Skip to content

Open nowPosted 24 hours ago

HQ - CISO - EMEA Remote

Job&Talent28 open roles

Where
Madrid HQ, ES
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowHQ - CISO - EMEA RemoteJob&Talent · Madrid HQ, ES
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Job&Talent's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Job&Talent postings stay open a median of 3 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 33.9%30 days
This job: posted 24 hours ago

Job&Talent median: 3 days open

The posting

Join us to shape the future of work: your next adventure awaits!

About the Role

Job&Talent is looking for a Chief Information Security Officer (CISO) to own and lead the company's global information security strategy, organization, and execution.

Reporting directly to the CTO, the CISO will be responsible for protecting Job&Talent's technology, infrastructure, products, corporate environment, and data while enabling the company to move quickly and safely.

Job&Talent operates a large-scale technology product supporting critical workforce processes, including hiring, worker management, clocking, payroll-related workflows, and increasingly AI-powered capabilities. This creates a broad security surface spanning cloud infrastructure, SaaS, endpoints, identity, product security, sensitive personal data, AI systems, third-party vendors, and multiple regulatory environments.

The CISO will therefore need to combine deep technical security expertise, strong operational execution, risk management, GRC understanding, and executive leadership.

We are looking for someone who can understand how systems actually work, identify the risks that matter, prioritize them pragmatically, and build the technology, processes, teams, and culture required to address them.

What you'll own

  • Own and continuously evolve Job&Talent's global information security strategy and roadmap, ensuring security investment is aligned with the company's actual risk profile and business priorities.
  • Translate technical security risks into clear business risks and provide the CTO and executive team with an accurate view of the company's security posture.
  • Establish measurable security objectives, KPIs, KRIs and risk-acceptance processes.
  • Build a security organization capable of supporting a fast-moving global technology company without creating unnecessary friction for Engineering or the business.
  • Own the security lifecycle across Job&Talent's products and engineering organization, including threat modelling, architecture reviews, secure development, application and supply-chain security, vulnerability management and security testing.
  • Own security architecture across cloud infrastructure and platform environments, ensuring security is embedded into architecture and technology decisions from the beginning.
  • Partner closely with Engineering, Platform and SRE to integrate security into development and infrastructure processes.
  • Provide appropriate security governance for AI-powered products, agents, and LLM integrations.
  • Own security across Job&Talent's corporate technology environment, including identity and access management, privileged access, endpoint and SaaS security, and corporate network security.
  • Drive the organization toward a Zero Trust model where access decisions consider identity, device posture, risk, and context.
  • Own the technical controls required to protect sensitive data throughout its lifecycle, including data access, encryption, monitoring and data-loss prevention.
  • Partner closely with Legal, Privacy and the DPO on applicable privacy requirements while maintaining a clear distinction between privacy governance and technical security ownership.
  • Build and continuously improve Job&Talent's ability to detect, investigate, contain and recover from security incidents.
  • Own security monitoring, detection engineering, incident response and threat intelligence capabilities.
  • Ensure significant security incidents are handled with strong operational discipline and effective coordination across technical, business and executive stakeholders.
  • Drive continuous improvement through incident reviews, remediation and lessons learned.
  • Maintain and evolve Job&Talent's security management framework, risk management and compliance programs, including ISO 27001, SOC 2 Type II, GDPR and applicable customer and regulatory security requirements.
  • Maintain clear ownership, remediation and risk acceptance while automating compliance and control monitoring wherever practical.
  • Own security risk management across Job&Talent's technology and vendor ecosystem, ensuring third-party risk is assessed based on actual exposure and impact.
  • Establish the technical security framework for AI across Job&Talent products and internal use.
  • Address emerging risks related to data access, AI agents, authentication and authorization, data exfiltration, model and provider risk, and shadow AI.
  • Partner with Legal and Privacy on regulatory requirements, including the EU AI Act, while maintaining ownership of the required technical security controls.
  • Build and develop a strong security organization with clear ownership and accountability.
  • Build a strong security culture across Job&Talent, embedding security into how Engineering, Product, IT, and business teams make decisions.
  • Develop targeted security education and effective security champion programs where they provide value.

Experience Required:

  • 10+ years of experience in information security, with significant experience within global software technology product companies.
  • 5+ years in significant security leadership roles within technology, SaaS, marketplace, fintech, HR-tech or similarly data-intensive product environments.
  • 2+ years as a CISO, VP Security or equivalent senior security leader within a global SaaS or software technology product company.
  • Experience leading security across both product technology and corporate IT environments.
  • Strong track record across Product and Application Security, cloud security and modern security architecture.
  • Demonstrated experience building or operating mature Security Operations and Incident Response capabilities.
  • Deep understanding of modern identity architecture, IAM, SSO, device trust and Zero Trust principles.
  • Experience protecting significant volumes of personal or otherwise sensitive data and managing SaaS and third-party security risks.
  • Experience with ISO 27001, SOC 2, GDPR and enterprise customer security requirements.
  • Familiarity with AI security and emerging risks associated with LLM-based applications and AI agents.
  • Experience partnering with Engineering, Platform, SRE, IT, Legal and Privacy teams, as well as executive leadership.

Skills & Competencies:

  • Technical Credibility: Ability to engage deeply with architecture, infrastructure, identity, applications, cloud security and incidents, independently assessing technical risks.
  • Risk-Driven Thinking: Ability to distinguish theoretical vulnerabilities and compliance gaps from risks that could materially impact the business, and prioritize security efforts accordingly.
  • Pragmatic Approach: Ability to balance security requirements with business priorities, enabling Engineering and the wider organization to operate securely without unnecessary friction.
  • Data-Driven Leadership: Ability to quantify security posture, establish meaningful metrics and demonstrate whether risk is increasing or decreasing.
  • Hands-On Mindset: Ability to move between executive-level discussions and detailed technical investigations when required.
  • Engineering Collaboration: Ability to establish strong partnerships with Engineering teams, collaborate on technical decisions and integrate security into engineering practices.
  • Incident Leadership: Ability to make clear decisions under uncertainty and coordinate technical, business, privacy and legal stakeholders during security incidents.
  • Organizational Leadership: Ability to build and develop effective security capabilities, determining what should be owned internally, automated, outsourced or supported by specialist expertise.

#LI-OK1

About us

Job&Talent is a world-leading, AI-powered workforce management platform for frontline industries. We help companies boost productivity and efficiency at scale, while giving workers the tools they need to thrive. Our mission is simple: to empower the people who make the world go round.

Built on deep industry expertise, cutting-edge technology, and smart AI agents, our end-to-end platform covers the entire workforce lifecycle — from recruitment and planning to time and attendance, performance, cost management, and communication.

It delivers measurable improvements in the areas that matter most: fulfilment, attendance, retention, and workforce quality. Our platform strength is rooted in unique experience: placing millions of workers over the years and serving thousands of blue-chip clients across delivery, logistics, manufacturing, e-commerce, retail, and hospitality.

Headquartered in Madrid, the company operates in 10 countries across Europe, the US, and Latin America and is backed by leading investors including Atomico, Goldman Sachs, Kinnevik, BlackRock, and SoftBank.

Join our community and make an impact

Innovation, high standards, and analytical thinking are in our DNA. Everyone has a voice here, and that voice matters. It’s how we stay sharp, move fast, and make decisions that keep us ahead of the curve.

You’ll take full ownership of your work, collaborate across borders, and grow by doing. Around here, you’ll hear a lot about 10x experiences, human-centered design, and the power of AI. But what truly sets us apart is our people: Our diverse team brings unique perspectives, deep commitment and real-world experience to the table.

We champion empathy, honesty, and inclusion. Because when people can be their authentic selves, incredible things happen—for our workers, our clients, and for each other.

And we reward that impact—with competitive pay, meaningful benefits, and the opportunity to shape what work looks like for millions around the globe.

If you're ready to make a real impact at scale, you're in the right place.

Proud to champion equality

At Job&Talent we value diversity and we're an Equal Opportunity Employer. We welcome applications from all suitably qualified people regardless of national origin, race, disability, religious beliefs or sexual orientation. Come join us. We look forward to your application.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Job&Talent's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Job&Talent's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Job&Talent's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.