← Back to job listings
HI
Chief Information Security Officer - CISO (based in Crete)
Heraklion International Airport · Heraklion, Crete, Greece
About The Role
International Airport of Heraklion, Crete S.A. is currently looking for a:
Chief Information Security Officer – CISO (based in Crete)
Responsibilities
- Develops, implements, and maintains the Airport’s information security governance framework, policies, and procedures
- Establishes and continuously improves an ISO/IEC 27001-aligned Information Security Management System (ISMS)
- Leads security governance initiatives and promotes a strong security culture across the organization
- Coordinates management reviews, governance reporting, audits, and certification activities
- Maintains the information security risk management methodology and risk register
- Facilitates risk assessments across business functions and critical systems
- Monitors mitigation plans and escalates significant residual risks
- Supports operational resilience and business continuity initiatives
- Leads cybersecurity governance activities supporting aerodrome certification and continuous compliance with EASA requirements, particularly Part-IS
- Coordinates inspections, compliance reviews, evidence submissions, and closure of findings
- Ensures effective alignment between cybersecurity, aviation safety, and aviation security requirements
- Serves as the primary point of contact for information security matters with the Hellenic Civil Aviation Authority (HCAA), National Cybersecurity Authority, EASA, and other relevant authorities
- Monitors compliance with NIS2, GDPR security obligations, aviation regulations, and contractual commitments
- Maintains the information-security obligations register and monitors relevant regulatory developments
- Coordinates regulatory submissions, audits, inspections, and follow-up actions
- Supports supplier due diligence and third-party security risk management
Requirements
- Bachelor’s degree in IT, Business Administration, Law, or a related discipline, or equivalent relevant professional experience
- Master’s degree in IT, Cybersecurity, Risk Management or related discipline will be considered a plus
- Minimum 5 years of experience in Information Security Governance, Risk & Compliance (GRC), cybersecurity risk management, compliance, or information systems auditing
- Professional certifications (e.g. CISSP, CISM, CRISC) will be considered an asset
- Demonstrated experience establishing, maintaining, or improving an ISO/IEC 27001-based ISMS
- Experience managing audits, regulatory assessments, and compliance programs
- Strong understanding of NIS2, GDPR security requirements and enterprise security architecture across IT, Cloud, OT/ICS environments
- Experience within aviation, transport, critical infrastructure, or another highly regulated sector
- Familiarity with EASA Part-IS requirements
Competencies
- Strategic thinking and business awareness
- Excellent stakeholder management and communication skills
- Strong analytical and problem-solving capability
- Ability to translate complex technical risks into business decisions
- High integrity, independence, and discretion when handling sensitive or confidential information
Similar roles you might like
See all →US
Senior Security Engineer
Uni Systems
Salary not disclosedPosted 1 day ago
CH
Identity & Security Engineer
Cepal Hellas Financial Services S.A.
Salary not disclosedPosted 4 days ago
PT
Senior Security Engineer – M365 E5 Security, Compliance & Data Protection
PwC Technology Consulting Services PC
Salary not disclosedPosted 15 days ago
N
Network Security Engineer L3
Neurosoft
Salary not disclosedPosted 15 days ago
N
Service Delivery Associate (Cyber Defense Services)
Neurosoft
Salary not disclosedPosted 15 days ago
R
Security Engineer
RE18
€40,000 – 55,000/yrPosted 16 days ago
O
Senior Security Engineer (Cyber Defense)
OpenBet
Salary not disclosedPosted 18 days ago
GG
Chief Information Security Officer (CISO)
Gelasakis Group of companies
Salary not disclosedPosted 18 days ago
This is an external listing. JobSpring does not represent or verify the employer. Report this listing