12 ago
|
Liebherr Group
|
Madrid
12 ago
Liebherr Group
Madrid
Overview Responsible for the delivery of the governance product and services: governance service: design, implementation and continuous improvement of the global Information Security Framework (ISF), aligning it with the evolving business needs, regulatory environment, industry standards and customer requirements. Support delivery of the GRC platform service and customer security assurance service. The working location for this position will be in Madrid city, where we operate a hybrid model, requiring at least 40% of the working time on-site.
Responsibilities Information Security Framework (ISF) Management: Design, implement, and maintain the ISF: policies, standards, procedures, and control baselines, aligned to business needs, regulatory obligations (e.G. NIS2, GDPR), industry standards (e.G. NIST CSF, ISO 27001), and customer contractual requirements
Regulatory Integration & Control Framework Alignment: Maintain inventory and traceability of external obligations (e.G. NIS2, GDPR, ISO/IEC 27001, IEC 62443) and customer requirements, integrating these into the ISF components (policies, controls)
Governance Operations & Executive Engagement: Oversee ISF governance processes, including stakeholder coordination, approval workflows, and documentation.
Collaborate and support the GRC platform service owner to deliver technology required to enable digital implementation of the information security framework.
Collaborate and support the Customer Security Assurance Service owner by delivering governance which supports the business to comply with customer security requirements.
Governance Metrics & Reporting: Design key risk and performance indicators, dashboards and report on the governance product and services relevant for management at the Liebherr group, divisions and companies
Qualifications Bachelor’s/Master’s in Cybersecurity, Computer Science, or related field
5+ years of working experience in integral organizations including Governance, GRC technology and customer security assurance services delivery
Following certificates are preferred: CISSP, CRISC, CISM, GSLC
Excellent written and verbal communication skills in English, German is a plus
Proven expertise in designing and maintaining information security governance frameworks using industry standards e.G. NIST CSF, ISO/IEC 27001, IEC 62443 and requirements in security regulations e.G. NIS2, GDPR, Defense contracting
Ability to lead multi-stakeholder governance processes across global business units and ensure documentation is structured, endorsed, and maintained
Experience in applying agile principles (e.G. iterative planning, continuous improvement, stakeholder collaboration) to the delivery and evolution of governance services, frameworks, or organizational processes
Experience in owning and evolving enterprise GRC platforms to support compliance, risk, and governance services
Strategic thinking combined with a pragmatic execution mindset, especially when aligning governance with operational realities
Highly desirable: experience in product ownership and service delivery using SAFe (Scaled Agile Framework) or similar agile methodologies
Benefits Competitive compensation and benefits package that recognizes your expertise
Flexible and hybrid working model
Creative freedom and responsibility to shape processes and solutions in our global transformation
Continuous learning and development with tailored training and certification opportunities
Meal vouchers
Life and accident insurance
Option to include a premium private health insurance package as part of the flexible remuneration
A safe, stable and international workplace within a trusted family business that invests in people
Location Liebherr IT Shared Service Centre Ibérica, S.L., Madrid, Spain (ES)
#J-18808-Ljbffr
📌 Information Security Governance Product Owner (M/F/D) (Madrid)
🏢 Liebherr Group
📍 Madrid