Cyber Security Manager at Shine
Shine Bank is looking for a Cyber Security Manager to help shape and operate our information security and digital operational resilience framework. Reporting directly to the CISO, you will take a key role in implementing and maturing our Cyber Defence capabilities in close collaboration with IT, Risk, Internal Audit and Management. As Cyber Security Manager, you will own our defensive security technology stack and our incident-readiness capability.
Your responsibilities
- Own, evaluate, and continuously improve our defensive security technology stack – EDR/XDR, DDoS protection, vulnerability management, DLP, and endpoint hardening.
- Ensure robust DDoS protection across our internet‑facing and payment‑critical services – selecting and managing mitigation solutions (e.g. Cloudflare, Akamai, AWS Shield) validating that protection holds up to the availability expectations regulators place on a payment institution.
- Design, write, and maintain incident response playbooks for our most relevant scenarios aligned with DORA ICT incident‑management expectations.
- Plan and facilitate regular tabletop exercises and simulations across technical, operational, and executive stakeholders; capture findings and drive remediation to closure.
- Partner with the SOC Manager to ensure tooling supports detection and response use cases (mapped to MITRE ATT&CK).
- Provide the technical evidence and control assurance the Information Security (GRC) function needs for PCI‑DSS, DORA, and ACPR‑related obligations.
- Manage security vendor and MSSP relationships, contribute to the security technology roadmap and budget, and translate threat intelligence into concrete control improvements.
- Report on resilience metrics and the effectiveness of deployed controls to security leadership.
Job located in Berlin or Madrid office, with possibility of two remote working days per week.
About you
- Hands‑on background in technical/engineering security operations, ideally within regulated financial services, payments, or fintech.
- Practical experience deploying and operating EDR/XDR platforms (e.g. CrowdStrike, SentinelOne, Microsoft Defender) and other core defensive tooling.
- Hands‑on experience with DDoS mitigation and edge/CDN security (e.g. Cloudflare, Akamai, AWS Shield/WAF) and an understanding of how to protect high‑availability, customer‑facing services.
- Demonstrated incident response experience – you have built playbooks and run tabletop exercises, not just read about them.
- Working knowledge of DORA, PCI‑DSS, NIS2 and MITRE ATT&CK.
- Strong stakeholder and vendor management skills, with the ability to bridge technical detail and business risk.
- Fluent English required; German is a strong advantage.
Equal Opportunity Employer
We follow the principle of equal treatment to consider all job applicants and do not discriminate based on their gender, sexual orientation, color, racial or ethnic origin, religion, disability, etc. as per applicable law.
Location: Madrid, Berlin (Banking & Compliance)