Chief Information Security Officer

Telefónica·Spain

What they ask for

  • Have the right to work in Spain

    No sponsorship mentioned, and this kind of work is rarely sponsored in Spain.

  • Speak native-level Spanish

    Listed as a requirement in the ad.

  • Work in English

    English is required, per the ad.

  • Work on-site in Spain

    No relocation package mentioned.

  • Have 5+ years of experience

    Senior-level role.

Pulled from the advert automatically — the full ad is what counts.

Added 1 month ago
Read the full advert

About the role

We connect the present. We transform the future.

Have you ever wondered what makes it possible for millions of people to be connected at the same time, from anywhere in the world, without anything failing?

At Telefónica, we make it possible.

We are a global telecommunications and technology company that connects people, businesses, and communities through next-generation networks and advanced digital solutions such as cloud, artificial intelligence, IoT, and cybersecurity.

With over 100 years of history, we work every day to ensure that innovation serves society, driving a digital transformation that is responsible, sustainable, and has real impact.

Here, we don't just design infrastructure—we design the future. We are looking for people who are curious, enthusiastic, and passionate about what they do, who never settle, and who want to build the Telefónica of tomorrow.

If you are passionate about technology that transforms lives, this is your place.

The Digital Security Unit, integrated into the Global Security and Intelligence Directorate, leads the protection of Telefónica's corporate technology ecosystem. It defines and implements the cybersecurity strategy, ensuring regulatory compliance (GDPR, SOX, DORA, among others) and risk control across systems, services, and the supply chain.

It operates transversally across complex technology environments (cloud, hybrid infrastructures, Big Data, AI, IoT, DevOps), promoting security by design and a cybersecurity culture throughout the group, in coordination with areas such as Technology, Risk, Legal, Privacy, and Audit.

What will your mission be?🎯

It involves participating in the planning, execution, and governance of digital security across corporate systems and services. Ensuring the deployment of controls, regulatory compliance, and proper risk management, acting as a coordination point between business, technology, and governance bodies.

What you'll do

How will you contribute to the purpose of the role with your skills? 💼

  1. Security Management in Technology Projects

The professional will oversee the security lifecycle of projects and services within their scope of action. Likewise, they will act as the primary point of contact and facilitator for different internal and external stakeholders (suppliers) regarding security matters.

  1. Governance, Internal Control, and Regulatory Compliance

They will advise on the implementation, maintenance, and updating of corporate standards, security policies, and regulatory frameworks applicable to global assets. They will collaborate in the processes of preparing, collecting, and validating evidence required for internal, external, and regulatory audits, ensuring the standardization of IT controls. Their focus will be oriented towards the effective operationalization of governance frameworks, supervising that infrastructure and applications comply with the group's regulatory and internal control requirements.

  1. Advanced Security Risk and Exceptions Management

They will direct and supervise security risk analysis and assessment processes, both in internal projects and across the supply chain and third parties with access to the corporate perimeter. The profile requires judgment in defining risk treatment strategies, validating functional and architectural changes with security impact, and managing the complete lifecycle of security exceptions.

  1. Security by Design and Technology Enablement

Ensuring the adoption and integration of Security by Design principles from the conceptual and early stages of the development and systems lifecycle (SSDLC). The role will actively participate in architecture forums and technical committees to assess the viability of solutions before their promotion to production environments. Likewise, they will drive the prioritization and tracking of remediation plans for critical vulnerabilities identified in assets, ensuring that implemented mitigation measures remain strictly aligned with the business risk profile.

  1. Operational Control and Oversight of Security Services

They will continuously supervise the execution and efficiency of recurring operational processes related to information security. The role requires ensuring the proper functioning of corporate services under standardized models, coordinating service channels for managing operational requests, temporary exceptions, and validating security alerts. The candidate will act as a liaison providing support in incident management.

  1. Performance Reporting and Executive Metrics Analysis

They will participate in consolidating the data required for the Security management dashboard by extracting and analyzing Key Performance Indicators. They will use this information to prepare periodic security positioning reports for the Global Security Directorate and governance committees. They will identify trends, anticipate deviations, and propose continuous improvement plans based on data linked to this process.

  1. Economic, Financial, and Supplier Management

They will collaborate in the preparation, defense, and monitoring of the annual budget plan (OPEX and CAPEX) assigned to the security management team. The profile will coordinate the economic execution of budget lines, control variances, and provide specialized support in drafting technical and administrative contractual documentation (Technical Specifications, RFPs, Service Level Agreements) necessary for the homologation, contracting, and lifecycle management of services and products supporting the management function.

  1. Cross-functional Coordination and Organizational Alignment

Acting as a strategic liaison and catalyst between the company's different organizational units (Business, Operations, Systems, Privacy, Legal Counsel, Risk, etc.). The position demands a high capacity to manage complex expectations and competing priorities in a dynamic corporate environment. They must facilitate executive decision-making by transforming complex technical data into structured information.

  1. Leadership, Team Management, and Mentorship

They will lead, organize, and prioritize the daily activities of the team under their responsibility, fostering a collaborative, rigorous, and strongly results-oriented work environment. The role holder will be responsible for setting individual and collective objectives, monitoring professional performance, and fostering the development of technical capabilities and skills within the team. Their function will be to promote a culture of continuous improvement, empowerment, and high methodological accountability.

  1. Promoting Cybersecurity Awareness and Culture

They will design, supervise, and promote the security awareness and training strategy within the scope of the management team and with global reach. The position involves coordinating the creation and launch of periodic threat simulation campaigns (such as social engineering/phishing), defining training paths on corporate learning platforms, and developing technical and awareness-raising informational content aimed at consolidating security best practices within the Group's organizational culture.

What other aspects are relevant?📚

What we're looking for

What skills are we looking for in you? 🔎

  • A high capacity to translate complex technical risks into business impact.
  • Cross-functional leadership skills, analytical thinking, and results orientation, backed by effective communication adapted to both engineering teams and executive committees.
  • Knowledge, assessment capability, and governance vision in securing operating systems (Linux/Windows), public and hybrid cloud environments (AWS, Azure, GCP, VMware), modern architectures and containers (Kubernetes, DevSecOps), corporate identity and access management (IAM, PAM, MFA), as well as in the deployment and integration of perimeter and operational cybersecurity solutions (NGFW, EDR, SIEM).
  • English: Upper-intermediate level spoken and written (equivalent to a minimum B2 level of the Common European Framework of Reference for Languages), with fluency for technical conversations, negotiations with international suppliers, and writing governance documentation.
  • University Degree / Engineering in Computer Science, Telecommunications, Cybersecurity, Information Systems, or equivalent scientific/technological disciplines.
  • More than 5 years of proven professional experience in Cybersecurity, Information Systems Audit, IT Infrastructure, Digital Operations Management, or related GRC technology consulting areas.
  • Solid and demonstrable experience in leading technology security projects with cross-functional scope and in leading or coordinating technical teams in complex organizations.
  • To perform these tasks, a solid professional profile is required that combines proven technical experience in cybersecurity project management, governance, risk and compliance frameworks (GRC), auditing, and regulatory compliance, with a high capacity to translate complex technical risks into business impact.

Nice to have

  • Alternative Education: Equivalent qualifications or solid professional careers backed by postgraduate studies and certifications recognized in the field of digital security and IT governance will be valued.
  • Regulatory Familiarity: Experience in implementing and auditing controls aligned with the ISO/IEC 27001 family of standards, data privacy regulations (GDPR), and financial and operational compliance frameworks (SOX, PCI DSS, banking or insurance sector regulations).
  • CISSP, CISM, CRISC, CISA, ISO 27001, cloud certifications (Azure, AWS, GCP), and privacy/compliance certifications.

What you'll get

What advantages will you have by being part of our team?💙

  • Transformative projects. At Telefónica, you will be part of high-impact projects that set trends and address the connectivity and digital transformation challenges of our society.
  • Professional development. You will have a long career path and learning opportunities on a global scale, thanks to our presence in different geographies. We will share with you opportunities for development, training and mobility options. We want to grow and build a future with you!
  • Flexibility. We are committed to the balance between professional and personal life. At Telefónica, we care about flexibility, positioning ourselves as a benchmark in new ways of working and work-life balance measures.
  • 27 working days of vacation to enjoy.
  • Social benefits. You will be able to enjoy a comprehensive package of social benefits, including:
    • Life and accident insurance
    • Medical insurance for you and your family unit (spouse and children)
    • Meal voucher card
    • Flexible compensation plan with numerous options to choose from.
    • Pension plan

And much more!

Additional information

At Telefónica, we are committed to building a diverse, inclusive, and sustainable work environment where every person feels valued, respected, and free. Our culture is based on equal opportunity and inclusion because we have the responsibility to transform society and make the world a better place.

If you want to be part of an innovative team and contribute to a better future, we are waiting for you!

This job was automatically translated to English, .

About the company

Telefónica

Telefónica

Telecom

View company profile
Spanish company
100000 employees