Information Security Officer, Valencia
Empresa
Luminary
Provincia
Valencia
Ciudad
Valencia
Tipo de Contrato
Por Horas
Salario
Entre 2700 Euros y 9000 Euros Bruto/mes
Descripción
Information Security Officer
Luminary is looking for an Information Security Officer to join the team and own our information security function setting priorities, managing risk, and independently verifying controls with direct access to the Board.
About the Role
The Information Security Officer will own the information security function, defining and maintaining the security framework, managing risk, overseeing controls and monitoring, and reporting directly to leadership and the Board, with oversight of external security providers.
Responsibilities
Governance Risk
- Build and maintain the security framework, risk register, and roadmap
- Report risks to the Board
Controls Access
- Set security requirements
- Verify controls
- Run recurring access reviews (MFA, PAM, logging, monitoring)
Monitoring Incident Response
- Run security monitoring (incl. MSSPs)
- Maintain incident response runbooks
- Lead investigations
Vendor Third-Party
- Select, assess, and oversee security vendors and third-party risk
Testing Remediation
- Commission penetration tests
- Prioritize findings
Verify fixes
Regulatory Audit
Support DORA, PCI DSS, GDPR, and ISO 27001 compliance
Own audits and regulatory reviews.
Required Skills
Experience building or leading an information security function from the ground up
Strong grounding in governance, risk, access management, monitoring, and incident response
Technical ability to independently assess controls, configurations, and logging coverage
Experience managing security vendors and participating in audits or supervisory reviews
Strong communication skills for senior management and Board reporting
Working knowledge of DORA, PCI DSS, GDPR, and ISO/IEC 27001.
5+ years in information security, including 3+ years in a regulated financial organisation (EMI, payment institution, bank, or payment system).
Nice to have
Experience with MSSPs and within an EMI, PSP, FinTech, or neobank environment
Experience implementing DORA, supporting PCI DSS assessments, or preparing ISO 27001 evidence
Comfortable owning security solo in a smaller organisation
CISM, CISSP, CCSP, CISA, or ISO/IEC 27001 Lead Implementer/Auditor a plus.
What you can expect from us
A team that actually has your back. Close-knit, talented, low-ego no bureaucracy, just people who care about doing great work together
Real ownership from day one. In a fast-moving startup, your decisions shape the security function not inherit it
An office worth showing up for. Right in the heart of Valencia sunshine, great coffee, and a team that genuinely enjoys being there
Relocation? We can make it happen and well support it fully. ...but tssshhh, lets keep that between us.
MSSP, PCI DSS, Dora
Luminary is looking for an Information Security Officer to join the team and own our information security function setting priorities, managing risk, and independently verifying controls with direct access to the Board.
About the Role
The Information Security Officer will own the information security function, defining and maintaining the security framework, managing risk, overseeing controls and monitoring, and reporting directly to leadership and the Board, with oversight of external security providers.
Responsibilities
Governance Risk
- Build and maintain the security framework, risk register, and roadmap
- Report risks to the Board
Controls Access
- Set security requirements
- Verify controls
- Run recurring access reviews (MFA, PAM, logging, monitoring)
Monitoring Incident Response
- Run security monitoring (incl. MSSPs)
- Maintain incident response runbooks
- Lead investigations
Vendor Third-Party
- Select, assess, and oversee security vendors and third-party risk
Testing Remediation
- Commission penetration tests
- Prioritize findings
Verify fixes
Regulatory Audit
Support DORA, PCI DSS, GDPR, and ISO 27001 compliance
Own audits and regulatory reviews.
Required Skills
Experience building or leading an information security function from the ground up
Strong grounding in governance, risk, access management, monitoring, and incident response
Technical ability to independently assess controls, configurations, and logging coverage
Experience managing security vendors and participating in audits or supervisory reviews
Strong communication skills for senior management and Board reporting
Working knowledge of DORA, PCI DSS, GDPR, and ISO/IEC 27001.
5+ years in information security, including 3+ years in a regulated financial organisation (EMI, payment institution, bank, or payment system).
Nice to have
Experience with MSSPs and within an EMI, PSP, FinTech, or neobank environment
Experience implementing DORA, supporting PCI DSS assessments, or preparing ISO 27001 evidence
Comfortable owning security solo in a smaller organisation
CISM, CISSP, CCSP, CISA, or ISO/IEC 27001 Lead Implementer/Auditor a plus.
What you can expect from us
A team that actually has your back. Close-knit, talented, low-ego no bureaucracy, just people who care about doing great work together
Real ownership from day one. In a fast-moving startup, your decisions shape the security function not inherit it
An office worth showing up for. Right in the heart of Valencia sunshine, great coffee, and a team that genuinely enjoys being there
Relocation? We can make it happen and well support it fully. ...but tssshhh, lets keep that between us.
MSSP, PCI DSS, Dora