15 sep
|
shine
|
Cantabria
Founded by serial entrepreneurs Rico Andersen and Martin Hegelund, Shine is a leading European fintech unicorn on a mission to restore the joy of running a business, by ending wasted time on financial admin. Shine offers a connected solution for invoicing, accounting, payroll, business accounts, payments, and financing, meaning business owners can focus their energy on growing a healthy business, not held back by manual admin. Today we're part of Cegid, a European leader in cloud software for finance and accounting.
We're a multicultural team working from France, Germany, Denmark and the Netherlands, contributing to a wider European network that spans Spain, Portugal and Belgium.
The Information
Security team at Shine We work directly with leadership to integrate resilience into the company's core, navigating the complex intersection of cloud-native architecture, AI innovation, and rigorous regulatory standards like DORA and ISO 27001. By partnering cross-functionally with Engineering and Risk, we aren't just maintaining a perimeter; we are building a scalable, high-visibility security framework that defines the future of digital operational excellence in the fintech space.
Your Role as a Cyber Security Manager (Incident Response) at Shine Shine Bank is looking for an Cyber Security Manager (Incident Response)
to help shape and operate our information security and digital operational resilience framework.
As Cyber Security
Manager, you will own our defensive security technology stack and our incident-readiness capability. Ensure robust DDoS protection across our internet-facing and payment-critical services — selecting and managing mitigation solutions (e.g. Cloudflare, Akamai, AWS Shield) validating that protection holds up to the availability expectations regulators place on a payment institution.
Manage security vendor and MSSP relationships, contribute to the security technology roadmap and budget, and translate threat intelligence into concrete control improvements. Provide the technical evidence and control assurance the Information Security (GRC) function needs for PCI-DSS, DORA, and ACPR-related obligations. Report on resilience metrics and the effectiveness of deployed controls to security leadership.
Job located in Berlin or Madrid office, with possibility of two remote working days per week CrowdStrike, SentinelOne, Microsoft Defender) and other core defensive tooling. Cloudflare, Akamai, AWS Shield/WAF) and an understanding of how to protect high-availability, customer-facing services.
Fluent
English required; German is a strong advantage.
📌 Cyber Security Manager > (Cantabria)
🏢 shine
📍 Cantabria