Live opening · Posted 7 hours ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
International Airport of Heraklion, Crete S.A. is currently looking for a:
Chief Information Security Officer – CISO (based in Crete)
Responsibilities
Develops, implements, and maintains the Airport’s information security governance framework, policies, and procedures
Establishes and continuously improves an ISO/IEC 27001-aligned Information Security Management System (ISMS)
Leads security governance initiatives and promotes a strong security culture across the organization
Coordinates management reviews, governance reporting, audits, and certification activities
Maintains the information security risk management methodology and risk register
Facilitates risk assessments across business functions and critical systems
Monitors mitigation plans and escalates significant residual risks
Supports operational resilience and business continuity initiatives
Leads cybersecurity governance activities supporting aerodrome certification and continuous compliance with EASA requirements, particularly Part-IS
Coordinates inspections, compliance reviews, evidence submissions, and closure of findings
Ensures effective alignment between cybersecurity, aviation safety, and aviation security requirements
Serves as the primary point of contact for information security matters with the Hellenic Civil Aviation Authority (HCAA), National Cybersecurity Authority, EASA, and other relevant authorities
Monitors compliance with NIS2, GDPR security obligations, aviation regulations, and contractual commitments
Maintains the information-security obligations register and monitors relevant regulatory developments
Coordinates regulatory submissions, audits, inspections, and follow-up actions
Supports supplier due diligence and third-party security risk management
Requirements
Bachelor’s degree in IT, Business Administration, Law, or a related discipline, or equivalent relevant professional experience
Master’s degree in IT, Cybersecurity, Risk Management or related discipline will be considered a plus
Minimum 5 years of experience in Information Security Governance, Risk & Compliance (GRC), cybersecurity risk management, compliance, or information systems auditing
Professional certifications (e.g. CISSP, CISM, CRISC) will be considered an asset
Demonstrated experience establishing, maintaining, or improving an ISO/IEC 27001-based ISMS
Experience managing audits, regulatory assessments, and compliance programs
Strong understanding of NIS2, GDPR security requirements and enterprise security architecture across IT, Cloud, OT/ICS environments
Experience within aviation, transport, critical infrastructure, or another highly regulated sector
Familiarity with EASA Part-IS requirements
Competencies
Strategic thinking and business awareness
Excellent stakeholder management and communication skills
Strong analytical and problem-solving capability
Ability to translate complex technical risks into business decisions
High integrity, independence, and discretion when handling sensitive or confidential information
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.