Security Manager

Hace 2 semanas

Sant Joan Despí Barcelona, Bajo Llobregat (comarca); Provincia de Barcelona; Cataluña, España Jobtailor Jornada completa

Responsibilities

  • Own and continuously improve our ISMS, policies, and security governance lifecycle.
  • Act as a trusted advisor to engineering, product, compliance, and customer‑facing teams.
  • Lead security risk assessments, maintain the risk register, and drive quarterly risk cycles.
  • Ensure operational compliance with ISO 27001:2022, GSMA SAS, NIS-2 and customer security requirements and support hands‑on with configuration tasks.
  • Coordinate external and internal audits and assessments, ensuring evidence readiness and smooth execution.
  • Lead vendor risk programs that strengthen our supply chain resilience.
  • Review product and architectural changes for governance alignment and secure design.
  • Collaborate with the Security Architect to connect governance with DevSecOps and cloud practices.
  • Own Azure security posture, govern Microsoft Defender for Cloud findings, Entra ID Conditional Access policies, Privileged Identity Management (JIT access), and quarterly access reviews.
  • Support on cross‑platform governance tasks, policy alignment, and shared risk register entries covering AWS and Azure workloads.
  • Enforce Zero Trust controls across cloud environments: continuous verification, least‑privilege access, and RBAC/ABAC enforcement.
  • Govern IaC and CI/CD pipeline security gates: review IaC templates for secrets management compliance, approve pipeline security controls, and validate rollback procedures.
  • Produce structured assurance reporting for management: metrics tied to the risk register, control effectiveness, and remediation tracking for findings from Defender for Cloud and AWS Security Hub.

Requirements

  • At least 5 years in information security, risk, audit, or compliance, with a minimum of 3 years in a similar role (security management, cloud security governance, or ISMS ownership), ideally in regulated environments (telecommunications, banking, payments, SaaS).
  • Strong understanding of ISO 27001, risk methodologies, and modern security frameworks.
  • Solid knowledge of security controls (IAM, third‑party risk, secure SDLC, cloud).
  • Ability to challenge and support engineering teams constructively.
  • Solid knowledge of Azure and AWS security controls.
  • Practical understanding of Zero Trust architecture principles and shared responsibility models across IaaS, PaaS, and SaaS.
  • Familiarity with IaC security practices: secrets management, pipeline approval workflows, and dependency vulnerability handling.
  • Experience producing security assurance metrics and governance reports for senior stakeholders.
  • Excellent analytical, documentation, and problem‑solving skills.
  • Fluent English; German or Spanish is a plus.
#J-18808-Ljbffr