Senior Cyber Security Manager (m./f./div.)

Keenfinity Group

Aveiro

Híbrido

EUR 80 000 - 110 000

Tempo integral

há 40 horas
Torna-te num dos primeiros candidatos
Gerador de candidaturas

Uma candidatura feita para esta oferta — um currículo e uma carta de apresentação personalizados que vão ao encontro do anúncio.

Ultrapassa os filtros ATS

Vantagens oferecidas por esta oferta de emprego

Flexible work
Health insurance
Gym
Training & certifications
Career progression
Global collaboration
Disability friendly

Resumo da oferta

Keenfinity Group seeks a Senior Cyber Security Manager to define and operate a lean, risk-based cyber security capability for the business unit. You will be the main security interface with the Central CISO Office, balancing security with business enablement and compliant delivery.

The role covers cloud, ERP, APIs, data platforms and supplier environments, partnering with architecture and IT teams to embed secure-by-design principles. 7+ years of relevant experience is expected.

Qualificações

  • 7+ years in cyber security, information security, or security operations.
  • Experience across cloud and SaaS security governance.
  • Ability to translate regulatory requirements into pragmatic controls.
  • Proven stakeholder management in multinational environments.

Responsabilidades

  • Define and implement a lean, risk-based cyber security strategy aligned with business priorities and Central CISO standards.
  • Translate group policies into practical business-unit controls and processes.
  • Establish security governance rhythms for risk reviews and leadership reporting.
  • Own local cyber security execution in the first line of defence.
  • Coordinate security activities across commercial, engineering, back-office, product and data domains.
  • Drive IAM improvements including SSO, RBAC and access reviews.
  • Plan and execute cyber risk assessments for applications, platforms and vendors.
  • Coordinate vulnerability management, penetration testing and incident response.
  • Promote secure-by-design principles with architecture teams.

Conhecimentos

Cyber security leadership
Risk management
ISO 27001 / NIST CSF
GDPR compliance
API security
IAM / RBAC
Vulnerability management
Incident response
Stakeholder management

Formação académica

Degree in Computer Science or related field

Ferramentas

Azure
AWS

Descrição da oferta de emprego

Senior Cyber Security Manager (m./f./div.)
  • Full-time

The Keenfinity Group delivers professional communication and security solutions that connect and protect people and assets. Following its carve-out from the Bosch Group in mid-2025, it operates as independent company within the portfolio of European investment firm Triton. The Group’s four Businesses include Audio delivering professional communication products of the globally renowned brands Bosch, Electro-Voice, Dynacord, RTS and Telex, IQSIGHT Video Systems, Radionix Intrusion & Access, and KEENFINITY Electronics Manufacturing Services (EMS). In fiscal year 2025, the group generated revenues of over €1 billion and employed approximately 4,000 people across more than 40 countries.

The Senior Cyber Security Manager is responsible for defining, implementing and operating a lean, pragmatic and risk-based cyber security capability for the business unit. The role acts as the primary security interface between the business unit and the Central CISO Office, while ensuring that local applications, platforms, data, vendors and technology initiatives meet appropriate security, privacy and compliance expectations.

The role covers the wider IT landscape such as business applications, APIs, ERP, MDM, engineering tooling, back-office systems, cloud and SaaS services, data platforms, supplier environments and business-critical integrations. The Senior Cyber Security Manager balances security rigour with business enablement, ensuring that cyber controls support transformation rather than slow it down unnecessarily.

Key Responsibilities
Cyber Security Strategy & Governance
  • Define and implement a lean, risk-based cyber security strategy aligned with business priorities and Central CISO standards.
  • Translate group-level information security policies into practical business-unit controls, processes and decision criteria.
  • Establish security governance rhythms for risk reviews, control follow-up, exception management and leadership reporting.
  • Maintain a transparent view of the business-unit cyber risk posture, priorities, exceptions and remediation progress.
  • Ensure that security becomes part of the normal IT operating model rather than a separate after-the-fact review activity.
Federated CISO / First Line of Defence Ownership
  • Act as the primary security interface between the business unit and the Central CISO Office.
  • Own local cyber security execution in the first line of defence while escalating material risks to the appropriate governance forums.
  • Support the business in making risk-informed decisions, including risk acceptance, mitigation prioritisation and control design.
  • Coordinate business-unit security activities across commercial, engineering, back-office, product, operations and data domains.
  • Ensure security requirements are practical, business-relevant and aligned with risk appetite.
  • Collaborate closely with Enterprise Architecture, Solution Architecture and Integration teams to embed secure-by-design principles.
  • Define security requirements for API-first solutions, customer portals, headless architectures, iPaaS integrations and backend systems.
  • Ensure secure patterns for authentication, authorization, token-based security, OAuth2/OIDC, API gateways and data exchange.
  • Review security implications of cloud, SaaS, ERP, MDM, CRM, engineering and back-office platform decisions.
  • Help reduce point-to-point security complexity by encouraging reusable, documented and governed security patterns.
Identity & Access Management
  • Own and mature the business-unit identity and access management approach, including SSO, RBAC, least privilege and access reviews.
  • Drive improvements in privileged access, role design, joiner-mover-leaver controls and segregation of duties where relevant.
  • Partner with application owners and IT operations to ensure access rights remain appropriate and auditable.
  • Support cloud and SaaS access governance across business-critical platforms.
  • Promote consistent identity standards across new implementations and transformation initiatives.
Risk, Compliance & Control Management
  • Plan and execute cyber risk assessments for applications, platforms, integrations, vendors and change initiatives.
  • Translate ISO 27001, NIST CSF, ISO 27005, NIS2, GDPR and EU AI Act expectations into pragmatic controls and actions.
  • Support ISO 27001 readiness and evidence collection, including control ownership, documentation and remediation tracking.
  • Define and maintain data protection and information classification expectations in cooperation with legal, privacy and data stakeholders.
  • Prepare clear leadership reporting on risks, control gaps, remediation progress, compliance status and security KPIs/KRIs.
Operational Security & Incident Management
  • Coordinate vulnerability management, penetration testing, remediation tracking and security testing follow-up.
  • Act as escalation point for security incidents, suspected breaches and high-risk operational events.
  • Support monitoring, alerting, incident response and post-incident lessons learned with central and external security teams.
  • Ensure incidents and near misses are converted into practical control improvements and risk reduction actions.
  • Contribute to business continuity and resilience planning for critical applications and technology services.
  • Define cyber security requirements for external implementation partners, SaaS vendors, managed service providers and suppliers.
  • Support security and privacy reviews for contracts, Data Processing Agreements, architecture decisions and vendor onboarding.
  • Assess vendor security posture and ensure appropriate remediation or compensating controls where needed.
  • Embed security requirements into sourcing, implementation and operational handover processes.
  • Monitor key supplier-related risks and escalation material exposures through governance.
Security Awareness, Enablement & Change
  • Act as a trusted security partner to business and IT stakeholders.
  • Translate technical and regulatory security requirements into clear, business-relevant guidance.
  • Promote secure behaviours through targeted awareness, practical guidance and role-based training.
  • Support project teams with early security input to avoid late-stage rework.
  • Balance security controls with speed, scalability, usability and business adoption.
Strategic Value Realisation
  • Convert the cyber security elements of the IT strategy into a concrete execution roadmap.
  • Ensure cyber security contributes to risk reduction, business continuity, regulatory readiness and buyer-readiness.
  • Support application rationalisation, vendor optimisation and cloud/SaaS governance through security input.
  • Track and report measurable improvement in cyber maturity, control effectiveness and remediation progress.
  • Help move the organisation from ad hoc security support to permanent security capability ownership.

Education: Degree in Computer Science, Information Technology, Engineering, or a comparable qualification.

Experience
  • 7+ years of experience in cyber security, information security, IT risk, security architecture or security operations roles.
  • Experience operating in modern cloud and SaaS environments, including security governance for third-party platforms and integrations.
  • Experience translating security policies, frameworks and regulatory requirements into pragmatic controls.
  • Experience working with architects, business stakeholders, engineering teams, IT operations and external vendors.
  • Experience with risk assessments, vulnerability management, penetration testing coordination and incident response processes.
  • Experience in international, multi-site or matrix organisations.
  • Strong understanding of identity and access management, secure integration patterns and data protection expectations.
  • Experience in a federated CISO, BISO, security champion or first-line security ownership model.
  • Experience with ISO 27001 implementation, audit readiness, control evidence and remediation tracking.
  • Experience with NIS2, GDPR and practical security governance in European operating environments.
  • Experience with cloud security in Azure and/or AWS, SaaS security governance and enterprise platform security models.
  • Experience with API security, OAuth2/OIDC, API gateways, iPaaS and secure integration layers.
  • Experience contributing to technology transformation programmes such as CRM replacement, HubSpot implementation, ERP integration, cloud migration, application rationalisation, post-M&A integration or carve-out readiness.
  • Experience working in manufacturing, security technology, industrial technology, engineering, product or connected-device environments.
Competency Profile
  • Pragmatic, risk-based judgement with the ability to balance security rigour and business enablement.
  • Strong stakeholder management and ability to explain security risks in business language.
  • Structured analytical thinking and ability to simplify complex technical, regulatory and risk topics.
  • Confidence to challenge solution designs, vendor statements and business assumptions constructively.
  • Ability to operate in a resource-conscious environment with competing priorities.
  • Clear communication style suitable for business leaders, IT teams, vendors, auditors and the CISO Office.
  • Ownership mentality and ability to move topics from assessment to execution.
  • Change management capability and ability to embed security into daily delivery and operating processes.

Languages: Excellent written and spoken English. German or Portuguese is a plus.

Keenfinity benefits includes:

Flexible work conditions (2-3 days of HO)

Health insurance and medical office on site (nutrition, psychology, physiotherapy and general clinic)

Sports and health related activities (gym)

Training opportunities (i.e., technical training, foreign languages training) & certifications

Opportunities for career progression and continuous professional development

Exchange with colleagues around the world

Access to great discounts in partnerships and products

All our positions are open to people with disability

At Keenfinity we don’t just build innovative solutions — we shape a smarter, more connected world through technology.

We value different backgrounds, ideas, and experiences and we’re committed to growing, learning, and celebrating success as one team. Everyone is welcome here — we foster an environment where everyone is respected, valued, and encouraged to be their authentic self.

Keenfinity is an equal opportunity employer, offering equal opportunities for all. We welcome applications from people with disabilities and can offer support, if needed. When everyone has a chance to contribute, we all do better.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Chief Information Security Officer (Ciso) (M/F/Div.)
Chief Information Security Officer (Ciso) (M/F/Div.)

Bosch Group • Viseu

Presencial
EUR 120 000 - 180 000
Flexible work conditions
Hybrid work system
Health insurance and on-site medical
+2
Aviation Security Officer
Aviation Security Officer

Bosch Group • Viseu

Híbrido
EUR 120 000 - 180 000
Flexible work conditions
Hybrid work system
Health insurance
+2
Chief Information Security Officer (CISO) (m/f/div.)
Chief Information Security Officer (CISO) (m/f/div.)

Bosch Group • Portugal

Presencial
EUR 120 000 - 180 000
Flexible work conditions
Hybrid work system
Health insurance and medical on site
+2
Aviation Security Officer
Aviation Security Officer

Bosch Group • Lisboa

Híbrido
EUR 110 000 - 150 000
Flexible work conditions
Hybrid work system
Health insurance and medical on site
+2
Senior CISO for M&A & Divestiture Security
Senior CISO for M&A & Divestiture Security

Bosch Group • Portugal

Presencial
EUR 120 000 - 180 000
Commercial IT Product Owner (m./f./div.)
Commercial IT Product Owner (m./f./div.)

Keenfinity Group • Aveiro

Híbrido
EUR 60 000 - 90 000
Health insurance
Flexible work conditions (2-3 days at/
Training opportunities
+2
Content Management System Application Owner (m./f./div.)
Content Management System Application Owner (m./f./div.)

Keenfinity Group • Ovar

Híbrido
EUR 34 000 - 52 000
Flexible work conditions (2 days HO)
Health insurance and on-site medical(
Canteen
+7
Project Manager (m./f./div.)
Project Manager (m./f./div.)

Keenfinity Group • Portugal

Híbrido
EUR 55 000 - 75 000
Health insurance
Flexible work conditions
On-site medical office
+6
Senior Mechanical Process Engineer (f/m/div.)
Senior Mechanical Process Engineer (f/m/div.)

Keenfinity Group • São João

Presencial
EUR 29 000 - 32 000
Flexible work conditions
Exchange with colleagues around the世界
Health insurance and on-site medical
+7
Project Manager (m./f./div.)
Project Manager (m./f./div.)

Keenfinity • Ovar

Híbrido
EUR 45 000 - 65 000
Health insurance
Flexible work conditions
Training opportunities
+2