Skip to main content
Liebherr Group

Information Security Governance Product Owner

1w

Liebherr Group

Madrid, ES · Full-time · €65,000 – €95,000

About this role

Responsible for the delivery of the governance product and services, including design, implementation and continuous improvement of the global Information Security Framework (ISF). Align the ISF with evolving business needs, regulatory environment, industry standards and customer requirements. Support delivery of the GRC platform service and customer security assurance service.

Manage the ISF by designing, implementing and maintaining policies, standards, procedures and control baselines. Maintain inventory and traceability of external obligations like NIS2, GDPR, ISO 27001 and customer requirements, integrating them into ISF components. Oversee governance operations including stakeholder coordination and approval workflows.

Collaborate with the GRC platform service owner to deliver technology enabling digital implementation of the information security framework. Support the Customer Security Assurance Service owner by delivering governance for business compliance with customer security requirements. Operate in a hybrid model in Madrid requiring at least 40% on-site time within a global organization.

Design key risk and performance indicators, dashboards and reports for management at Liebherr Group levels. Apply agile principles like iterative planning and continuous improvement to governance services. Enjoy long-term career growth in a family-owned company valuing innovation and collaboration.

Requirements

  • Bachelor’s/Master’s in Cybersecurity, Computer Science, or related field
  • 5+ years of working experience in global organizations including Governance, GRC technology and customer security assurance services delivery
  • Preferred certificates: CISSP, CRISC, CISM, GSLC
  • Excellent written and verbal communication skills in English, German is a plus
  • Proven expertise in designing and maintaining information security governance frameworks using NIST CSF, ISO/IEC 27001, IEC 62443 and regulations like NIS2, GDPR
  • Ability to lead multi-stakeholder governance processes across global business units
  • Experience in applying agile principles to delivery and evolution of governance services
  • Experience in owning and evolving enterprise GRC platforms to support compliance, risk, and governance services

Responsibilities

  • Design, implement, and maintain the Information Security Framework (ISF): policies, standards, procedures, and control baselines, aligned to business needs, regulatory obligations, industry standards, and customer requirements
  • Maintain inventory and traceability of external obligations (e.g. NIS2, GDPR, ISO/IEC 27001, IEC 62443) and customer requirements, integrating into ISF components
  • Oversee ISF governance processes, including stakeholder coordination, approval workflows, and documentation
  • Collaborate and support the GRC platform service owner to deliver technology for digital implementation of the information security framework
  • Collaborate and support the Customer Security Assurance Service owner by delivering governance to comply with customer security requirements
  • Design key risk and performance indicators, dashboards and reports on governance product and services for Liebherr Group management

Benefits

  • Secure role in a family-owned company
  • Values innovation, collaboration, and long-term career growth
  • Part of an international team