27 sep
|
Luminary
|
Valencia
Information Security OfficerLuminary is looking for an Information Security Officer to join the team and own our information security function setting priorities, managing risk, and independently verifying controls with direct access to the Board.About the RoleThe Information Security Officer will own the information security function, defining and maintaining the security framework, managing risk, overseeing controls and monitoring, and reporting directly to leadership and the Board, with oversight of external security providers.ResponsibilitiesGovernance Risk- Build and maintain the security framework, risk register, and roadmap- Report risks to the BoardControls Access- Set security requirements- Verify controls- Run recurring access reviews (MFA, PAM, logging, monitoring)Monitoring Incident Response- Run security monitoring (incl. MSSPs)- Maintain incident response runbooks- Lead investigationsVendor Third-Party- Select, assess, and oversee security vendors and third-party riskTesting Remediation- Commission penetration tests- Prioritize findingsVerify fixesRegulatory AuditSupport DORA, PCI DSS, GDPR, and ISO 27001 complianceOwn audits and regulatory reviews.Required SkillsExperience building or leading an information security function from the ground upStrong grounding in governance, risk, access management, monitoring,
and incident responseTechnical ability to independently assess controls, configurations, and logging coverageExperience managing security vendors and participating in audits or supervisory reviewsStrong communication skills for senior management and Board reportingWorking knowledge of DORA, PCI DSS, GDPR, and ISO/IEC 27001.5+ years in information security, including 3+ years in a regulated financial organisation (EMI, payment institution, bank, or payment system).Nice to haveExperience with MSSPs and within an EMI, PSP, FinTech, or neobank environmentExperience implementing DORA, supporting PCI DSS assessments, or preparing ISO 27001 evidenceComfortable owning security solo in a smaller organisationCISM, CISSP, CCSP, CISA, or ISO/IEC 27001 Lead Implementer/Auditor a plus.What you can expect from usA team that actually has your back. Close-knit, talented, low-ego no bureaucracy, just people who care about doing great work togetherReal ownership from day one. In a fast-moving startup, your decisions shape the security function not inherit itAn office worth showing up for. Right in the heart of Valencia sunshine, great coffee, and a team that genuinely enjoys being thereRelocation? We can make it happen and well support it fully. ...But tssshhh, lets keep that between us. MSSP, PCI DSS, Dora
📌 Information Security Officer, Valencia
🏢 Luminary
📍 Valencia