Now hiring

Cybersecurity & IT Lead @ Veridas

Pamplona HeadquartersOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

Your mission We are looking for a new member of our team with strategic vision and technical expertise to lead our technology infrastructure and security strategy. As IT Lead &amp; Cybersecurity, you will play a key role in ensuring the resilience of our systems, leading the IT &amp; Systems team and ensuring compliance with security standards in a high-tech environment.<br><br>As part of the IT &amp; Operations team, you will report directly to the Head of Operations and will be responsible for the integrity and availability of our digital assets.<br><br>Your responsibilities:<br><br><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><strong>1. Corporate IT Leadership and Management:</strong></span></p><br><ul style="margin-top:0;margin-bottom:0;"><li style="list-style-type:disc;font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Team management: Leading, supervising and coordinating the work of the technical team.</span></p></li><li style="list-style-type:disc;font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Infrastructure and Assets: Organising, implementing and maintaining IT systems, networks and applications. Managing the lifecycle, procurement and supply of equipment for staff.</span></p></li><li style="list-style-type:disc;font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Governance: Oversee the internal infrastructure (servers, networks and perimeter) and ensure high-quality technical support for users.</span></p></li></ul><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><br></p><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><strong>2. Cybersecurity and Risk Management:</strong></span></p><br><ul style="margin-top:0;margin-bottom:0;"><li style="list-style-type:disc;font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Prevention: Analyse threats, detect security breaches and implement defence mechanisms to mitigate attacks on vulnerable points.</span></p></li><li style="list-style-type:disc;font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Vulnerabilities: Select and implement vulnerability management tools, establishing a schedule for scanning products and systems.</span></p></li><li style="list-style-type:disc;font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Incident Management: Lead the response to security incidents to follow up on findings with product teams.</span></p></li><li style="list-style-type:disc;font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Continuity: Responsible for the strategy regarding backups, restoration and disaster recovery plans.</span></p></li><li style="list-style-type:disc;font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Operations and Incident Response: Active monitoring of alerts (EDR, firewalls, phishing and data breaches) to move from automatic detection to actual remediation, ensuring that confirmed threats are addressed.</span></p></li><li style="list-style-type:disc;font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Infrastructure Hygiene and Vulnerabilities: Cleaning up access in the cloud (AWS/GCP), resuming asset scanning and monitoring vulnerable libraries both in the data centre and in the development pipeline.</span></p></li><li style="list-style-type:disc;font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Compliance and Awareness: Managing annual training, internal safety bulletins, maintaining documentation and carrying out risk assessments.</span></p></li></ul><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><br></p><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><strong>3. Compliance:</strong></span></p><br><ul style="margin-top:0;margin-bottom:0;"><li style="list-style-type:disc;font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Standards: Ensure compliance with national and international standards (ISO 27001, ENS, etc.).</span></p></li><li style="list-style-type:disc;font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Audits: Provide technical evidence for external audits and support the System Manager on cloud and product-related matters.</span></p></li><li style="list-style-type:disc;font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;"><p style="line-height:1.38;margin-top:0pt;margin-bottom:0pt;"><span style="font-size:10.5pt;font-family:Arial, sans-serif;color:#000000;background-color:transparent;font-weight:400;font-style:normal;text-decoration:none;">Awareness: Plan and deliver security training initiatives for staff, supplemented by regular communications on best practice.</span></p></li></ul><br> Your profile <ul><li>Qualifications: Higher vocational training qualification or university degree relevant to the post and its duties. Will be assessed on the basis of relevant experience.</li><li>Experience: 2 to 5 years</li><li>Languages: Advanced English, particularly in terms of reading comprehension.</li><li>Attitudes: initiative, teamwork, problem-solving, analytical skills, empathy and communication.</li><li>Technical skills:</li><li>Knowledge of network management, servers and perimeter security.</li><li>Experience in administering identity management platforms (LDAP, OAuth2 and similar).</li><li>In-depth knowledge of security standards (ISO 27001 / ENS).</li><li>Experience in managing cloud infrastructure and using tools for scanning and monitoring security alerts.</li></ul>Furthermore, the following knowledge would be an advantage:<ul><li>Experience in high-availability environments and in-house technology products.</li><li>Knowledge of patch automation and component lifecycle management.</li></ul> What we offer? Be part of a high-tech company with its own product, operating worldwide in critical environments.<br><br>The opportunity to develop a global career and be part of a team made up of highly qualified and experienced staff.<br><ul><li>A highly competitive fixed and variable salary package, commensurate with the candidate’s experience.</li><li>Working from home (WFH) in accordance with company policy.</li><li>A collaborative and multidisciplinary working environment.</li><li>Flexible remuneration and ongoing training.</li></ul>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores