CYBER SECURITY SENIOR OFFICER (HYBRID)
iTRTech Group
CYBER SECURITY SENIOR OFFICER (HYBRID LISBON OR PORTO)
Portuguese company hires for hybrid position
Location: Lisbon or Porto, Portugal
- ️ Only candidates already based in Portugal will be considered
Work Model: Hybrid
️ Language Requirements: English B2+ — mandatory, Basic French — valued
Seniority: Senior (8+ years)
Sector: Banking
Rate Between €2600 - 3300 RV / €1840 - 2320 CTI
- ️ Instructions: Please send your CV in English and make sure to include all skills and experience that match the requirements of the opportunity. This will significantly increase your chances of success
About the Opportunity
We are looking for a Senior Cyber Security Officer to help build a resilient, security-by-design environment for global banking platforms.
Working closely with the CISO Office, senior business leaders, IT delivery teams, product owners, and security engineers, you will protect critical financial services, influence security strategy, and define controls for cloud-native environments.
This position offers the opportunity to work on large-scale international projects and contribute to innovative, AI-enabled security solutions across teams located in Portugal, France, and India.
Key Responsibilities
Cyber Risk Management
- Identify, assess, and prioritise cybersecurity risks across IT projects and production environments.
- Ensure alignment with internal security policies and recognised standards, including ISO 27001, ISO 27005, ISO 31000, and NIST CSF.
- Conduct independent security assessments and identify control gaps.
- Review risk assessments, threat models, security test results, and architecture diagrams.
- Define practical remediation roadmaps and monitor the resolution of security findings.
- Advise stakeholders on risk acceptance, mitigation, transfer, and remediation decisions.
Security Architecture
- Design end-to-end security architectures covering networks, applications, data, infrastructure, and cloud environments.
- Embed security controls from the initial stages of solution design.
- Produce security blueprints, reference architectures, and hardened configuration baselines.
- Define security requirements for microservices, APIs, containers, serverless solutions, and Zero Trust networks.
- Translate complex security requirements into clear and actionable guidance for technical and non-technical stakeholders.
- Act as the primary security advisor to delivery teams, product owners, and business units.
Cloud and DevSecOps Security
- Lead detailed assessments of complex, cloud-centric architectures.
- Evaluate multi-cloud environments, Infrastructure as Code, containers, orchestration platforms, and serverless technologies.
- Define cloud-specific controls, tools, and secure integration patterns.
- Assess IAM, network security, encryption, secrets management, and secure CI/CD pipelines.
- Support the implementation and use of CSP-native security services, CSPM and cloud-security assessment tools.
- Promote security-by-design principles throughout cloud and software-development lifecycles.
Security Improvement and AI-Enabled Controls
- Identify gaps and improvement opportunities within existing security processes.
- Lead continuous-improvement initiatives across cybersecurity practices.
- Evaluate or integrate AI and machine-learning security solutions.
- Use technologies such as automated threat-intelligence enrichment, anomaly detection, risk scoring, and code-review assistants.
- Improve the speed, consistency, and accuracy of security reviews through automation.
- Ensure that innovative security solutions remain controlled, traceable, and aligned with risk requirements.
Security Awareness and Collaboration
- Conduct security workshops and training sessions.
- Develop and support Security Champion programmes.
- Contribute to internal security knowledge bases, standards, and best-practice documentation.
- Work collaboratively with multidisciplinary and geographically distributed teams.
- Communicate cybersecurity risks, recommendations, and decisions to senior stakeholders.
Mandatory Requirements
- CISSP certification.
- Bachelor’s degree or higher in Computer Science, Information Security, Engineering, or a related discipline.
- At least eight years of progressive professional experience in cybersecurity.
- At least four years of experience in security architecture or a senior cybersecurity advisory role.
- Proven experience delivering security for large-scale, cloud-native projects.
- Strong knowledge of the ISO/IEC 27000 series, ISO 27005, and ISO 31000.
- Familiarity with NIST CSF or equivalent cybersecurity frameworks.
- Strong understanding of application, data, infrastructure, network, and cloud architecture.
- Knowledge of microservices, APIs, container orchestration, and Zero Trust principles.
- Hands-on experience securing AWS, Azure, and/or Google Cloud Platform environments.
- Experience with cloud IAM, networking, encryption, secrets management, and secure CI/CD pipelines.
- Mastery-level English.
- Strong written and verbal communication skills.
Highly Valued Qualifications
- CISA, CCSP, AWS Security Specialty, Azure Security, GCP Security, or equivalent certifications.
- Experience in banking, investment banking, or financial services.
- Knowledge of financial-sector cybersecurity threats and regulatory expectations.
- Familiarity with PSD2, GDPR, and PCI DSS.
- Experience with vulnerability-management platforms.
- Knowledge of SIEM, DLP, CSPM, cloud-security assessment, SAST, DAST, and IAM governance tools.
- Experience evaluating or integrating AI-based security solutions.
- Knowledge of automated threat intelligence, anomaly detection, security-risk scoring, or AI-assisted code analysis.
- Experience working with teams across different countries and time zones.
- Basic or conversational knowledge of French.
The Ideal Candidate
The ideal candidate is an experienced cybersecurity professional who combines strong security-architecture expertise with practical cloud-security knowledge.
You can review complex technical environments, identify meaningful risks, and convert security policies into pragmatic controls and remediation plans. You are comfortable advising senior business stakeholders while also engaging in detailed technical discussions with architects, developers, cloud engineers, and security specialists.
You are collaborative, results-driven, client-focused, and committed to professional integrity. You also have the confidence to challenge technical decisions constructively and promote security-by-design across international teams.
Questions for Candidates
- Do you hold a valid CISSP certification?
- Do you have a bachelor’s degree or higher in Computer Science, Information Security, Engineering, or a related area?
- Do you have at least eight years of professional cybersecurity experience?
- Do you have at least four years of experience in security architecture or a senior security advisory position?
- Have you delivered security solutions for large-scale, cloud-native banking or financial-services projects?
- Which cloud platforms have you secured: AWS, Azure, GCP, or a combination of them?
- What hands-on experience do you have with cloud IAM, networking, encryption, secrets management, and secure CI/CD?
- Have you designed end-to-end security architectures or produced security blueprints and reference architectures?
- What experience do you have with risk assessments, threat modelling, security testing, and remediation roadmaps?
- Have you assessed microservices, APIs, containers, Kubernetes, serverless technologies, or Infrastructure as Code?
- Which security tools have you used for SIEM, DLP, CSPM, vulnerability management, SAST, DAST, and IAM governance?
- Are you familiar with ISO 27001, ISO 27005, ISO 31000, and NIST CSF?
- Do you have experience with PSD2, GDPR, PCI DSS, or other financial-sector regulations?
- Have you evaluated or implemented AI-based cybersecurity solutions?
- Have you led security workshops, training sessions, or Security Champion programmes?
- Is your English level mastery or fully proficient?
- What is your current level of French?
- Are you currently based in Portugal?
- Would you prefer to work in Lisbon or Porto?
- What is your availability to start?
- What are your salary expectations under RV or CTI?
Keywords to Include in Your CV
Cyber Security, Cybersecurity, Cyber Security Officer, Security Architecture, Security Architect, Security Advisory, CISSP, CISA, CCSP, AWS Security Specialty, Azure Security, GCP Security, Information Security, Cyber Risk Management, Security Risk Assessment, Threat Modelling, Security Assessment, Security by Design, Security Controls, Security Blueprint, Reference Architecture, Hardened Baseline, Remediation Roadmap, ISO 27001, ISO 27005, ISO 31000, ISO IEC 27000, NIST CSF, Cloud Security, AWS, Microsoft Azure, Google Cloud Platform, GCP, Multi-Cloud, Cloud Native, IAM, IAM Governance, Identity and Access Management, Network Security, Encryption, Secrets Management, Zero Trust, Microservices, API Security, Containers, Kubernetes, Container Orchestration, Serverless, Infrastructure as Code, IaC, DevSecOps, Secure CI/CD, Vulnerability Management, SIEM, DLP, CSPM, Cloud Security Assessment, SAST, DAST, Threat Intelligence, Anomaly Detection, AI Security, Machine Learning Security, Automated Risk Scoring, Code Analysis, Security Automation, Security Champions, Security Awareness, Banking, Investment Banking, Financial Services, PSD2, GDPR, PCI DSS, CISO, Stakeholder Management, English Fluent, French Basic
#CI - PROC26302
€40,000 a €50,000 por año
...consideradas empregadores de topo a nível nacional. Integrando a área de Security Services & Operations , irá trabalhar de forma próxima com o Business Information Security Officer (BISO) , apoiando a unidade de negócio nas diferentes vertentes da segurança da...- Empresa está à procura de um/a Cyber Security Senior Officer para integrar um projeto em Lisboa, com contrato permanente e de longo prazo. A função terá foco na construção de um ambiente resiliente e orientado por princípios de security by design para plataformas bancárias...
- ...new role As a Senior Cybersecurity Expert... ..., and strategic security initiatives aligned... ...review, and validate secure architectures... ...on-premises, and hybrid environments, ensuring... ...ahead of emerging cyber threats, industry... ...model (2 days in the office, 3 days remote) ~...
- Fundada em 2005, em Lisboa, a agap2IT é uma organização europeia na área dos Sistemas de Informação, Ciência e Tecnologia. A capacidade de intervir globalmente aliada à elevada experiência e know-how técnico, funcional e de negócio da equipa, garantem a excelência da resposta...
- ...documentation and operational management of securities issues by BNP Paribas Issuance,... ...agent’s information) Securities Issuance Officer tasks are within the activity of issuing... ...work in a demanding environment #LI-Hybrid Why joining BNP Paribas? BNP Paribas...
€11.6 por dia
.... We also handle our customers' back office operations from three hubs, in Switzerland... ...The team You will be member of the Securities transfer team (within the Securities... ...day). ~ Annual performance bonus. ~ Hybrid work model – up to 2 days/week from home...- ...experience driven by an experienced and senior team that helps clients make the... ...to join WIRE IT. Role: Security Operations Officer Location: Hybrid, Lisbon, Portugal Required skills... ...Testing Encryption methods and secure protocols Secure Software...
- ...Implementing, handling, monitoring & upgrading security measures for the protection of the OT devices in our hybrid Power Plants. Troubleshoot security and network... ...bonuses for talent recommendations. Great office locations. ABOUT CAPGEMINI Capgemini is an...
- ...position are welcome! We are looking for an Amazing: Cyber security engineer Seniority: Senior-level (5+ years) Type of position: Full Remote from... ...you might find one of this types of projects): In hybrid Systems: Is important to balance work with...
- ...what's possible. We are seeking a Principal Engineer – Cyber Security to act as a senior technical authority in cyber security–focused... ...by translating security, risk, and compliance needs into secure-by-design solutions, combining deep technical expertise with...
- ...their Operational Technology (OT) security capabilities. You will work on... ...infrastructure protection, cyber resilience, regulatory... ...architectures, segmentation models and secure remote access solutions.... ...by actively participating in creating solutions. #LI-HYBRID...
€11.6 por dia
.... We also handle our customers' back office operations from three hubs, in Switzerland... ...The team You will be member of the Securities transfer team (within the Securities... ...day). ~ Annual performance bonus . ~ Hybrid work model – up to 2 days/week from home...- ...Senior Cyber Incident Manager - Lisbon, Portugal Who We Are Boston Consulting Group partners with leaders in business and society... ...Draft clear, timely incident communications for Information Security leadership, IT, Legal, Risk, Data Privacy, regional leadership...
- ...a real impact. Join Vodafone’s Cyber Prevent team and help shape the future of secured telco and network infrastructure. As... ...opportunity. What's in it for you Hybrid Work Model - Flexible hybrid work model with 8-10 in-office days per month, managed by team...
- ...few years – growing our team to more than 550 individuals across offices in London, New York, Singapore, Sydney and our newly... ...Thought Machine teams are taking all required steps in building a secure product set. You will play a major and leading role in protecting...
- ...team to more than 550 individuals across offices in London, New York, Singapore, Sydney... ...four days a week onsite. A Senior Cloud Security Engineer is a part of the larger Security... ...on their own expertise: Designs of secure products and platforms Reviews of engineering...
- ...Devoteam Cyber Trust is the Cybersecurity specialist arm of the Devoteam Group. With our 800+ experts located... ...an end-to-end approach to Cyber Resilience, Applied Security, and Managed Security services to secure the tech journey of large and medium-sized companies...
€2,024 por mês
...Inetum registou um volume de negócios de 2,4 mil milhões de euros em 2024. Descrição do emprego Procuramos um Senior Business Management Officer para integrar uma organização financeira internacional de referência. Será um parceiro estratégico da liderança,...- ...SENIOR C++ DEVELOPER (HYBRID LISBON OR PORTO) Portuguese company hires for hybrid position Location: Lisbon or Porto, Portugal ~️ Only candidates... .... Ensure the platform meets demanding quality, security, reliability, and performance standards. Participate throughout...
- ...love to meet you! ABOUT THE ROLE We are looking for a Senior Security Software Engineer to build cloud security AI accelerators,... .... - Flextime : Flexible schedule with remote and office options. Meet Our Recruitment Process Application →...
- ...The Security Research team at Datadog tracks the evolving threat landscape and develops impactful... ...At Datadog, we place value in our office culture - the relationships and collaboration... ...it brings to the table. We operate as a hybrid workplace to ensure our Datadogs can...
€50,000 a €65,000 por año
**Senior Java Backend Developer (Spring Boot/Kafka/Kubernetes) - Hybrid Lisbon (1 day/week office)** ### ABOUT THE OPPORTUNITY Join the Lisbon tech hub of **Switzerland's national postal and logistics company** — one of the country's largest employers and a major IT organisation...- ...landscape through cloud‑centric security, modern identity, and data... ...response capabilities across hybrid and cloud environments. Our strong... ...side, we design and implement secure, resilient, and scalable... ...international and fast‑growing cyber security practice, delivering...
- ...the Enhesa’s cybersecurity infrastructure by implementing robust security controls, deploying innovative security solutions, and... ...environments. The successful candidate will provide guidance on secure design patterns, conduct comprehensive security reviews of application...
- ...Portugal in 2018—and now with offices in both Lisbon and San Francisco... ...way. The Role As a Security Engineer at Air Apps, you will... ..., and IT teams to implement secure coding practices, vulnerability... ...remain resilient against cyber threats. Your expertise will...
- ...with skills for the position are welcome! We are looking for an Amazing: Project Management Officer Seniority: Senior-level (5+ years) Type of position: Hybrid model in Lisbon. Candidates need to be already living in Portugal! The amazing you, will...
- ...skills shortage. About the role We are looking for a Senior Application Security Engineer to join our Engineering team and own the security... ...and Agentic development practices Drive adoption of secure coding standards and OWASP best practices across the...
- ...Office Operations Senior Manager - Lisbon, Portugal Who We Are Boston Consulting Group partners with leaders in business and society to... ...compliant, and resilient workplace in line with global physical security, health & safety, and risk expectations. Take the role...
- ...CYBERSECURITY EXPERT – CRYPTOGRAPHY (HYBRID LISBON OR PORTO) Portuguese... ...English B2+ — mandatory Seniority: Senior (6+ years) Sector: Banking... ...to enterprise-level security activities covering approximately... ...Your CV Cybersecurity, Cyber Security, Cryptography,...
- ...Planning and time management ~ Technical skills ~ Team working ~ English – fluent (spoken, written) ~ Advanced literacy (MS Office) Additional Information When you join Ergomed Group, you make a difference by helping to bring safe and effective...
Deseja receber mais vagas?
Assine e receba vagas semelhantes a CYBER SECURITY SENIOR OFFICER (HYBRID). Seja o primeiro a se candidatar!


