04 ago
|
Jobtailor
|
Sant Joan Despí
04 ago
Jobtailor
Sant Joan Despí
ph3Responsibilities /h3 ul liOwn and continuously improve our ISMS, policies, and security governance lifecycle. /li liAct as a trusted advisor to engineering, product, compliance, and customer‑facing teams. /li liLead security risk assessments, maintain the risk register, and drive quarterly risk cycles. /li liEnsure operational compliance with ISO 27001:2022, GSMA SAS, NIS-2 and customer security requirements and support hands‑on with configuration tasks. /li liCoordinate external and internal audits and assessments, ensuring evidence readiness and smooth execution. /li liLead vendor risk programs that strengthen our supply chain resilience. /li liReview product and architectural changes for governance alignment and secure design. /li liCollaborate with the Security Architect to connect governance with DevSecOps and cloud practices. /li liOwn Azure security posture, govern Microsoft Defender for Cloud findings, Entra ID Conditional Access policies, Privileged Identity Management (JIT access), and quarterly access reviews. /li liSupport on cross‑platform governance tasks, policy alignment, and shared risk register entries covering AWS and Azure workloads. /li liEnforce Zero Trust controls across cloud environments: continuous verification, least‑privilege access, and RBAC/ABAC enforcement. /li liGovern IaC and CI/CD pipeline security gates: review IaC templates for secrets management compliance, approve pipeline security controls,
and validate rollback procedures. /li liProduce structured assurance reporting for management: metrics tied to the risk register, control effectiveness, and remediation tracking for findings from Defender for Cloud and AWS Security Hub. /li /ul h3Requirements /h3 ul liAt least 5 years in information security, risk, audit, or compliance, with a minimum of 3 years in a similar role (security management, cloud security governance, or ISMS ownership), ideally in regulated environments (telecommunications, banking, payments, SaaS). /li liStrong understanding of ISO 27001, risk methodologies, and modern security frameworks. /li liSolid knowledge of security controls (IAM, third‑party risk, secure SDLC, cloud). /li liAbility to challenge and support engineering teams constructively. /li liSolid knowledge of Azure and AWS security controls. /li liPractical understanding of Zero Trust architecture principles and shared responsibility models across IaaS, PaaS, and SaaS. /li liFamiliarity with IaC security practices: secrets management, pipeline approval workflows, and dependency vulnerability handling. /li liExperience producing security assurance metrics and governance reports for senior stakeholders. /li liExcellent analytical, documentation, and problem‑solving skills. /li liFluent English; German or Spanish is a plus. /li /ul /p #J-18808-Ljbffr
📌 Security Manager – Azure (Sant Joan Despí)
🏢 Jobtailor
📍 Sant Joan Despí