17 sep
|
Luminary Bank
|
España
17 sep
Luminary Bank
España
Luminary is looking for an Information Security Officer to join the team and own our information security function — setting priorities, managing risk, and independently verifying controls — with direct access to the Board.
About the Role The Information Security Officer will own the information security function, defining and maintaining the security framework, managing risk, overseeing controls and monitoring, and reporting directly to leadership and the Board, with oversight of external security providers.
Responsibilities
Governance & Risk
- Build and maintain the security framework, risk register, and roadmap
- Report risks to the Board
Controls & Access
- Set security requirements
- Verify controls
- Run recurring access reviews (MFA, PAM, logging, monitoring)
Monitoring & Incident Response
- Run security monitoring (incl. MSSPs)
- Maintain incident response runbooks
- Lead investigations
Vendor & Third-Party
- Select, assess, and oversee security vendors and third-party risk
Testing & Remediation
- Commission penetration tests
- Prioritize findings
- Verify fixes
Regulatory & Audit
- Support DORA, PCI DSS, GDPR, and ISO 27001 compliance
- Own audits and regulatory reviews.
Required Skills
- Experience building or leading an information security function from the ground up
- Strong grounding in governance, risk, access management, monitoring, and incident response
- Technical ability to independently assess controls, configurations, and logging coverage
- Experience managing security vendors and participating in audits or supervisory reviews
- Strong communication skills for senior management and Board reporting
- Working knowledge of DORA, PCI DSS, GDPR, and ISO/IEC 27001.
- 5+ years in information security, including 3+ years in a regulated financial organisation (EMI, payment institution, bank, or payment system).
Nice to have
- Experience with MSSPs and within an EMI, PSP, FinTech, or neobank environment
- Experience implementing DORA, supporting PCI DSS assessments, or preparing ISO 27001 evidence
- Comfortable owning security solo in a smaller organisation
- CISM, CISSP, CCSP, CISA, or ISO/IEC 27001 Lead Implementer/Auditor a plus.
What you can expect from us
- A team that actually has your back. Close-knit, talented, low-ego — no bureaucracy, just people who care about doing great work together
- Real ownership from day one. In a fast-moving startup, your decisions shape the security function — not inherit it
- An office worth showing up for. Right in the heart of Valencia — sunshine, great coffee, and a team that genuinely enjoys being there
- Relocation? We can make it happen — and we'll support it fully. …but tssshhh, let's keep that between us. ?
📌 Information Security Officer (España)
🏢 Luminary Bank
📍 España