Head of IT & IS
hace 21 horas
Valladolid
pbHead of IT IS /b /p pOwn our IT foundations and make security a business enabler. At Mimacom (300+ people, global), we build digital products that create measurable impact—for clients who expect reliability, speed, and trust. /ppbr/ppAs bIT Information Security Manager /b, you lead our IT team and own security governance and certifications (ISO 27001, TISAX). You set direction, remove friction, and keep us audit-ready with controls that are clear, pragmatic, and easy to evidence. /ppbr/ppbYour impact /b /ppbr/ppbRole overview /b /ppTwo missions define the role: blead IT /b and brun security governance /b. You bring focus to priorities, roadmap, and decisions so the team delivers reliably—and the business moves fast with confidence. /ppThis is a leadership role first. You don’t have to be the most hands-on engineer—your team has strong depth. You do need excellent judgement, crisp communication, and the ability to challenge, decide, and drive outcomes. /ppYou report to company management and partner closely with Development, HR, Finance, and Legal. Externally, you represent Mimacom in audits and due diligence—clear answers, consistent evidence, smooth renewals. /ppbr/ppbKey responsibilities /b /ppbr/ppbIT Team Leadership /b /pulliLead and grow the IT team with clear priorities, healthy workload, and fast escalation paths. /liliOwn the IT roadmap and outcomes—make trade-offs explicit across operations, improvements, and security. /liliTranslate business needs into direction, standards, and practical options. /liliOwn budget and vendors: licences, contracts, renewals, and investment cases. /liliRaise service maturity: onboarding, self-service, runbooks, and continuous improvement. /li /ulpbr/ppbInformation Security Certification /b /pulliOwn ISO 27001 and TISAX end-to-end: scope, controls, evidence, internal audits, and external audits. /liliKeep the ISMS and TQMi system sharp: policies, risks, assets, and treatment plans. /liliDrive pragmatic risk management and business continuity—measures that work in real life. /liliLead security incident response with IT team, Legal, and the business—fast, calm, documented. /liliSupport Sales and Delivery with security questionnaires and client due diligence. /liliAssess supplier security and keep third-party risk evidence up to date. /liliBuild a security-first culture through awareness, training, and policies people actually follow. /li /ulpbr/ppbYour first 12 months /b /ppYou’ll join a team with solid technical foundations and a strong appetite for improvement. In your first year, you’ll focus on measurable upgrades to reliability, automation, and audit readiness. /pullibModernise our cloud foundation. /b Review our Azure environment, identify optimisation opportunities, and drive a roadmap that improves reliability, cost-efficiency, and security posture. /lilibScale automation-first operations. /b Keep raising the bar on scripting, templating, and standardisation—prioritising automation alongside support and platform work. /lilibIntroduce AI-enabled IT support. /b Explore and implement AI-based support models that improve employee experience and shift the team away from repetitive tasks. /lilibKeep us audit-ready. /b Own the ISO 27001 and TISAX cycle—maintain controls and evidence so renewals run smoothly without disrupting delivery. /li /ulpbr/ppbWhat you bring /b /pulli5+ years in a comparable role, with strengths across IT leadership and information security governance. /liliISO 27001 ownership (or strong co-ownership): controls, evidence, internal audits, and external audit coordination. TISAX is a strong plus. /liliVendor and budget ownership: contracts, licences, spend, renewals, and stakeholder communication. /liliSolid working understanding of infrastructure and cloud (Azure, Entra ID, Microsoft 365), plus modern delivery practices (CI/CD, SDLC)—able to evaluate trade-offs and coach decision-making (hands-on implementation not required). /liliStrong understanding of security principles, common controls, and enabling technologies. /liliExperience with client security questionnaires, RFPs, and vendor due diligence. /li /ulpbr/ppbHow you work /b /pulliExcellent English—clear with both engineers and executives. German and/or Spanish is a plus. /liliStructured and dependable: prioritise, document, deliver. /liliProactive and pragmatic: find root causes and fix them sustainably. /liliCollaborative across cultures and levels: low ego, high ownership. /liliBalance today and the long game: keep operations stable while building what’s next. /li /ulpbr/ppbWhat you get /b /pulliHigh-impact scope: you own both IT leadership and security governance with direct visibility to management. /liliModern stack and real autonomy to improve it (cloud, automation-first mindset, continuous improvement). /liliA strong, collaborative engineering culture—high trust, low bureaucracy, pragmatic decision-making. /liliRemote-first collaboration in European time zones (Spain preferred), with a global team and cross-functional partners. /liliRoom to shape how we operate: service maturity, audit readiness, and security culture. /li /ulpbr/ppbEducation certifications /b /pulliBA/MSc in Computer Science, Information Systems, Engineering, or a related field (or equivalent experience). /liliHelpful certifications (not required): ISO 27001 Lead Implementer/Lead Auditor, TISAX, CISM, CISSP. /li /ulpbr/ppAt Mimacom, we know that creative minds thrive on exciting projects. Join our team and be part of a lively community that’s all about working together, growing together, and coming up with innovative ideas and technologies! /ppbr/ppOur company is committed to fostering a diverse and inclusive workplace. We encourage candidates from all walks of life to apply, as we believe in providing equal opportunities for everyone. /p