OOCC Madrid Information Security Governance & Risk Sr. Manager

OOCC Madrid Information Security Governance & Risk Sr. Manager

Palladium Hotel Group
Palladium Hotel Group
Madrid, SpainCompetitiveOn-siteAdded 5 days agoSenior · 8+ yearsPermanent

Need a visa? No sponsorship mentioned, and this kind of work is rarely sponsored in Spain. See which routes exist.

About the role

At Palladium Hotel Group we are looking to add, within the corporate area and for our Madrid offices, a strategic profile with a global vision for the position of Information Security Governance & Risk Sr. Manager.

If you are passionate about leading governance, risk, and compliance strategies in cybersecurity within an international and constantly evolving environment, and you want to drive a solid security culture aligned with the business, this position could be your next big challenge.

Your mission will be to define, lead, and maintain the global framework for cybersecurity governance, risk, compliance, and privacy, ensuring its correct regional execution and alignment with business objectives and regulatory requirements.

The role acts as a global reference in IS Governance, Risk Management & Privacy matters, providing executive visibility and risk escalation to the IS VP and the corresponding committees.

What you'll do

Cybersecurity Governance

  • Define and maintain the global security governance framework.
  • Establish policies, standards, and procedures.
  • Align cybersecurity with business objectives.
  • Ensure consistency across regions and areas.

Security Risk Management

  • Identify, assess, and prioritize cybersecurity risks.
  • Maintain the risk map and mitigation plans.
  • Evaluate security exceptions.
  • Escalate critical risks to the IS VP and committees.

Compliance and Audit

  • Ensure compliance with frameworks and regulations (ISO, NIST, PCI, ENS, etc.).
  • Prepare and manage internal and external audits.
  • Follow up on findings and action plans.
  • Compliance evidence and reporting.

Third Party Risk Management

  • Supplier risk assessment (IT, OT, SaaS, PMS, integrators).
  • Review of security requirements in contracts.
  • Coordination with Legal.
  • Monitoring of critical third-party risk.

Privacy & Data Protection

  • Global privacy and data protection governance.
  • Coordination with DPO and Legal.
  • Oversight of DPIAs.
  • Management of personal data incidents.
  • Regulatory compliance by region (GDPR and local regulations).

Security Awareness & Culture

  • Definition of security awareness programs.
  • Delivery of training to employees and hotels.
  • Phishing simulations.
  • Definition of clear operational procedures.

What you'll get

  • You will join Palladium Hotel Group, a Spanish company with international presence in the midst of an expansion process, which has been recognized for the sixth consecutive year as a Top Employer in Spain, Italy, Mexico, the Dominican Republic, Brazil, and Jamaica.
  • We offer a competitive salary policy, permanent contract and job stability, as well as training plans so you have opportunities for development and growth within the company both nationally and internationally.
  • You will be part of a dynamic, multicultural team with a winning mindset that includes great professionals from the hospitality sector, and you will stay up to date with the latest trends in your area and the industry.
  • In addition, you will enjoy access to discounts at group hotels and other associated companies through PHG Benefits Club.
  • In our commitment to equal opportunities, we guarantee selection processes based exclusively on talent and professional skills. We actively foster diversity and inclusion. We believe in diverse teams and opportunities for everyone.

How you'll work

permanent

On-site

Profile requirements:

Education / Studies

  • University degree in Engineering, Information Systems, Information Security, Law, or equivalent.

Other Requirements

  • Certifications in governance, risk, or compliance (CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, or others).
  • Training in data protection and privacy (GDPR, DPIA, local regulations).
  • Corporate risk management training will be valued.
  • Training or knowledge in AI governance and regulation (AI Act, ethical frameworks, risk-based approach).
  • Knowledge of the PCI-DSS control framework. Availability for frequent travel, both nationally and internationally.

Experience

  • Senior experience (min. 8 years) in IS Governance & Risk.
  • Experience in cybersecurity risk management and development of risk maps.
  • Experience in internal and external audits.
  • Experience in multi-regional data protection and cybersecurity models and coordination with legal areas.
  • Experience as a cybersecurity trainer. Experience in privacy governance and data protection.
  • Experience using visualization tools, data analysis, dashboards, and reporting (e.g., Power BI).

You'll most likely need Spanish to apply.This job was automatically translated to English, .

Apply Now