Overview

Information Security Officer Jobs in Dublin, County Dublin, Ireland at CNP Santander Insurance

Title: Information Security Officer

Company: CNP Santander Insurance

Location: Dublin, County Dublin, Ireland

Information Security is a key priority for CNPSI. We have built a strong governance framework and have an Information Security Strategy for the period 2026-2028. As a financial entity regulated by the CBI, compliance with DORA is an important requirement.

The Information Security Officer for CNPSI leads the Information Security Function. Reporting directly to the Chief Information Officer, the role is responsible for the design and delivery of day-to-day security controls and implementation of the security strategy. This person will work closely with the CIO and external security consultants to ensure that CNPSI maintains a strong security posture across both its internal systems and supply chain.

Key Responsibilities:

  • Information Security SME: provide technical security advice and risk-based recommendations across the business.
  • Define and evolve the Information Security (IS) strategy, roadmap and operating model with the CIO; lead delivery of IS programmes.
  • Design, implement and continuously improve security controls, standards and procedures.
  • Ensure compliance and alignment with internal policy, regulatory expectations and CNP group requirements.
  • Own security policy and awareness content; promote understanding and adoption across stakeholders.
  • Provide regular reporting on security posture, key initiatives and emerging risks to senior stakeholders, CRO and group forums.
  • Define and track IS KPIs/KRIs; analyse trends and drive measurable improvement actions.
  • Oversee remediation for security events/incidents, assessments and audits; verify closure and effectiveness.
  • Monitor threat intelligence and vulnerability information; assess impact, share insight and coordinate response. Maintain visibility of security posture and key risks across critical suppliers and the wider supply chain.
  • Direct and support managed security service providers and operations teams on security priorities and issues.
  • Challenge technology changes and vendor proposals to ensure security-by-design, compliance with DORA and proportionate controls.
  • Lead security incident management and problem management; drive root-cause remediation and prevention.
  • Assess and recommend security technologies and best practices to strengthen capabilities and resilience.
  • Coordinate with CNP group CISOs on security initiatives, reporting and shared control improvements.
  • Provide ad hoc security support and input to business initiatives as required.
  • Support personal data protection in collaboration with the DPO (security controls, incidents and risk treatment).
  • Set third-party security requirements with Vendor Management; advise on supplier assessments and risk decisions.
  • Contribute to security monitoring with CNP and external bodies (threats, vulnerabilities, sharing and coordinated response).

Qualifications/Competencies:

  • 3rd level qualification
  • Information Security related qualifications
  • Extensive years of solid experience in either IT analysis/design, information security, or control and compliance
  • Able to operate and articulate effectively in a matrix environment
  • Strong vendor management skills

Competencies:

Strong understanding of:

  • Cyber security for Cloud technologies; particularly Azure, ADFS, SAML, Microsoft Stack including Intune, O365, AIP etc.
  • Cyber security for WAN/LAN.
  • Vulnerability and Pen test reports and ability to analyse and evaluate.
  • Cyber risk management.
  • Security awareness concepts.

  • Excellent communication skills – able to communicate effectively with colleagues at all levels. Particularly adept at visual communications, PowerPoint slides etc for the purpose of developing security awareness content
  • Strong, proven negotiation skills and ability to influence others particularly when working with external vendors.
  • Continually seeking to improve work processes in line with best practice
  • Ability to prioritise tasks, meet deadlines and deal with changing priorities
  • Well organised and self-motivated
  • Excellent attention to detail
  • Ambition to exceed expectations
  • Experience of working within a regulated sector and an understanding of the implications of the same on Information Security.

Desirable but not essential for the role:

  • Experience of working in the insurance sector, preferably in a cross-border business environment
  • Experience in working in a multilingual, multicultural environment
  • Experience with ISO27001, NIST, CyFun and/or CIS IG3

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.