Information Security Director, Spain
cexio ·
- Work mode
- Remote
- Category
- Security
CEX.IO Europe S.L. is in the final stages of obtaining authorization under the EU Markets in Crypto-Assets Regulation (MiCA) as a Crypto-Asset Service Provider (CASP) in Spain. As part of our regulatory readiness and local substance requirements, we are actively recruiting a Spain‑based Information Security Director.
The Information Security Director will be the primary local official responsible for ensuring the digital operational resilience of CEX.IO Europe S.L. in accordance with Regulation (EU) 2022/2554 (DORA).
The Information Security Director’s core mandate is to maintain an effective local capacity for decision-making, supervision, and questioning over all ICT functions delegated to group entity service providers. This includes the explicit authority to understand, supervise, question, approve, reject, or nullify any technical action, proposal, or recommendation from Group service providers that impacts EU operations.
The Information Security Director is responsible for the independent management of technology and cyber risks within the Spanish jurisdiction, ensuring operational substance and digital resilience. The Information Security Director acts as the principal technical liaison and accountable officer for the National Securities Market Commission (CNMV) and the Bank of Spain on all cybersecurity, DORA compliance, and DLT-related supervisory matters.
Key Responsibilities
- DORA & MiCA Governance: Lead the implementation and maintenance of the ICT risk management framework to meet CNMV, ESMA, and EBA standards.
- Oversight of Delegated Functions: Supervise and control ICT services provided by CEX.IO group entities (including CEX.IO Ltd, UK), spanning cloud infrastructure, software development, and security operations.
- ICT Risk Management: Identify, assess, and mitigate technological risks. Conduct annual reviews of the Business Impact Analysis (BIA) and the ICT Risk Assessment.
- Incident Management: Act as the ultimate local authority for initiating the Incident Response Plan (IRP) for high and critical security events. Coordinate notifications of major ICT-related incidents to the CNMV within mandated regulatory timelines (4h / 72h / 30 days).
- Third-Party ICT Security: Supervise critical ICT third-party service providers, monitoring compliance with contractual SLAs, Recovery Point Objectives (RPOs), and Recovery Time Objectives (RTOs).
- Custody Security & Cryptographic Controls: Oversee the security of crypto-asset custody solutions (proprietary V2/V3 infrastructure and external sub-custodians). Ensure the integrity of Multi-Party Computation (MPC), Hardware Security Modules (HSM), and multisig signing workflows.
- Secure SDLC Oversight: Supervise the Secure Software Development Life Cycle (SDLC) and validate security testing in pre-production (UAT) environments prior to operational deployment.
- Resilience & DLT Testing: Approve and collaborate on operational resilience testing plans, threat-led penetration testing (TLPT), and specific tests covering Distributed Ledger Technology (DLT) protocols.
- Asset & Inventory Governance: Maintain a unified, centralized inventory of all CEX.IO ICT assets, systems, and network infrastructure supporting Spanish and EU operations.
Requirements and Qualifications
- University degree in Computer Science, Computer Engineering, Cybersecurity, or a related technical field, ideally holding relevant industry certifications (e.g., CISM, CISSP, CRISC, or CISA).
- Proven track record in building cybersecurity frameworks and complying with EU financial sector regulations (DORA, MiCA, PCI DSS).
- Technical Domain Knowledge: Vulnerability management, threat monitoring tools, and SIEM/SOC platforms (e.g., Grafana, Kibana, Elastic).
- Cryptographic protocols, key ceremony management, and secure private key storage.
- Strong communication skills for interacting directly with financial regulators (CNMV / Bank of Spain) and leading technical governance under a "hub and spoke" group operational model.
- Full local tax/legal residency in Spain with native/bilingual proficiency in Spanish and professional working proficiency in English.