hirq
← All jobs

Veridas Digital Authentication Solutions, S.L.

IT Lead & Cybersecurity

Pamplona Headquarters · On-site · full-time · IT & Operations

Apply well, not just fast

Create a free account and upload your resume to get a match score, keyword gaps, a tailored resume, a cover letter and interview prep for this job.

About the role

CybersecurityISO 27001ComplianceAWSGCPIncident ResponseRisk ManagementLeadership
We are looking for a new member of our team with strategic vision and technical expertise to lead our technology infrastructure and security strategy. As IT Lead & Cybersecurity, you will play a key role in ensuring the resilience of our systems, leading the IT & Systems team and ensuring compliance with security standards in a high-tech environment. As part of the IT & Operations team, you will report directly to the Head of Operations and will be responsible for the integrity and availability of our digital assets. Your responsibilities: 1. Corporate IT Leadership and Management: - Team management: Leading, supervising and coordinating the work of the technical team. - Infrastructure and Assets: Organising, implementing and maintaining IT systems, networks and applications. Managing the lifecycle, procurement and supply of equipment for staff. - Governance: Oversee the internal infrastructure (servers, networks and perimeter) and ensure high-quality technical support for users. 2. Cybersecurity and Risk Management: - Prevention: Analyse threats, detect security breaches and implement defence mechanisms to mitigate attacks on vulnerable points. - Vulnerabilities: Select and implement vulnerability management tools, establishing a schedule for scanning products and systems. - Incident Management: Lead the response to security incidents to follow up on findings with product teams. - Continuity: Responsible for the strategy regarding backups, restoration and disaster recovery plans. - Operations and Incident Response: Active monitoring of alerts (EDR, firewalls, phishing and data breaches) to move from automatic detection to actual remediation, ensuring that confirmed threats are addressed. - Infrastructure Hygiene and Vulnerabilities: Cleaning up access in the cloud (AWS/GCP), resuming asset scanning and monitoring vulnerable libraries both in the data centre and in the development pipeline. - Compliance and Awareness: Managing annual training, internal safety bulletins, maintaining documentation and carrying out risk assessments. 3. Compliance: - Standards: Ensure compliance with national and international standards (ISO 27001, ENS, etc.). - Audits: Provide technical evidence for external audits and support the System Manager on cloud and product-related matters. - Awareness: Plan and deliver security training initiatives for staff, supplemented by regular communications on best practice. - Qualifications: Higher vocational training qualification or university degree relevant to the post and its duties. Will be assessed on the basis of relevant experience. - Experience: 2 to 5 years - Languages: Advanced English, particularly in terms of reading comprehension. - Attitudes: initiative, teamwork, problem-solving, analytical skills, empathy and communication. - Technical skills: - Knowledge of network management, servers and perimeter security. - Experience in administering identity management platforms (LDAP, OAuth2 and similar). - In-depth knowledge of security standards (ISO 27001 / ENS). - Experience in managing cloud infrastructure and using tools for scanning and monitoring security alerts.Furthermore, the following knowledge would be an advantage: - Experience in high-availability environments and in-house technology products. - Knowledge of patch automation and component lifecycle management. Be part of a high-tech company with its own product, operating worldwide in critical environments. The opportunity to develop a global career and be part of a team made up of highly qualified and experienced staff. - A highly competitive fixed and variable salary package, commensurate with the candidate’s experience. - Working from home (WFH) in accordance with company policy. - A collaborative and multidisciplinary working environment. - Flexible remuneration and ongoing training.