Description
**Role Purpose**
Ensure comprehensive organizational security across cloud and on\-premise environments, guaranteeing regulatory compliance, data protection, and resilience against threats. This role
reports directly to the CIO and is responsible for defining, implementing, and overseeing the corporate security strategy.
**Areas of Responsibility**
1\. **Governance and Compliance:**
* Define the corporate security policy and maintain alignment with ISO 27001, ENS (High Level), NIS2, DORA, and GDPR.
* Lead internal and external audits, manage evidence and remediation plans.
* Establish a risk and control management framework (Risk Assessment, Risk Treatment).
**2\.** **Architecture and Cloud Security:**
* Design and validate controls in Azure environments based on HUB\-Spoke architecture.
* Oversee security for corporate AKS clusters (PRE and PRO) and multi\-tenant environments.
* Define the security strategy for Azure AI Foundry and advanced services.
* Implement Zero Trust policies and network segmentation.
**3\.** **Protection and Monitoring:**
* Configure and optimize Defender for Cloud, Defender for Endpoints, and Purview.
* Integrate data sources into the SOC (Cyrebro with IBM QRadar) and improve event correlation.
* Define incident response playbooks and coordinate with the SOC.
**4\.** **Security in Development (DevSecOps):**
* Establish standards for SAST, DAST, penetration testing, and vulnerability management.
* Integrate security controls into CI/CD pipelines (Azure DevOps and GitHub).
* Define policies for secret management, identity, and privilege governance.
**5\.** **Assessment and Continuous Improvement:**
* Conduct periodic tests (Red Team, Purple Team).
* Measure security posture KPIs and report findings to the CIO.
* Propose technological enhancements and hardening processes.
**6\.** **Training and Security Culture**
* Promote organization-wide security awareness (campaigns, simulations).
* Design training paths for IT and DevOps teams on security topics.
* Profile and Competencies
**Hard Skills:**
* Experience in cloud security (Azure required).
* In-depth knowledge of Kubernetes, CI/CD, and DevSecOps.
* Desired certifications: AZ\-500, SC\-200, SC\-300, and advanced penetration testing courses.
* Experience with SIEM, EDR, DLP, and Microsoft security tools.
**Soft Skills:**
* Leadership and influence capabilities.
* Clear communication with technical teams and executive leadership.
* Results orientation and crisis management.
**Responsibilities:**
* Define the corporate security policy and keep it updated.
* Ensure compliance with ISO 27001, ENS, NIS2, DORA, and GDPR.
* Design controls in Azure (HUB\-Spoke, RBAC, NSG, Defender).
* Supervise security for corporate AKS clusters and multi\-tenant environments.
* Define the strategy for Azure AI Foundry.
* Configure and optimize Defender for Cloud, Endpoints, and Purview.
* Integrate data sources into the SOC (Cyrebro \+ QRadar) and improve correlation.
* Establish the model for SAST, DAST, and penetration testing in CI/CD.
* Conduct periodic tests (Red Team, Purple Team).
* Measure KPIs and report security posture to the CIO.
* Design training paths for IT and DevOps teams.
* Drive organization-wide awareness campaigns.
* Lead incident and crisis response.
* Evaluate emerging technologies and propose improvements.
* Madrid, Spain
* Indefinite contract
* 6 months to 2 years of experience
* University degree
* 0
* 0 ()
* 0 ()