Sobre esta vaga de Chief Information Security Officer - CISO (based in Crete) na ΟΜΙΛΟΣ ΓΕΚ ΤΕΡΝΑ / GEK TERNA GROUP
International Airport of Heraklion, Crete S.A. is currently looking for a:
Chief Information Security Officer – CISO (based in Crete)
Responsibilities
- Develops, implements, and maintains the Airport’s information security governance framework, policies, and procedures
- Establishes and continuously improves an ISO/IEC 27001-aligned Information Security Management System (ISMS)
- Leads security governance initiatives and promotes a strong security culture across the organization
- Coordinates management reviews, governance reporting, audits, and certification activities
- Maintains the information security risk management methodology and risk register
- Facilitates risk assessments across business functions and critical systems
- Monitors mitigation plans and escalates significant residual risks
- Supports operational resilience and business continuity initiatives
- Leads cybersecurity governance activities supporting aerodrome certification and continuous compliance with EASA requirements, particularly Part-IS
- Coordinates inspections, compliance reviews, evidence submissions, and closure of findings
- Ensures effective alignment between cybersecurity, aviation safety, and aviation security requirements
- Serves as the primary point of contact for information security matters with the Hellenic Civil Aviation Authority (HCAA), National Cybersecurity Authority, EASA, and other relevant authorities
- Monitors compliance with NIS2, GDPR security obligations, aviation regulations, and contractual commitments
- Maintains the information-security obligations register and monitors relevant regulatory developments
- Coordinates regulatory submissions, audits, inspections, and follow-up actions
- Supports supplier due diligence and third-party security risk management
Requirements
- Bachelor’s degree in IT, Business Administration, Law, or a related discipline, or equivalent relevant professional experience
- Master’s degree in IT, Cybersecurity, Risk Management or related discipline will be considered a plus
- Minimum 5 years of experience in Information Security Governance, Risk & Compliance (GRC), cybersecurity risk management, compliance, or information systems auditing
- Professional certifications (e.g. CISSP, CISM, CRISC) will be considered an asset
- Demonstrated experience establishing, maintaining, or improving an ISO/IEC 27001-based ISMS
- Experience managing audits, regulatory assessments, and compliance programs
- Strong understanding of NIS2, GDPR security requirements and enterprise security architecture across IT, Cloud, OT/ICS environments
- Experience within aviation, transport, critical infrastructure, or another highly regulated sector
- Familiarity with EASA Part-IS requirements
Competencies
- Strategic thinking and business awareness
- Excellent stakeholder management and communication skills
- Strong analytical and problem-solving capability
- Ability to translate complex technical risks into business decisions
- High integrity, independence, and discretion when handling sensitive or confidential information
