Our client, a Technological Start Up, is searching for a full-time position of Head of Security and Compliance (HSC) for its global operations in Madrid. Reporting to the Chief Information Officer (CIO), the HSC will develop and execute a comprehensive information security strategy aligned with the company’s business objectives and regulatory requirements.
KEY RESPONSIBILITIES:
- Strategic Leadership: Develop and execute a comprehensive information security strategy aligned with the company’s business objectives and regulatory requirements.
- Risk Management: Collaborate with IT, Engineering and Product Teams to identify, assess, and prioritize security risks associated with Cloud native data and AI products. Develop and implement risk mitigation plans.
- Policy Development: Establish and enforce security policies, standards, and procedures to ensure the confidentiality, integrity, and availability of company data and systems.
- Incident Response: Lead the development and execution of incident response plans to effectively address security breaches and other incidents.
- Compliance: Ensure compliance with relevant laws, regulations, and industry standards, including GDPR, NIST, DORA, AI-Act, NIS2, or ISO.
- Security Awareness: Promote a culture of security awareness and best practices across the organization through training and communication initiatives.
- Vendor Management: Oversee the security of third-party vendors and partners, ensuring they meet the company’s security standards.
- Continuous Improvement: Stay current with emerging security trends, threats, and technologies, and continuously improve the company’s security posture.
SKILLS AND REQUIREMENTS:
- Excellent verbal and written communication skills in both English and Spanish, with the ability to interact effectively with stakeholders at all levels.
- Excellent ability to conceptualize long term business goals.
- Ability to make informed and effective decisions.
- Strong people management skills.
- Familiar with start-up culture and ecosystem.
EDUCATION AND EXPERIENCE:
- Bachelor’s in computer science, engineering, or relevant field.
- 10+ years of experience in Security and Compliance.
- Proven experience in leading and scaling teams.
- Strong knowledge of security frameworks and standards (e.g., NIST, ISO).
- Experience defining B2B digital channels and managing them.
- Excellent problem-solving and analytical skills.
- International work experience working with international teams.
- Experience with Cloud data and AI products and the security challenges they present.
- Outstanding communication and presentation skills.