EnglishWillDo

CISO

Freightos · Barcelona, Spain

No Spanish requiredPosted today
Apply for this job

You apply on the site where the job is posted. I never handle applications.

Think about literally anything in your house. Your shirt. Your phone. That random IKEA wrench thingamabob you still haven’t thrown away. Odds are, it all came from somewhere else.

Freight is the invisible magic trick that makes the global economy work. And we’re the ones helping it work a little bit faster, smarter, and cheaper.

Freightos (Nasdaq: CRGO) is the global booking and payment platform for the trillion-dollar freight industry. Hundreds of airlines and ocean liners, thousands of freight companies, and over ten thousand importers and exporters use our platform to move goods around the world faster and more efficiently. This matters. Efficient freight ultimately makes things cost a little bit less when you buy them in the store.

We are looking for a hybrid powerhouse: a Chief Information Security Officer. In this role, you will be the guardian of Freightos' trust. You will shape and drive our cybersecurity vision, ensuring our platform, products, people, and data remain secure while enabling innovation and business growth. You are the kind of leader who builds security into everything, protecting every digital doorway without slowing down the movement of global trade. From strategic risk management and governance to incident response and security engineering, you'll foster a culture where security is a business enabler, not a roadblock.

Responsibilities:

  • Develop, implement, and continuously enhance Freightos' enterprise-wide cybersecurity strategy, policies, standards, and governance framework.
  • Lead Freightos information security program to protect the confidentiality, integrity, and availability of information assets.
  • Identify, assess, and manage cybersecurity risks, ensuring appropriate controls are implemented to mitigate business and technology risks.
  • Oversee security operations, including threat monitoring, vulnerability management, incident response, and remediation activities.
  • Direct the development and execution of incident response, disaster recovery, and business continuity plans.
  • Establish and maintain security architecture and best practices across cloud infrastructure, network, endpoint, application, and data environments.
  • Ensure compliance with applicable laws, regulations, contractual obligations, and industry standards, and support internal and external audits.
  • Develop and maintain security policies, procedures, and awareness programs that promote a strong culture of cybersecurity across the organization.
  • Advise executive leadership and the Board of Directors on cybersecurity strategy, emerging threats, risk posture, and investment priorities.
  • Lead and mentor the information security team, fostering professional development, accountability, and operational excellence.
  • Manage cybersecurity budgets, evaluate emerging technologies, and recommend investments that improve the organization's security capabilities.
  • Oversee identity and access management, data protection, encryption, and privileged access controls.
  • Collaborate with SRE, IT, R&D, legal and business leaders to integrate security into organizational processes and strategic initiatives.
  • Manage third-party and vendor cybersecurity risk assessments, ensuring external partners meet organizational security requirements.
  • Monitor the evolving threat landscape and implement proactive measures to address emerging cybersecurity risks and improve the organization's overall security maturity.

Requirements:

  • ReBachelor's degree in Information Security, Computer Science, Information Technology, Cybersecurity, or a related field.
  • 10+ years of progressive experience in information security or cybersecurity.
  • 5+ years of leadership experience managing security teams and programs.
  • Strong understanding of cybersecurity frameworks such as NIST CSF, ISO/IEC 27001, CIS Controls, and COBIT.
  • Experience presenting cybersecurity strategy to executive leadership and Boards of Directors.
  • Experience with cloud security (AWS and Google Cloud).
  • Experience managing security operations, incident response, vulnerability management, identity management, and governance.
  • Strong understanding of risk management and regulatory compliance.
  • Excellent leadership, communication, and stakeholder management skills.

Preferred Qualifications

  • Master's degree in Cybersecurity, Information Technology, Business Administration, or related discipline.
  • Professional certifications such as:
  • CISSP
  • CISM
  • CRISC
  • CCSP
  • CISA
  • GIAC certifications

General:

Reports to: CEO

Location: Barcelona, hybrid

Full-time position

Hybrid:

Yes