Information Security Risk Manager

MultiSafepay

Málaga

Presencial

EUR 70.000 - 100.000

Jornada completa

Hace 7 días
Sé de los primeros/as/es en solicitar esta vacante
Generador de candidaturas

No envíes un currículum genérico: crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Ventajas ofrecidas por este puesto de trabajo

Free Spanish classes
Afterwork sports activities
Professional growth opportunities
International team

Descripción de la vacante

MultiSafepay, a leading FinTech in Europe, seeks an Information Security Risk Manager to own the ICT risk framework and the Eramba GRC suite in the second line of defence. You will oversee risk registers, ISMS policy alignment, and 2LoD PCI DSS and DORA governance, reporting to senior risk leadership.

The role requires 5–8 years in ICT risk management, strong knowledge of DORA and ISO 27001, and experience translating complex tech risks to executives.

Formación

  • Candidates must have experience in ICT risk management within regulated financial environments.
  • Strong knowledge of DORA, ISO/IEC 27001 and PCI DSS v4.0 is required.
  • Experience with GRC platforms such as Eramba and RCSA execution is essential.

Responsabilidades

  • Maintain and develop the ICT risk register and monitor ICT controls via KRI dashboards.
  • Own the ISMS policy suite aligned with ISO 27001 and DORA; coordinate 2LoD oversight.
  • Support DORA obligations including ICT incident classification and major incident reporting.
  • Lead PCI DSS 2LoD governance and coordinate PCI-3DS as a project stream.
  • Manage Eramba GRC platform data structures, user access, and rollout to new modules.
  • Provide second line of defence oversight of ICT third-party risk and support EY IT audit.

Conocimientos

ICT risk management
ISO 27001
PCI DSS
GRC platform (Eramba)
RCSA
KRI reporting
2LoD governance
stakeholder communication
DORA

Educación

Bachelor's or Master's in Information Security / CS / Risk Management

Herramientas

Eramba GRC

Descripción del empleo

MultiSafepay is a leading payment service provider, offering omnichannel and advanced payment solutions to businesses across Europe. We are innovative and fast-growing, building powerful solutions that transform the way our clients do business. We focus on delivering real solutions to their challenges and always stay ahead of the curve. In short, we are a true FinTech.

We're on a mission to make payments simple, secure, and accessible for every business. With powerful in-house technology and deep expertise, our modular platform brings online, in-person, and cross-border payments together in one place — giving merchants the flexibility to scale on their own terms. Through a partnership-first approach, we tackle complexity head-on, keep payments running smoothly, and boost success rates. It's how we level the playing field for businesses of all sizes and ambitions.

We are looking for an Information Security Risk Manager to act as the primary operational owner of MultiSafepay's ICT Risk Management Framework within the second line of defence. In this role, you will be responsible for the day-to-day execution, monitoring, and reporting of ICT risk and information security activities in line with DORA, ISO 27001, and PCI DSS requirements. You will own the Eramba GRC platform, the ISMS policy suite, and the ICT risk register, providing technical ICT risk input to the Head of Risk & Compliance for board-level reporting.

What you'll be doing:
  • Maintaining and developing the ICT risk register, executing the RCSA cycle for ICT risk domains, and monitoring key ICT controls including KRI dashboard management
  • Owning the ISMS policy suite in line with ISO 27001, DORA, and MultiSafepay document standards, and coordinating security monitoring oversight from a 2LoD perspective
  • Supporting DORA Chapter II obligations including ICT incident classification and major incident reporting, and monitoring the external threat landscape to translate developments into 2LoD risk signals
  • Leading PCI DSS 2LoD governance as primary owner of PCI DSS v4.0 compliance oversight, coordinating PCI-3DS as a separate project stream, and acting as primary contact for QSA and internal stakeholders
  • Owning the Eramba GRC platform including data structure, user access, and module configuration, and driving its rollout to new modules and processes as the ICT risk framework matures
  • Providing second line of defence oversight of ICT third-party risk, acting as primary liaison for the annual EY IT audit, and supporting the annual Ant Group IT risk reporting cycle
What You'll Need
  • 5-8 years of experience in ICT risk management, information security, or a related discipline within a highly regulated financial institution
  • Demonstrable experience with DORA (ICT risk management chapter), ISO/IEC 27001, and PCI DSS v4.0
  • Hands-on experience with a GRC platform such as Eramba or equivalent, including RCSA execution, control monitoring, and KRI reporting
  • A Bachelor's or Master's degree in Information Security, Computer Science, Risk Management, or an equivalent field
  • Strong ability to translate complex technical risks into clear reporting for non-technical stakeholders, with a structured, process-oriented working style
  • Ability to constructively challenge first line of defence stakeholders on ICT risk and security topics
  • Strong written and verbal communication skills in English
Nice To Have
  • Relevant certifications such as ISO 27001 Lead Implementer, CISM, or CRISC
  • PCI DSS certification or demonstrable practical experience
What You'll Get From Us
  • A competitive salary and benefits package
  • Free Spanish classes and optional afterwork sports activities
  • Opportunities for professional growth
  • A diverse role within a dedicated international team of enthusiastic colleagues
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Information Security Risk Manager
Information Security Risk Manager

Multisafepay BV • Estepona

Híbrido
EUR 70.000 - 100.000
Competitive salary & benefits
Free Spanish classes
Growth opportunities
+1
InfoSec Risk Manager – 2LoD, ISO27001 & PCI DSS
InfoSec Risk Manager – 2LoD, ISO27001 & PCI DSS

MultiSafepay • Málaga

Presencial
EUR 70.000 - 100.000
Free Spanish classes
Afterwork sports activities
Professional growth opportunities
+1
Senior ICT Risk & InfoSec Manager (DORA/ISO27001)
Senior ICT Risk & InfoSec Manager (DORA/ISO27001)

Multisafepay BV • Estepona

Híbrido
EUR 70.000 - 100.000
Competitive salary & benefits
Free Spanish classes
Growth opportunities
+1
Risk Analyst
Risk Analyst

Multisafepay BV • Málaga

Presencial
EUR 42.000 - 54.000
Health insurance
Professional growth
Diverse international team
+2
Information Security Manager
Information Security Manager

COLIBRIX ONE • Barcelona

Presencial
EUR 60.000 - 90.000
Competitive salary
Flexible work arrangements
Continuous learning and development
Senior Data Engineer
Senior Data Engineer

Multisafepay BV • Estepona

Híbrido
EUR 40.000 - 65.000
Salary package
Career growth
International team
+4
Business Development Manager
Business Development Manager

Multisafepay BV • España

Presencial
EUR 42.000 - 60.000
Competitive salary & benefits
Professional growth opportunities
Diverse international team
+2
Merchant Solutions Engineer - Payments
Merchant Solutions Engineer - Payments

Multisafepay BV • Málaga

Híbrido
EUR 60.000 - 90.000
Database Administrator
Database Administrator

Multisafepay BV • Estepona

Presencial
EUR 42.000 - 62.000
Full health coverage
Free Spanish classes
Afterwork sports activities
+2
Risk Lead
Risk Lead

PayXpert • Barcelona

Presencial
EUR 90.000 - 130.000