Senior Director, Deputy Chief Information Security Officer

Madrid, Spain·Security·Full-time·Added 6 days ago

What they offer

  • Full-time hours

    Per the ad.

What they ask for

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Work in English

    English is required, per the ad.

  • Work on-site in Madrid

    No relocation package mentioned.

  • Have senior-level experience

    Senior-level role.

About the job


Are you ready to unlock your potential?

At Straumann Group we're on an exciting journey of growth, innovation, and impact - driven by our mission to improve oral health and transform millions of lives worldwide. United by purpose, we bring our best selves to work every day, embracing a high-performance, player-learner culture that inspires collaboration, curiosity, and ambition. Here, you'll have the opportunity to take charge of your own career, harnessing your skills, passion, and enthusiasm for learning to continually grow and progress. Together, we're not just shaping brighter smiles, we're unlocking the potential of people everywhere, including our own.

Introduction

As Senior Director, Deputy Chief Information Security Officer, you will be the operational partner to the Chief Information Security Officer and act on their behalf during periods of delegated absence.

This role has a clear focus: strengthening application and product security across digital products, platforms and connected medical devices, while supporting the execution of Straumann Group's wider cybersecurity strategy.

Your Role

  • You will lead and mature the application and product security function, embedding secure software development practices across architecture, design, development, testing, release and post-market activities.
  • You will define and govern secure software development lifecycle requirements, security architecture reviews, threat modelling, application security testing, vulnerability remediation, software supply-chain security, SBOMs and third-party component governance.
  • You will oversee product vulnerability management, coordinated vulnerability disclosure and post-market cybersecurity monitoring, ensuring product-security requirements become practical engineering controls.
  • Working closely with Product Development, Engineering, Quality, Regulatory Affairs, Enterprise Architecture, Digital Trust & Assurance, Security Operations, Legal, Privacy and strategic technology partners, you will help ensure security risks, exceptions and remediation decisions are clearly documented and well governed.
  • You will also support the CISO in translating cybersecurity strategy into measurable execution, lead selected cross-functional security priorities, resolve issues across product and technology teams, and represent the CISO in internal or external forums when delegated.

Your Profile

  • You bring significant leadership experience in cybersecurity, application security, product security or software security.
  • You have built or led application and product security capabilities in a complex enterprise environment.
  • You understand secure software development, DevSecOps, modern application architectures, cloud-native applications, APIs, identity, CI/CD pipelines and software supply-chain security.
  • You have experience with threat modelling, security architecture, penetration testing and vulnerability management.
  • You are confident engaging senior stakeholders, auditors and regulators, and can translate cybersecurity and regulatory requirements into practical, risk-based controls.
  • Experience in regulated environments is important; medical devices, healthcare, life sciences or manufacturing experience would be an advantage.
  • Knowledge of medical-device cybersecurity and secure product lifecycle requirements is strongly preferred.
  • Certifications such as CISSP, CISM, CSSLP, CCSP or equivalent are welcome, but not mandatory.

What Makes You a Great Fit

  • You combine technical credibility with senior leadership judgement. You can challenge constructively, influence across organisational boundaries and focus teams on material product and software-security risks.
  • You are effective at turning complex security and regulatory topics into clear decisions, practical actions and measurable outcomes.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or disability.

Employment Type: Full Time

Alternative Locations: Spain : Madrid

Travel Percentage: 0 - 20%

Requisition ID: 21909

How they hire

2 steps1 interviewa task to do
  1. Application

  2. Review · With a Talent Acquisition Advisor

  3. Interview

    Structured, competency-based interview covering prior projects, behavioural and situational questions, skills and achievements; time, format and interviewer are confirmed beforehand.

  4. Assessment

    Not every role

    Used for some roles, typically intern/graduate, sales, operations, management and leadership.

  5. Offer · With a Talent Acquisition Advisor

  • Interview format (video, phone or onsite) and who you will meet are confirmed in advance.
  • Review timing varies with application volume; some roles are reviewed only after the closing date.
WhatsApp