Information Security Officer

CNP Santander Insurance

Dublin

On-site

EUR 90,000 - 120,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CNP Santander Insurance (CNPSI) is seeking an Information Security Officer to lead the Information Security Function. Reporting directly to the Chief Information Officer, the role is responsible for the design and delivery of day-to-day security controls and implementation of the security strategy.

This person will work closely with the CIO and external security consultants to ensure CNPSI maintains a strong security posture across both its internal systems and supply chain.

Qualifications

  • Information Security qualifications related to the role.
  • Extensive years of solid experience in IT analysis/design, information security, or control and compliance.
  • Ability to operate and articulate effectively in a matrix environment.

Responsibilities

  • Provide technical security advice and risk-based recommendations across the business.
  • Define and evolve the Information Security strategy, roadmap, and operating model with the CIO; lead delivery of IS programmes.
  • Design, implement and continuously improve security controls, standards and procedures.
  • Ensure compliance and alignment with internal policy, regulatory expectations, and CNP group requirements.
  • Own security policy and awareness content; promote understanding and adoption across stakeholders.
  • Provide regular reporting on security posture, initiatives and risks to senior stakeholders, CRO and group forums.
  • Define and track IS KPIs/KRIs; analyse trends and drive improvements.
  • Oversee remediation for security events/incidents, assessments and audits; verify closure.
  • Monitor threat intelligence and vulnerabilities; coordinate response and supplier visibility.
  • Direct and support managed security service providers and operations teams on security priorities.
  • Challenge technology changes and vendor proposals to ensure security-by-design and proportionate controls.
  • Lead security incident management and root-cause remediation.
  • Assess security technologies and best practices to strengthen capabilities.
  • Coordinate with CNP group CISOs on security initiatives and reporting.
  • Provide ad hoc security input to business initiatives; support data protection with the DPO.
  • Set third-party security requirements with Vendor Management; advise on supplier risk assessments.
  • Contribute to security monitoring with CNP and external bodies.

Skills

Information security
IT analysis/design
Control and compliance
Matrix environment
Communication skills

Education

Information security qualifications

Job description

Information Security is a key priority for CNPSI. We have built a strong governance framework and have an Information Security Strategy for the period 2026-2028. As a financial entity regulated by the CBI, compliance with DORA is an important requirement.

The Information Security Officer for CNPSI leads the Information Security Function. Reporting directly to the Chief Information Officer, the role is responsible for the design and delivery of day-to-day security controls and implementation of the security strategy. This person will work closely with the CIO and external security consultants to ensure that CNPSI maintains a strong security posture across both its internal systems and supply chain.

Key Responsibilities:
  • Information Security SME: provide technical security advice and risk-based recommendations across the business.
  • Define and evolve the Information Security (IS) strategy, roadmap and operating model with the CIO; lead delivery of IS programmes.
  • Design, implement and continuously improve security controls, standards and procedures.
  • Ensure compliance and alignment with internal policy, regulatory expectations and CNP group requirements.
  • Own security policy and awareness content; promote understanding and adoption across stakeholders.
  • Provide regular reporting on security posture, key initiatives and emerging risks to senior stakeholders, CRO and group forums.
  • Define and track IS KPIs/KRIs; analyse trends and drive measurable improvement actions.
  • Oversee remediation for security events/incidents, assessments and audits; verify closure and effectiveness.
  • Monitor threat intelligence and vulnerability information; assess impact, share insight and coordinate response. Maintain visibility of security posture and key risks across critical suppliers and the wider supply chain.
  • Direct and support managed security service providers and operations teams on security priorities and issues.
  • Challenge technology changes and vendor proposals to ensure security-by-design, compliance with DORA and proportionate controls.
  • Lead security incident management and problem management; drive root-cause remediation and prevention.
  • Assess and recommend security technologies and best practices to strengthen capabilities and resilience.
  • Coordinate with CNP group CISOs on security initiatives, reporting and shared control improvements.
  • Provide ad hoc security support and input to business initiatives as required.
  • Support personal data protection in collaboration with the DPO (security controls, incidents and risk treatment).
  • Set third-party security requirements with Vendor Management; advise on supplier assessments and risk decisions.
  • Contribute to security monitoring with CNP and external bodies (threats, vulnerabilities, sharing and coordinated response).
Qualifications/Competencies:
  • Information Security related qualifications
  • Extensive years of solid experience in either IT analysis/design, information security, or control and compliance
  • Able to operate and articulate effectively in a matrix environment
Strong understanding of:
  • Cyber security for Cloud technologies; particularly Azure, ADFS, SAML, Microsoft Stack including Intune, O365, AIP etc.
  • Cyber security for WAN/LAN.
  • Vulnerability and Pen test reports and ability to analyse and evaluate.
  • Security awareness concepts.
  • Excellent communication skills - able to communicate effectively with colleagues at all levels. Particulary adept at visual communications, PowerPoint slides etc for the purpose of developing security awareness content
  • Strong, proven negotiation skills and ability to influence others particularly when working with external vendors.
  • Continually seeking to improve work processes in line with best practice
  • Ability to prioritise tasks, meet deadlines and deal with changing priorities
  • Well organised and self-motivated
  • Excellent attention to detail
  • Ambition to exceed expectations
  • Experience of working within a regulated sector and an understanding of the implications of the same on Information Security.
Desirable but not essential for the role:
  • Experience of working in the insurance sector, preferably in a cross-border business environment
  • Experience in working in a multilingual, multicultural environment
  • Experience with ISO27001, NIST, CyFun and/or CIS IG3
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Lead: Strategy, Risk & Compliance
Information Security Lead: Strategy, Risk & Compliance

CNP Santander Insurance • Dublin

On-site
EUR 90,000 - 120,000
Information Security Officer
Information Security Officer

Cpl Healthcare • Dublin

Hybrid
EUR 95,000 - 130,000
European CISO
European CISO

FNZ Group • Ireland

On-site
EUR 70,000 - 100,000
European CISO
European CISO

FNZ • Dublin

On-site
EUR 80,000 - 120,000
Senior Cyber Security Specialist
Senior Cyber Security Specialist

Irving Oil • Dublin

On-site
EUR 120,000 - 180,000
Senior Manager Information Security
Senior Manager Information Security

I.T. Alliance Resourcing Services • Dublin

Hybrid
EUR 100,000 - 110,000
Cyber Security Analyst (Operations & Risk)
Cyber Security Analyst (Operations & Risk)

BnM • Newbridge

On-site
EUR 70,000 - 100,000
Senior Cyber Security Specialist
Senior Cyber Security Specialist

Irving Oil • Cork

On-site
EUR 110,000 - 140,000
Senior Specialist, IT Infosecurity Technical & Operations
Senior Specialist, IT Infosecurity Technical & Operations

THE FARRER PARK COMPANY PTE. LTD. • Dublin

On-site
EUR 50,000 - 80,000
Information Security Consultant
Information Security Consultant

Digital Waffle • Dublin

On-site
EUR 65,000 - 90,000