Head of Information Security

Head of Information Security

Infront

Madrid, Spain

About the Role

We’re seeking an experienced Head of Information Security to strengthen and improve the company’s security posture; this is a hands-on leadership role suited to someone who enjoys rolling up their sleeves, solving problems, and directly implementing improvements, rather than focusing primarily on high-level strategy. You will act as a pragmatic security leader who actively contributes to day-to-day security operations and initiatives, while also line managing 2–3 Information Security Engineers, providing guidance, support, and technical direction to drive practical security outcomes across the organisation.

Responsibilities

  • Lead a major ISO 27001 compliance programme across the organisation;
  • Monitor and continuously improve the organisation’s security posture;
  • Develop, maintain, and update information security policies in line with industry standards, ensuring company-wide compliance;
  • Partner closely with engineering teams to embed security into software development processes;
  • Ensure compliance with relevant financial services regulations and standards;
  • Manage security audits and penetration testing activities;
  • Implement staff training initiatives to increase security awareness (e.g. phishing, access control);
  • Hire team members and select external vendors as appropriate;
  • Operate within budget constraints, leveraging open-source solutions where beneficial;
  • Manage security incidents effectively, with the ability to respond quickly under pressure;
  • Provide regular reporting on security status and KPIs to senior management.

Who you are

Requirements

  • 6+ years of professional experience in cybersecurity, with at least 2 years of team leadership experience;
  • Technical background in computer science, software development, or a related field;
  • Proven track record of improving cybersecurity in companies with 100–1000 employees;
  • Hands-on experience implementing ISO 27001;
  • Expertise in risk management, including threat analysis and risk acceptance vs. mitigation;
  • Familiarity with security controls in at least one major cloud platform (AWS, Azure, or GCP);
  • Strong analytical and problem-solving skills, including root cause analysis and sound build-vs-buy decision-making;
  • Good understanding of GDPR regulations;
  • Solid project and change management skills, with a track record of delivering initiatives to completion;
  • Strong leadership skills, including for teams you do not directly manage;
  • Strong communication, presentation, and stakeholder management skills, with the ability to influence without formal authority;
  • Fluent in written and spoken English.

Nice to have, experience with

  • DORA regulation;
  • NIST Cyber security framework;
  • Cyber Resiliance Act.

Don't forget to mention EuroTechJobs when applying.

Share this Job

More Job Searches

Spain      Cyber Security      Developer      Hybrid      Infront     

EuroTechJobs Logo

© EuroJobsites 2026