About the Role
Shine is seeking a Cyber Security Manager to shape and operate its information security and digital operational resilience framework. This role involves implementing and maturing Cyber Defence capabilities in collaboration with IT, Risk, Internal Audit, and Management, owning the defensive security technology stack and incident-readiness capability.
Responsibilities
- Own, evaluate, and continuously improve the defensive security technology stack, including EDR/XDR, DDoS protection, vulnerability management, DLP, and endpoint hardening.
- Ensure robust DDoS protection for internet-facing and payment-critical services, selecting and managing mitigation solutions and validating protection against regulatory availability expectations.
- Design, write, and maintain incident response playbooks for relevant scenarios aligned with DORA ICT incident-management expectations.
- Plan and facilitate regular tabletop exercises and simulations across technical, operational, and executive stakeholders, capturing findings and driving remediation.
- Partner with the SOC Manager to ensure tooling supports detection and response use cases mapped to MITRE ATT&CK.
- Provide technical evidence and control assurance for Information Security (GRC) functions related to PCI-DSS, DORA, and ACPR obligations.
- Manage security vendor and MSSP relationships, contribute to the security technology roadmap and budget, and translate threat intelligence into concrete control improvements.
- Report on resilience metrics and the effectiveness of deployed controls to security leadership.
Requirements
- Hands-on background in technical/engineering security operations, ideally within regulated financial services, payments, or fintech.
- Practical experience deploying and operating EDR/XDR platforms (e.g., CrowdStrike, SentinelOne, Microsoft Defender) and other core defensive tooling.
- Hands-on experience with DDoS mitigation and edge/CDN security (e.g., Cloudflare, Akamai, AWS Shield/WAF) and understanding of how to protect high-availability, customer-facing services.
- Demonstrated incident response experience, including building playbooks and running tabletop exercises.
- Working knowledge of DORA, PCI-DSS, NIS2, and MITRE ATT&CK.
- Strong stakeholder and vendor management skills, with the ability to bridge technical detail and business risk.
- Fluent English required.
- German is a strong advantage.
Skills
- EDR/XDR
- DDoS protection
- Vulnerability management
- DLP
- Endpoint hardening
- DDoS mitigation
- Edge/CDN security
- Incident response
- DORA
- PCI-DSS
- NIS2
- MITRE ATT&CK
- Stakeholder management
- Vendor management
- Threat intelligence
Location
- Berlin
- Madrid
Work Type
- Remote (two days per week)
Experience Level
- Manager
About the Company
- Shine is the financial copilot for entrepreneurs and small business owners, founded by serial entrepreneurs Rico Andersen and Martin Hegelund.
- Shine is a leading European fintech unicorn on a mission to restore the joy of running a business by ending wasted time on financial admin.
- Shine offers a connected solution for invoicing, accounting, payroll, business accounts, payments, and financing.
- Shine is now part of Cegid, a European leader in cloud software for finance and accounting, building Europe's leading financial copilot for small businesses and their accountants.
- Shine already supports more than 400,000 small businesses and as part of Cegid, reaches over one million small businesses and 15,000 accountants across Europe.
- The company is a multicultural team working from France, Germany, Denmark, and the Netherlands, contributing to a wider European network spanning Spain, Portugal, and Belgium.
- The Information Security team at Shine operates as a strategic driver, working directly with leadership to integrate resilience into the company’s core, navigating the intersection of cloud-native architecture, AI innovation, and rigorous regulatory standards like DORA and ISO 27001.
- The team partners cross-functionally with Engineering and Risk to build a scalable, high-visibility security framework that defines the future of digital operational excellence in the fintech space.
Equal Opportunity
- We follow the principle of equal treatment to consider all job applicants and do not discriminate based on their gender, sexual orientation, color, racial or ethnic origin, religion, disability, etc. as per applicable law.
