Chief Information Security Officer - CISO (based in Crete)

Heraklion International Airport· General Management Division
Apply Now ↗
📍 Heraklion, Crete, GreeceFull time

About this role

International Airport of Heraklion, Crete S.A. is currently looking for a:

Chief Information Security Officer – CISO (based in Crete)

Responsibilities

  • Develops, implements, and maintains the Airport’s information security governance framework, policies, and procedures
  • Establishes and continuously improves an ISO/IEC 27001-aligned Information Security Management System (ISMS)
  • Leads security governance initiatives and promotes a strong security culture across the organization
  • Coordinates management reviews, governance reporting, audits, and certification activities
  • Maintains the information security risk management methodology and risk register
  • Facilitates risk assessments across business functions and critical systems
  • Monitors mitigation plans and escalates significant residual risks
  • Supports operational resilience and business continuity initiatives
  • Leads cybersecurity governance activities supporting aerodrome certification and continuous compliance with EASA requirements, particularly Part-IS
  • Coordinates inspections, compliance reviews, evidence submissions, and closure of findings
  • Ensures effective alignment between cybersecurity, aviation safety, and aviation security requirements
  • Serves as the primary point of contact for information security matters with the Hellenic Civil Aviation Authority (HCAA), National Cybersecurity Authority, EASA, and other relevant authorities
  • Monitors compliance with NIS2, GDPR security obligations, aviation regulations, and contractual commitments
  • Maintains the information-security obligations register and monitors relevant regulatory developments
  • Coordinates regulatory submissions, audits, inspections, and follow-up actions
  • Supports supplier due diligence and third-party security risk management

Requirements

  • Bachelor’s degree in IT, Business Administration, Law, or a related discipline, or equivalent relevant professional experience
  • Master’s degree in IT, Cybersecurity, Risk Management or related discipline will be considered a plus
  • Minimum 5 years of experience in Information Security Governance, Risk & Compliance (GRC), cybersecurity risk management, compliance, or information systems auditing
  • Professional certifications (e.g. CISSP, CISM, CRISC) will be considered an asset
  • Demonstrated experience establishing, maintaining, or improving an ISO/IEC 27001-based ISMS
  • Experience managing audits, regulatory assessments, and compliance programs
  • Strong understanding of NIS2, GDPR security requirements and enterprise security architecture across IT, Cloud, OT/ICS environments
  • Experience within aviation, transport, critical infrastructure, or another highly regulated sector
  • Familiarity with EASA Part-IS requirements

Competencies

  • Strategic thinking and business awareness
  • Excellent stakeholder management and communication skills
  • Strong analytical and problem-solving capability
  • Ability to translate complex technical risks into business decisions
  • High integrity, independence, and discretion when handling sensitive or confidential information

Frequently Asked Questions

Is the salary disclosed for the Chief Information Security Officer - CISO (based in Crete) position at Heraklion International Airport?
The salary for this Chief Information Security Officer - CISO (based in Crete) role at Heraklion International Airport is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Chief Information Security Officer - CISO (based in Crete) position at Heraklion International Airport located?
This Chief Information Security Officer - CISO (based in Crete) role at Heraklion International Airport is based in Heraklion, Crete, Greece. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Chief Information Security Officer - CISO (based in Crete) role at Heraklion International Airport full-time or part-time?
This is listed as a Full time position. It is posted as a Chief Information Security Officer - CISO (based in Crete) role in the General Management Division department at Heraklion International Airport.
Which team or department does the Chief Information Security Officer - CISO (based in Crete) at Heraklion International Airport belong to?
This Chief Information Security Officer - CISO (based in Crete) position is part of the General Management Division department at Heraklion International Airport. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Chief Information Security Officer - CISO (based in Crete) position at Heraklion International Airport?
Click the "Apply Now" button on this page. You will be redirected to Heraklion International Airport's official application portal hosted on workable where you can submit your application directly.
When was the Chief Information Security Officer - CISO (based in Crete) job at Heraklion International Airport posted?
This Chief Information Security Officer - CISO (based in Crete) position at Heraklion International Airport was posted on Oct 8, 2026. Apply as soon as possible — early applications are often reviewed first.
Chief Information Security Officer - CISO (based in Crete)
Heraklion International Airport
Apply for this role ↗

You'll be redirected to Heraklion International Airport's official application page on workable.