¡Activa las notificaciones laborales por email!

Head of Security

Expenti

Málaga

Híbrido

EUR 70.000 - 100.000

Jornada completa

Hace 3 días
Sé de los primeros/as/es en solicitar esta vacante

Descripción de la vacante

A leading technology company in Málaga is seeking a Head of Security to oversee cybersecurity efforts across corporate and enterprise environments. This hybrid role involves team leadership, technical direction, and managing security initiatives. Ideal candidates will have over 5 years of cybersecurity experience, including leadership roles, and strong skills in cloud security and risk management. Attractive salary and a customizable benefits package are offered, along with flexible working options.

Servicios

Attractive salary
Customizable benefits package
Flexible working hours
Relocation assistance
Wellbeing programmes

Formación

  • 5+ years in cybersecurity, with 2+ years in a leadership or team lead role.
  • Strong technical expertise in cloud security (Azure, AWS, GCP).
  • Experience delivering SSDLC practices.

Responsabilidades

  • Lead the cybersecurity function across corporate and enterprise environments.
  • Oversee threat detection, alert triage, and incident response processes.
  • Manage the cybersecurity risk register in collaboration with IT and Engineering.

Conocimientos

Cloud security expertise (Azure, AWS, GCP)
Cybersecurity leadership experience
Technical risk management
Threat modeling
CI/CD security
Stakeholder influence

Herramientas

Microsoft Defender
AWS security tools
GCP security tools
GitLab

Descripción del empleo

About this role

We are looking for a hands-on, technically fluent Head of Security to lead our cybersecurity efforts across both corporate and enterprise environments. This is a hybrid role combining team leadership, technical security direction, risk management, and delivery of key security initiatives.

You will work closely with IT, Engineering, Architecture, and Delivery teams to drive the implementation of our cybersecurity roadmap — spanning cloud security hardening, secure SDLC, data protection, and CIS benchmark compliance. This is an ideal opportunity for a security team lead or manager ready to step into a broader, more impactful leadership role while remaining close to technical execution

Your Mission

Your mission is to lead and grow our security capability; ensuring that cloud infrastructure, development pipelines, corporate systems, and critical data are all secured against evolving threats. You will shape the execution of security OKRs, manage and mentor a small but high-performing team, and directly contribute to the delivery of key technical initiatives. By translating strategic risks into actionable controls, and collaborating across departments, you will help embed security into everything we build, deploy, and operate.

Leadership & Strategy

  • Lead the cybersecurity function across corporate (Azure/O365) and enterprise (GitLab, AWS, GCP) environments
  • Own and drive delivery of security-related OKRs, working hands-on where needed
  • Provide technical direction and mentorship to security analysts and engineers
  • Act as the internal authority on security risk, translating business objectives into appropriate technical safeguards
  • Identify skills/resource gaps and write statements of work (SOWs) to onboard external SMEs when required

Security Operations & Engineering

  • Oversee threat detection, alert triage, and incident response processes
  • Ensure proper implementation of cloud security controls (Azure Security Center, Microsoft Defender, AWS/GCP posture management)
  • Guide implementation of secure software development lifecycle (SSDLC) controls, including threat modelling and CI/CD security
  • Drive coverage and remediation of vulnerabilities in infrastructure and code

Governance, Risk, and Compliance

  • Own and maintain the cybersecurity risk register in collaboration with IT and Engineering
  • Lead internal assessments against the CIS Benchmarks for Azure, Microsoft 365, AWS, GCP, and relevant platforms
  • Track remediation of CIS control gaps and report posture improvements to IT leadership
  • Manage the development and review of key security policies and operational procedures

Collaboration & Stakeholder Engagement

  • Work closely with IT on Azure and Microsoft 365 security initiatives, including Defender and Purview rollouts
  • Partner with Engineering on SSDLC enablement and GitLab security pipelines
  • Collaborate with Delivery/PMO to align and track execution of security objectives
  • Communicate risk posture, metrics, and roadmap progress to the Director of IT and key stakeholders

What you'll bring

  • 5+ years in cybersecurity, with 2+ years in a leadership or team lead role
  • Strong technical expertise in cloud security (Azure, AWS, GCP), Microsoft Defender stack, and IAM
  • Experience delivering SSDLC practices (e.g., threat modelling, CI/CD pipeline security)
  • Working knowledge of the CIS Benchmarks and implementing associated controls
  • Proven ability to manage competing priorities, influence stakeholders, and deliver results across technical teams

What's in it for you

  • Inspiring and fulfilling work at an innovative and values-driven company creating cutting-edge tech
  • Attractive salary and customisable benefits package
  • Flexible working hours and ways of working (we promote hybrid working model (work time is split between working 3 days a week in the office and 2 days from home).
  • Contemporary and accessible office environments with a range of workplace perks
  • Relocation package for you and your family including soft-landing package services to help you settle in (applicable in Spain, if you are moving from a different city/country)
  • Being part of a team with a forward-looking, international mindset and agile working practices
  • A friendly, inclusive and multicultural environment
  • Wellbeing programmes, learning and personal growth opportunities
  • A range of employee events throughout the year
  • Opportunities to shape the tech community within and outside of the company, through mentoring and knowledge-sharing
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra un archivo en formato PDF, DOC, DOCX, ODT o PAGES de hasta 5 MB.