21 ago
|
Sovendus
|
Barcelona
21 ago
Sovendus
Barcelona
STRONG NETWORK. STRONG TEAM.
Sovendus connects Europe’s leading brands with customers who buy.
We’ve been doing it for 17 years, with one clear focus: turning general checkout traffic into a source of new customers and incremental revenue.
More than 3,000 brands across Europe are already growing with Sovendus through long-term partnerships and real European transaction data. That’s how growth becomes predictable. And scalable. ?
Now, we're looking for an Information Security Manager based in Spain who wants to take ownership of security initiatives, strengthen trust with our partners, and help shape the future of security and compliance at Sovendus. ?
As an Information Security Manager, you will:
- Maintain and enhance our security documentation and Information Security Management System (ISMS), helping build a strong trust framework for partners and customers.
- Manage partner security assessments and questionnaires, creating reusable documentation and standardized responses.
- Drive the vulnerability management lifecycle, coordinating visibility, remediation activities, and reporting across teams.
- Review our AWS environment, identify security improvement opportunities, and provide guidance on cloud security best practices, including IAM, logging, network security, and encryption.
- Act as the go-to security contact for developers and Corporate IT, supporting topics such as secure design, threat modeling, endpoint security, identity management, and SaaS security.
- Coordinate penetration tests with our external security partners, support GDPR-related initiatives with Legal, and contribute to future ISO 27001 and/or SOC 2 certification readiness.
Your profile:
- You have 5+ years of experience in Information Security, combining hands-on technical work with governance and compliance responsibilities.
- You bring solid knowledge of AWS security, including IAM, network security, logging, and encryption.
- You have experience managing vulnerability management processes and related security tooling.
- You are familiar with ISMS frameworks and security standards, ideally ISO 27001 and/or SOC 2.
- You have a good understanding of GDPR and data protection concepts, with experience creating documentation and partner-facing security responses.
- You are structured, self-organized, and comfortable driving initiatives across teams in an international environment, with business-fluent English.
It's a plus if you have:
- Certifications such as CISSP, CISM, ISO 27001 Lead Implementer, or AWS Security Specialty.
- Experience with security questionnaires, audits, or partner assessments
- A background in Software Development, DevOps, Platform Engineering, or Corporate IT security
- Familiarity with identity, access, and endpoint security solutions
- Experience supporting ISO 27001 or SOC 2 initiatives
- German language skills
? Why Sovendus?
Because trust matters.
You'll be part of an international, fast-growing company that values ownership, collaboration, and continuous improvement. Your work will play a key role in strengthening our security posture, building trust with customers and partners, and supporting the sustainable growth of our business across Europe. ?
Please note: This is a remote role, but we are only considering candidates who are already based in Spain and have valid work authorization
📌 Information Security Manager (Barcelona)
🏢 Sovendus
📍 Barcelona