Cyber Security Manager

Shine

España

On-site

PHP 4,567,814 - 6,324,666

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Shine is looking for a Cyber Security Manager to enhance our information security framework. The role involves working closely with various teams to implement Cyber Defense capabilities. You will manage the defensive security technology stack and ensure incident readiness.

This position is available in Madrid or Berlin, allowing for two remote working days each week. Strong technical expertise in security operations and familiarity with relevant regulations is essential. Fluent English is required, and German is a plus.

Qualifications

  • Hands-on experience in security operations within regulated financial services.
  • Practical experience with EDR/XDR platforms and defensive tools.
  • Strong understanding of DDoS mitigation and edge/CDN security.

Responsibilities

  • Own and improve defensive security technology stack.
  • Ensure robust DDoS protection for critical services.
  • Design and maintain incident response playbooks.
  • Facilitate tabletop exercises and simulations.
  • Partner with SOC Manager for detection and response.
  • Manage security vendor relationships and technology roadmap.
  • Report on resilience metrics to security leadership.

Skills

Technical/engineering security operations
EDR/XDR platforms
DDoS mitigation
Incident response
Stakeholder management
Fluent English
German

Tools

CrowdStrike
SentinelOne
Microsoft Defender
Cloudflare
Akamai
AWS Shield

Job description

Cyber Security Manager at Shine

Shine Bank is looking for a Cyber Security Manager to help shape and operate our information security and digital operational resilience framework. Reporting directly to the CISO, you will take a key role in implementing and maturing our Cyber Defence capabilities in close collaboration with IT, Risk, Internal Audit and Management. As Cyber Security Manager, you will own our defensive security technology stack and our incident-readiness capability.

Your responsibilities
  • Own, evaluate, and continuously improve our defensive security technology stack – EDR/XDR, DDoS protection, vulnerability management, DLP, and endpoint hardening.
  • Ensure robust DDoS protection across our internet‑facing and payment‑critical services – selecting and managing mitigation solutions (e.g. Cloudflare, Akamai, AWS Shield) validating that protection holds up to the availability expectations regulators place on a payment institution.
  • Design, write, and maintain incident response playbooks for our most relevant scenarios aligned with DORA ICT incident‑management expectations.
  • Plan and facilitate regular tabletop exercises and simulations across technical, operational, and executive stakeholders; capture findings and drive remediation to closure.
  • Partner with the SOC Manager to ensure tooling supports detection and response use cases (mapped to MITRE ATT&CK).
  • Provide the technical evidence and control assurance the Information Security (GRC) function needs for PCI‑DSS, DORA, and ACPR‑related obligations.
  • Manage security vendor and MSSP relationships, contribute to the security technology roadmap and budget, and translate threat intelligence into concrete control improvements.
  • Report on resilience metrics and the effectiveness of deployed controls to security leadership.

Job located in Berlin or Madrid office, with possibility of two remote working days per week.

About you
  • Hands‑on background in technical/engineering security operations, ideally within regulated financial services, payments, or fintech.
  • Practical experience deploying and operating EDR/XDR platforms (e.g. CrowdStrike, SentinelOne, Microsoft Defender) and other core defensive tooling.
  • Hands‑on experience with DDoS mitigation and edge/CDN security (e.g. Cloudflare, Akamai, AWS Shield/WAF) and an understanding of how to protect high‑availability, customer‑facing services.
  • Demonstrated incident response experience – you have built playbooks and run tabletop exercises, not just read about them.
  • Working knowledge of DORA, PCI‑DSS, NIS2 and MITRE ATT&CK.
  • Strong stakeholder and vendor management skills, with the ability to bridge technical detail and business risk.
  • Fluent English required; German is a strong advantage.
Equal Opportunity Employer

We follow the principle of equal treatment to consider all job applicants and do not discriminate based on their gender, sexual orientation, color, racial or ethnic origin, religion, disability, etc. as per applicable law.

Location: Madrid, Berlin (Banking & Compliance)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Manager – Incident Response & Defense (Hybrid)
Cyber Security Manager – Incident Response & Defense (Hybrid)

Shine • España

Hybrid
PHP 4,567,000 - 6,325,000
Payments Security Consultant (m/f/d)
Payments Security Consultant (m/f/d)

Schwarz • España

On-site
PHP 800,000 - 1,200,000
IT Security Engineer (m/f/d)
IT Security Engineer (m/f/d)

Deutsche Pfandbriefbank AG • España

Hybrid
PHP 3,953,000 - 5,392,000
Compelling compensation
Family-friendly working conditions
Attractive locations
Senior Security Engineer
Senior Security Engineer

Swiss Re • España

Hybrid
PHP 4,237,000 - 7,062,000
Performance-based bonus
Hybrid work model
Cybersecurity/IT Risk Officer - Bank | Up to 80K Salary
Cybersecurity/IT Risk Officer - Bank | Up to 80K Salary

weSource Management Consultancy Firm • Makati

On-site
GDS Consulting_Cyber Risk, Compliance & Resilience- Senior
GDS Consulting_Cyber Risk, Compliance & Resilience- Senior

Hammerjack Pty Ltd • Taguig

On-site
PHP 1,200,000 - 1,800,000
Coaching and feedback
Career development opportunities
Flexible work approach
ACDC Governance - Customer Frontend & Reporting Internship (m/f/d)
ACDC Governance - Customer Frontend & Reporting Internship (m/f/d)

Allianz • España

Hybrid
Paid internship
Flexible working hours
Activities and events weekly
Remote IT Security Engineer — SIEM & Threat Response
Remote IT Security Engineer — SIEM & Threat Response

Deutsche Pfandbriefbank AG • España

Hybrid
PHP 3,953,000 - 5,392,000
Compelling compensation
Family-friendly working conditions
Attractive locations
Security Engineer - AppSec
Security Engineer - AppSec

Coberon Chronos • España

Remote
PHP 4,972,000 - 7,813,000
Cybersecurity Program Manager
Cybersecurity Program Manager

ContactPoint360 • Cebu City

On-site
PHP 900,000 - 1,500,000