Security Manager – Azure

Jobtailor

Sant Joan Despí

Presencial

EUR 90.000 - 120.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Jobtailor in Spain, Cataluña (Sant Joan Despí) seeks an experienced security governance lead to own and improve ISMS, policies, and risk management across cloud environments.

You will collaborate with engineering, product, and compliance teams to drive audits, implement Zero Trust, manage Defender for Cloud and AWS Security Hub findings, and report metrics to senior stakeholders.

Formación

  • At least 5 years in information security, risk, audit, or compliance, with 3+ years in a similar role.
  • Strong understanding of ISO 27001, risk methodologies and modern security frameworks.
  • Solid knowledge of Azure and AWS security controls.
  • Experience producing security assurance metrics for senior stakeholders.

Responsabilidades

  • Own and continuously improve ISMS, policies, and security governance lifecycle.
  • Act as trusted advisor to engineering, product, compliance and customer teams.
  • Lead security risk assessments and drive quarterly risk cycles.
  • Ensure ISO 27001:2022, GSMA SAS, NIS-2 compliance and evidence readiness.
  • Coordinate audits and assessments; manage governance evidence.
  • Lead vendor risk programs to strengthen supply chain resilience.
  • Review product changes for governance and secure design.
  • Collaborate with Security Architect to connect governance with DevSecOps.
  • Own Azure security posture; govern Defender for Cloud findings and Entra ID CA policies.
  • Support across AWS and Azure workloads; enforce Zero Trust across cloud environments.
  • Govern IaC and CI/CD security gates; review templates for secrets management.
  • Produce assurance reporting with metrics on risk register and remediation.

Conocimientos

ISMS ownership
Cloud security governance
ISO 27001
Azure security
AWS security
Zero Trust
IAM
Security audits
Risk management
DevSecOps

Descripción del empleo

Responsibilities
  • Own and continuously improve our ISMS, policies, and security governance lifecycle.
  • Act as a trusted advisor to engineering, product, compliance, and customer‑facing teams.
  • Lead security risk assessments, maintain the risk register, and drive quarterly risk cycles.
  • Ensure operational compliance with ISO 27001:2022, GSMA SAS, NIS-2 and customer security requirements and support hands‑on with configuration tasks.
  • Coordinate external and internal audits and assessments, ensuring evidence readiness and smooth execution.
  • Lead vendor risk programs that strengthen our supply chain resilience.
  • Review product and architectural changes for governance alignment and secure design.
  • Collaborate with the Security Architect to connect governance with DevSecOps and cloud practices.
  • Own Azure security posture, govern Microsoft Defender for Cloud findings, Entra ID Conditional Access policies, Privileged Identity Management (JIT access), and quarterly access reviews.
  • Support on cross‑platform governance tasks, policy alignment, and shared risk register entries covering AWS and Azure workloads.
  • Enforce Zero Trust controls across cloud environments: continuous verification, least‑privilege access, and RBAC/ABAC enforcement.
  • Govern IaC and CI/CD pipeline security gates: review IaC templates for secrets management compliance, approve pipeline security controls, and validate rollback procedures.
  • Produce structured assurance reporting for management: metrics tied to the risk register, control effectiveness, and remediation tracking for findings from Defender for Cloud and AWS Security Hub.
Requirements
  • At least 5 years in information security, risk, audit, or compliance, with a minimum of 3 years in a similar role (security management, cloud security governance, or ISMS ownership), ideally in regulated environments (telecommunications, banking, payments, SaaS).
  • Strong understanding of ISO 27001, risk methodologies, and modern security frameworks.
  • Solid knowledge of security controls (IAM, third‑party risk, secure SDLC, cloud).
  • Ability to challenge and support engineering teams constructively.
  • Solid knowledge of Azure and AWS security controls.
  • Practical understanding of Zero Trust architecture principles and shared responsibility models across IaaS, PaaS, and SaaS.
  • Familiarity with IaC security practices: secrets management, pipeline approval workflows, and dependency vulnerability handling.
  • Experience producing security assurance metrics and governance reports for senior stakeholders.
  • Excellent analytical, documentation, and problem‑solving skills.
  • Fluent English; German or Spanish is a plus.
Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Information Security Engineer
Information Security Engineer

Jobtailor • Madrid

Presencial
EUR 70.000 - 90.000
Security Manager Azure
Security Manager Azure

Giesecke & Devrient GB Ltd. • Barcelona

Híbrido
EUR 65.000 - 85.000
Flexible working hours
Career development programs
Own canteen with meal services
It Infrastructure & Security Project Manager
It Infrastructure & Security Project Manager

MCR International • Barcelona

Presencial
EUR 90.000 - 120.000
Information Security Engineer
Information Security Engineer

Dentons • Madrid

Presencial
EUR 60.000 - 90.000
Competitive salary
International environment
Azure Cloud Security Engineer
Azure Cloud Security Engineer

apeirum • Barcelona

Presencial
Confidencial
Small security team
Barcelona tech hub
Permanent contract
+1
Information Security Engineer
Information Security Engineer

Dentons • España

Presencial
EUR 60.000 - 90.000
Remuneration and benefits package will
Azure Cloud Security Engineer
Azure Cloud Security Engineer

ADD & CO • Bellprat

Híbrido
Confidencial
Hybrid work setup
Professional development
International collaboration
+1
Azure Cloud Security Engineer
Azure Cloud Security Engineer

ADD & CO • Barcelona

Híbrido
Confidencial
Hybrid setup – Barcelona-based
Small team of 4
International collaboration withSwitz
+2
Azure Security Manager - Remote & Flexible Hours
Azure Security Manager - Remote & Flexible Hours

Giesecke & Devrient GB Ltd. • Barcelona

Híbrido
EUR 65.000 - 85.000
Flexible working hours
Career development programs
Own canteen with meal services
Cloud Security Engineer
Cloud Security Engineer

Werfen • Barcelona

Presencial
EUR 50.000 - 75.000