelona, Spain - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Cloud Computing Security, Cyber Security, Continuous Integration, Disaster Recovery, Identity and Access Management, Payment Service Provider, PCI Data Security Standards, Role-Based Access Control, Phishing, Kubernetes - **Published:** September 6, 2026 - **Apply:** https://www.buscojobs.com.es/information-security-manager-en-barcelona-ID-369573202 ## About the Role We're looking for an experienced Information Security Manager to lead security policy development, manage risks and incidents, and ensure compliance with standards like PCI DSS, ISO, and GDPR., Experience in managing asset and access management systems Experience in incident management and security governance Knowledge of business domains, ability to identify security risks and mitigate them Solid understanding of infrastructure and cloud security (AWS, Kubernetes, CI/CD pipelines) Practical experience in Information Security Awareness: education, simulations Background in risk management, business continuity, and disaster recovery planning Experience working with vendors, regulators, and external partners Proficiency in Security standards: PCI DSS, DORA, SWIFT, ISO, GDPR Nice to have Experience in fintech, banking, or other regulated industries Participation in certification projects (PCI DSS, ISO, SOC 2) Certifications: CISSP, CISM, CISA, AWS Security Specialty Experience with FinOps and security cost optimization Background in building and scaling Security Awareness programs ## Description Join Colibrix One - Innovating the Future of PaymentsAt Colibrix One, we're building advanced, AI-powered payment technologies that support Payment Service Providers (PSPs), Electronic Money Institutions (EMIs), and neobanks across the EU and the UK. As a fully licensed EMI (FCA reference number ******) and a Principal Member of Mastercard, we offer real-world financial solutions that include:Global card processingDigital wallet infrastructureCross-border merchant accountsAlternative payment methods (APMs)Corporate accounts for legal entitiesWe're a fast-growing team with a passion for innovation, security, and scalability. Our culture values curiosity, collaboration, and impact - and we're looking for talented professionals who are ready to shape the future of fintech.We're looking for an experienced Information Security Manager to lead security policy development, manage risks and incidents, and ensure compliance with standards like PCI DSS, ISO, and GDPR.ResponsibilitiesDevelop and enforce security policies: company-wide rules, standards, and proceduresDefine acceptable use rules: corporate devices, data, communication toolsImplement asset management practices: classification, inventory, ownershipOversee access management: RBAC, periodic reviews, approval workflowsSafeguard data confidentiality: enforce handling rules, prevent leakage, monitor misuseDrive governance and awareness: security culture, training, phishing campaignsPrevent insider risks: education, monitoring, process enforcementManage security incidents: coordination, escalation, root cause, executive reportingAssess and manage business risks: finance, HR, sales, operationsStrengthen supply chain security: vendor risk assessments, third-party dependencies, assuranceMaintain and test continuity plans: BCP, DRP, resilience validationServe as an interface for PCI DSS, DORA, SWIFT, ISO, GDPR compliance needsRequirementsExperience in managing asset and access management systemsExperience in incident management and security governanceKnowledge of business domains, ability to identify security risks and mitigate themSolid understanding of infrastructure and cloud security (AWS, Kubernetes, CI/CD pipelines)Practical experience in Information Security Awareness: education, simulationsBackground in risk management, business continuity, and disaster recovery planningExperience working with vendors, regulators, and external partnersProficiency in Security standards: PCI DSS, DORA, SWIFT, ISO, GDPRNice to haveExperience in fintech, banking, or other regulated industriesParticipation in certification projects (PCI DSS, ISO, SOC 2)Certifications: CISSP, CISM, CISA, AWS Security SpecialtyExperience with FinOps and security cost optimizationBackground in building and scaling Security Awareness programsWhat We OfferOpportunity to shape the future of fintech solutions within a growing companyCollaborative, horizontal team structure that values your expertise and ideasContinuous learning and development opportunities to enhance your skills and career growthCompetitive salary and benefits packageFlexible work arrangements to support work-life balanceWe are an equal opportunities employer and welcome applications from all qualified candidates.#J-*****-Ljbffr ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers)