Cyber Security Senior Officer
$48,000–$58,000 year
HybridLisbon, Lisbon, Portugal or Porto, Porto, Portugal
Job Summary
Identify, assess, and prioritize cyber risks across IT projects and production environments while designing end-to-end security architectures for network, application, data, and cloud systems. Develop security blueprints, reference architectures, and hardened configuration baselines to embed security-by-design principles in multi-cloud, container, and serverless environments. Conduct threat modelling, security assessments, and reviews of deliverables to define remediation roadmaps and actionable recommendations for IT delivery teams and stakeholders. Monitor production environments, review vulnerability management activities, and support the implementation of cloud security controls including IAM, encryption, and secure CI/CD practices. Collaborate with engineering teams to improve security processes and facilitate workshops, training, and security champion initiatives. Contribute to security governance, internal knowledge bases, and compliance with regulatory requirements such as PSD2, GDPR, and PCI DSS.
Required Qualifications
- At least 8 years of professional experience in cybersecurity
- At least 4 years in security architecture, cyber risk, or a senior security advisory role
- Experience working in complex and demanding environments, ideally within banking, financial services, or other highly regulated industries
- Comfortable working across technical and business teams and translating complex cybersecurity requirements into clear and actionable recommendations
- Proactive, analytical, results-driven, and comfortable taking ownership of security topics from assessment through to remediation
- CISSP certification (mandatory)
- Bachelor's or Master's degree in Computer Science, Information Security, Engineering, or a related discipline
- English: Fluent / Professional proficiency required
- Ability to communicate effectively with both technical and non-technical stakeholders
- Strong analytical and problem-solving skills
- Client-focused and results-driven mindset
- Ability to work autonomously while contributing effectively to international and multicultural teams
- Comfortable collaborating across geographically distributed teams
- Strong sense of integrity, accountability, and ownership
- Ability to influence stakeholders and provide clear, pragmatic security recommendations
Desired Qualifications
- Experience in security architecture, cyber risk, or a senior security advisory role (in addition to the 4-year minimum)
- Experience working in complex and demanding environments (in addition to the banking/regulated industry preference)
- Knowledge of investment banking environments, regulatory expectations, PSD2, GDPR, PCI DSS and financial-sector threat landscapes
- Familiarity with AI-enabled security solutions, automated threat intelligence, risk scoring, anomaly detection, or AI-assisted code/security analysis
- CISA, CCSP, AWS/Azure/GCP Security certifications
- French: Basic knowledge
- Experience with AWS, Azure and/or GCP
- Knowledge of IAM, networking, encryption, secrets management, CSPM/CSA and cloud security controls
- Knowledge of Microservices, APIs, containers, Kubernetes, serverless architectures, Infrastructure-as-Code and secure CI/CD pipelines
- Experience with Vulnerability management, SIEM, DLP, SAST/DAST, IAM governance and security testing
- Knowledge of ISO/IEC 27000 series, ISO 27005, ISO 31000, NIST CSF and security governance frameworks
- Experience with zero trust, application, infrastructure, network and data security
- Experience with security-by-design, threat modelling, risk assessment, security controls
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.