Portuguese company hires for hybrid position
Location: Lisbon or Porto, Portugal
- ️ Only candidates already based in Portugal will be considered
Work Model: Hybrid
️ Language Requirements: English B2+ — mandatory, Basic French — valued
Seniority: Senior (8+ years)
Sector: Banking
Rate Between €2600 - 3300 RV / €1840 - 2320 CTI
- ️ Instructions: Please send your CV in English and make sure to include all skills and experience that match the requirements of the opportunity. This will significantly increase your chances of success
We are looking for a Senior Cyber Security Officer to help build a resilient, security-by-design environment for global banking platforms.
Working closely with the CISO Office, senior business leaders, IT delivery teams, product owners, and security engineers, you will protect critical financial services, influence security strategy, and define controls for cloud-native environments.
This position offers the opportunity to work on large-scale international projects and contribute to innovative, AI-enabled security solutions across teams located in Portugal, France, and India.
Cyber Risk Management
-
Identify, assess, and prioritise cybersecurity risks across IT projects and production environments.
- Ensure alignment with internal security policies and recognised standards, including ISO 27001, ISO 27005, ISO 31000, and NIST CSF.
- Conduct independent security assessments and identify control gaps.
- Review risk assessments, threat models, security test results, and architecture diagrams.
- Define practical remediation roadmaps and monitor the resolution of security findings.
- Advise stakeholders on risk acceptance, mitigation, transfer, and remediation decisions.
Security Architecture
-
Design end-to-end security architectures covering networks, applications, data, infrastructure, and cloud environments.
- Embed security controls from the initial stages of solution design.
- Produce security blueprints, reference architectures, and hardened configuration baselines.
- Define security requirements for microservices, APIs, containers, serverless solutions, and Zero Trust networks.
- Translate complex security requirements into clear and actionable guidance for technical and non-technical stakeholders.
- Act as the primary security advisor to delivery teams, product owners, and business units.
Cloud and DevSecOps Security
-
Lead detailed assessments of complex, cloud-centric architectures.
- Evaluate multi-cloud environments, Infrastructure as Code, containers, orchestration platforms, and serverless technologies.
- Define cloud-specific controls, tools, and secure integration patterns.
- Assess IAM, network security, encryption, secrets management, and secure CI/CD pipelines.
- Support the implementation and use of CSP-native security services, CSPM and cloud-security assessment tools.
- Promote security-by-design principles throughout cloud and software-development lifecycles.
Security Improvement and AI-Enabled Controls
-
Identify gaps and improvement opportunities within existing security processes.
- Lead continuous-improvement initiatives across cybersecurity practices.
- Evaluate or integrate AI and machine-learning security solutions.
- Use technologies such as automated threat-intelligence enrichment, anomaly detection, risk scoring, and code-review assistants.
- Improve the speed, consistency, and accuracy of security reviews through automation.
- Ensure that innovative security solutions remain controlled, traceable, and aligned with risk requirements.
Security Awareness and Collaboration
-
Conduct security workshops and training sessions.
- Develop and support Security Champion programmes.
- Contribute to internal security knowledge bases, standards, and best-practice documentation.
- Work collaboratively with multidisciplinary and geographically distributed teams.
- Communicate cybersecurity risks, recommendations, and decisions to senior stakeholders.
-
CISSP certification.
- Bachelor’s degree or higher in Computer Science, Information Security, Engineering, or a related discipline.
- At least eight years of progressive professional experience in cybersecurity.
- At least four years of experience in security architecture or a senior cybersecurity advisory role.
- Proven experience delivering security for large-scale, cloud-native projects.
- Strong knowledge of the ISO/IEC 27000 series, ISO 27005, and ISO 31000.
- Familiarity with NIST CSF or equivalent cybersecurity frameworks.
- Strong understanding of application, data, infrastructure, network, and cloud architecture.
- Knowledge of microservices, APIs, container orchestration, and Zero Trust principles.
- Hands-on experience securing AWS, Azure, and/or Google Cloud Platform environments.
- Experience with cloud IAM, networking, encryption, secrets management, and secure CI/CD pipelines.
- Mastery-level English.
- Strong written and verbal communication skills.
-
CISA, CCSP, AWS Security Specialty, Azure Security, GCP Security, or equivalent certifications.
- Experience in banking, investment banking, or financial services.
- Knowledge of financial-sector cybersecurity threats and regulatory expectations.
- Familiarity with PSD2, GDPR, and PCI DSS.
- Experience with vulnerability-management platforms.
- Knowledge of SIEM, DLP, CSPM, cloud-security assessment, SAST, DAST, and IAM governance tools.
- Experience evaluating or integrating AI-based security solutions.
- Knowledge of automated threat intelligence, anomaly detection, security-risk scoring, or AI-assisted code analysis.
- Experience working with teams across different countries and time zones.
- Basic or conversational knowledge of French.
The ideal candidate is an experienced cybersecurity professional who combines strong security-architecture expertise with practical cloud-security knowledge.
You can review complex technical environments, identify meaningful risks, and convert security policies into pragmatic controls and remediation plans. You are comfortable advising senior business stakeholders while also engaging in detailed technical discussions with architects, developers, cloud engineers, and security specialists.
You are collaborative, results-driven, client-focused, and committed to professional integrity. You also have the confidence to challenge technical decisions constructively and promote security-by-design across international teams.
-
Do you hold a valid CISSP certification?
- Do you have a bachelor’s degree or higher in Computer Science, Information Security, Engineering, or a related area?
- Do you have at least eight years of professional cybersecurity experience?
- Do you have at least four years of experience in security architecture or a senior security advisory position?
- Have you delivered security solutions for large-scale, cloud-native banking or financial-services projects?
- Which cloud platforms have you secured: AWS, Azure, GCP, or a combination of them?
- What hands-on experience do you have with cloud IAM, networking, encryption, secrets management, and secure CI/CD?
- Have you designed end-to-end security architectures or produced security blueprints and reference architectures?
- What experience do you have with risk assessments, threat modelling, security testing, and remediation roadmaps?
- Have you assessed microservices, APIs, containers, Kubernetes, serverless technologies, or Infrastructure as Code?
- Which security tools have you used for SIEM, DLP, CSPM, vulnerability management, SAST, DAST, and IAM governance?
- Are you familiar with ISO 27001, ISO 27005, ISO 31000, and NIST CSF?
- Do you have experience with PSD2, GDPR, PCI DSS, or other financial-sector regulations?
- Have you evaluated or implemented AI-based cybersecurity solutions?
- Have you led security workshops, training sessions, or Security Champion programmes?
- Is your English level mastery or fully proficient?
- What is your current level of French?
- Are you currently based in Portugal?
- Would you prefer to work in Lisbon or Porto?
- What is your availability to start?
- What are your salary expectations under RV or CTI?
Cyber Security, Cybersecurity, Cyber Security Officer, Security Architecture, Security Architect, Security Advisory, CISSP, CISA, CCSP, AWS Security Specialty, Azure Security, GCP Security, Information Security, Cyber Risk Management, Security Risk Assessment, Threat Modelling, Security Assessment, Security by Design, Security Controls, Security Blueprint, Reference Architecture, Hardened Baseline, Remediation Roadmap, ISO 27001, ISO 27005, ISO 31000, ISO IEC 27000, NIST CSF, Cloud Security, AWS, Microsoft Azure, Google Cloud Platform, GCP, Multi-Cloud, Cloud Native, IAM, IAM Governance, Identity and Access Management, Network Security, Encryption, Secrets Management, Zero Trust, Microservices, API Security, Containers, Kubernetes, Container Orchestration, Serverless, Infrastructure as Code, IaC, DevSecOps, Secure CI/CD, Vulnerability Management, SIEM, DLP, CSPM, Cloud Security Assessment, SAST, DAST, Threat Intelligence, Anomaly Detection, AI Security, Machine Learning Security, Automated Risk Scoring, Code Analysis, Security Automation, Security Champions, Security Awareness, Banking, Investment Banking, Financial Services, PSD2, GDPR, PCI DSS, CISO, Stakeholder Management, English Fluent, French Basic
#CI - PROC26302