Santander

Chief Information Security Officer Technology Risk & Cybersecurity

Boadilla del Monte Full time
Chief Information Security Officer Technology Risk & Cybersecurity

Country: Spain

Chief Information Security Officer (CISO) – Cards

Mission
Define, lead and oversee the cybersecurity strategy for Plard (Global Cards Platform), ensuring alignment with Group and Cards cybersecurity frameworks while addressing the specific regulatory, operational and fraud-risk landscape of the Cards business.

Key Responsibilities

  • Define and supervise the correct implementation of the cybersecurity strategy for Plard (Cards) in alignment with the Group and Cards cybersecurity strategy.

  • Ensure compliance with all applicable regulatory requirements (e.g., financial services regulation, data protection, PCI-DSS and other payment industry standards) and address the specific cybersecurity risks associated with card issuing, authorization, disputes and processing platforms.

  • Promote, support and enable the adoption of global cybersecurity controls, capabilities and defence mechanisms across Plard systems, applications, infrastructure and data.

  • Drive the implementation of Group cybersecurity minimum requirements, policies, standards and regulatory obligations within the Cards perimeter.

  • Identify, assess, monitor and report cybersecurity risks affecting Plard to senior management and relevant governance forums, ensuring appropriate mitigation plans are defined and executed.

  • Perform and oversee security risk assessments on systems, assets, applications, projects and third parties within the Cards ecosystem, enforcing timely remediation of identified vulnerabilities.

  • Oversee cybersecurity requirements in technology transformation initiatives, ensuring security-by-design and secure SDLC practices across Cards platforms (CIO, Disputes, Authorization/Stratos).

  • Lead electronic fraud risk protection activities in close coordination with Fraud Risk, Operations, Authorization and Disputes teams, ensuring strong alignment between cybersecurity and fraud prevention controls.

  • Coordinate cybersecurity incident response within the Cards perimeter, ensuring proper escalation, communication and reporting to business leadership, regulators and other relevant stakeholders.

  • Engage with internal business areas, Group cybersecurity teams, regulators, payment schemes, government agencies and external partners to ensure effective cybersecurity governance and collaboration.

  • Support leadership and business managers in fostering a strong security culture and driving appropriate security behaviours across the Cards organization.