Jonathan Signorino

Chief Information Security Officer (CISO) @Powens Group | Building security programs that enable regulated open banking and fintech across Europe & LATAM | Security Engineering Manager · Senior Security Engineer

Barcelona, Catalonia, Spain

About

I build security functions from zero (strategy, teams, governance, and the roadmap to make them mature) in some of the most heavily regulated environments in tech. As Group CISO at Powens Group, an open banking provider operating across Europe and Latin America, I hold board-level responsibility for information security across every country we operate in. I designed and launched the group's entire security program from the ground up: strategy, governance, risk management, team structure, and a multi-phase maturity roadmap aligned with PSD2, ISO 27001, GDPR, DORA, NIST, and local regulations, all tied to the company's growth objectives. My foundation is technical, and I've kept it that way. Over 10+ years across fintech, banking, logistics, and enterprise, I've led cloud security architecture and engineering across AWS, Azure, and GCP, built and managed cross-functional teams, and delivered programs spanning Cloud Security, IAM, Incident Response, Offensive Security, and Regulatory Compliance. What I do best: translate complex technical risk into clear business decisions, and stay hands-on no matter the title on the door. I believe security should enable the business, not constrain it. Building the frameworks, teams, and cultures that turn security into a strategic advantage is what drives my work. Core expertise: Cloud Security (AWS, Azure, GCP, Kubernetes, CSPM/CNAPP) · Security Program Design · GRC · ISO 27001 · GDPR · PSD2 · DORA · NIST CSF · CIS Benchmarks · Incident Response · IAM · Security Architecture · Executive Reporting Certifications: AWS Security Specialty · KCNA · HashiCorp Terraform · Azure Security Engineer · Microsoft Security Administrator · ISO 27001 Internal Auditor (Applus+) · API Security Architect · Cisco CCENT · DevSecOps Engineer · ISC2 (CISO Leadership, Risk Management, Security Engineering Operations, Incident Management, AI for Cybersecurity) Languages: English · Spanish (native) · Italian

Experience

  • Chief Information Security Officer (CISO) at Powens Group
    Sep 2025 - Present · 11 mos

    CISO at Powens Group, a PSD2-regulated open banking provider operating across Europe and Latin America. I lead the information security program end-to-end, having built the function from the ground up in a fast-moving fintech environment where security, compliance, and product velocity must coexist. What I've built so far: a full security program structured around the NIST Cybersecurity Framework and six pillars (governance, risk management, defense-in-depth, threat operations, incident response, and continuous improvement), a GRC layer that achieved ISO 27001:2022 certification, and DORA and GDPR alignment across multiple jurisdictions. I defined the strategy, team structure, and a multi-phase maturity roadmap tied directly to the company's growth. My approach combines technical depth with strategic leadership. I stay hands-on across API and cloud security, IAM, PKI infrastructure, DevSecOps, and PSD2/FAPI compliance, while owning risk management, security policy, third-party risk, and regulatory compliance across jurisdictions. I lead a cross-functional security team and work closely with Engineering, Product, Compliance, and Executive leadership, so every security decision is grounded in business reality. Beyond the technical and governance work, I invest heavily in security culture, positioning security as a trusted partner rather than a bottleneck. In a company where trust is the core product, that mindset is not optional. Security Program Design · ISO 27001:2022 · DORA · GDPR · PSD2 / Open Banking · NIST CSF · Cloud Security · IAM · PKI · DevSecOps · Threat Operations · Incident Response · GRC · Risk Management · Security Awareness

  • Stuart (4 yrs)
    • Security & IT Engineering Manager
      Jun 2025 - Sep 2025 · 4 mos

      Led the Security and IT Engineering functions at Stuart, serving as the organization's primary reference point for all matters related to information security and internal IT operations. Security Leadership: Head of Stuart's Security Team, owning strategy and execution across Cloud Security, Kubernetes Security, Security Architecture, Offensive & Defensive Security, and Governance. Designed and implemented a comprehensive, risk-driven security program aligned with business goals and resource constraints. Led framework adoption and audit and certification processes (e.g., ISO 27001), driving remediation plans and security maturity initiatives. Managed security tooling (SIEM, CNAPP, EDR, and more), third-party assessments, awareness programs, and executive reporting. Owned budget management, team development, and cross-functional alignment with Engineering, Product, and Legal teams. IT Engineering Management: Led the IT Engineering team, managing a combined team of 8 direct reports across Security and IT. Oversaw IT infrastructure, asset lifecycle management, endpoint security, MDM, IAM, and company-wide software and systems. Drove process improvement, compliance readiness (e.g., for financial audits), and user experience optimization across global offices. Created synergies between IT and Security to increase efficiency, reduce risk, and support business growth through secure, reliable systems. A hands-on, technically skilled manager who fostered a culture of accountability, collaboration, and continuous improvement, delivering strategic value across both domains.

    • Security Engineering Manager
      Jul 2023 - Jun 2025 · 2 yrs

      Head of Stuart's security team, serving as the primary security leader and reference for the entire organization. Responsible for creating, designing, and executing strategies across various domains, including Cloud Security, Kubernetes Security, Defensive Security, Security Architecture, Offensive Security, Security Governance, and IT Security. A hands-on manager with deep technical expertise, actively contributing to team projects while fostering a collaborative environment. Leading multiple security disciplines within the team and reporting directly to the CTO, I oversee the implementation of security frameworks, audit responses, certification renewals, budget management, and the professional development of team members. Charged with designing and executing the company's comprehensive security program, I perform risk analyses, propose tailored solutions, and execute initiatives that align with organizational needs and available resources.

    • Senior Cyber Security Engineer
      Jul 2022 - Sep 2023 · 1 yr 3 mos

      As a Senior Security Engineer, I was entrusted with leading multiple critical domains within the security team, including Offensive Security, Cloud Security, and Security Architecture. This role involved driving strategic initiatives, overseeing the design and implementation of security frameworks, and ensuring the alignment of security practices with business goals. Key Achievements: Designed and delivered secure cloud architectures for AWS, Azure, and hybrid environments, ensuring the protection of critical assets, and developed multi-cloud security roadmaps to mitigate risks proactively. Implemented robust security strategies and policies, enhancing the security of infrastructure, applications, and data while achieving compliance with industry standards like ISO 27001, PCI DSS, and NIST. Integrated security into development workflows by driving the successful adoption of DevSecOps across teams and fostering cross-functional collaboration. Built and mentored a high-performing security team, aligning objectives with organizational goals, and delivered a company-wide security awareness program to foster a security-first culture. Enhanced infrastructure and network security with advanced threat detection, system hardening, and deploying cutting-edge security tools like SIEM, SOAR, and vulnerability management solutions. Led successful incident response efforts, managing critical investigations and forensic analysis to resolve threats swiftly. Optimized security investments, managing budgets, vendor relationships, and procurement processes effectively. Provided strategic recommendations to leadership, addressing emerging security challenges and enabling secure growth.

  • Ualá (1 yr 6 mos)
    • Cloud Security Leader
      May 2021 - Oct 2021 · 6 mos

      Leader of the Cloud Security team within Ualá's Information Security department, driving secure architecture and innovative solutions for business-critical projects in agile environments. Key responsibilities include: Architecting secure Cloud Native environments on AWS with a focus on serverless and microservices-based architectures. Collaborating with cross-functional technology teams to ensure security is embedded into project designs and implementations. Implementing security projects and tools, including vendor management, proof of concept coordination, and budget oversight. Developing and executing the Offensive Security strategy, encompassing cloud vulnerability analysis, penetration testing, code security, container security, and AWS security. Leading the DevSecOps strategy, integrating security into development pipelines and fostering a culture of secure software development. Expertise in AWS services (e.g., S3, EC2, CloudWatch, VPC, Route53, KMS, Security Hub, Lambda), infrastructure security, and network security. Skilled in compliance management and governance, adhering to frameworks such as CIS, PCI DSS, ISO 27001, ISO 27032, and NIST CSF. Proficient with Infrastructure as Code (Terraform), version control (GitHub/Git), CI/CD pipelines (GitHub Actions), and security platforms (Auth0, Okta, Netskope, Splunk). A hands-on leader committed to strengthening Ualá's security posture through innovation, collaboration, and technical excellence.

    • Cloud Security Architect
      Jan 2021 - May 2021 · 5 mos

    • Senior Cyber Security Analyst
      May 2020 - Jan 2021 · 9 mos

      Specialized in securing full cloud architectures and implementing security projects within the Information Security area while embedding cybersecurity best practices into organizational initiatives." Key responsibilities and achievements include: AWS: Securing AWS environments, including services such as S3, EC2, CloudWatch, VPC, Security Groups, Route53, KMS, Secret Manager, RDS, DynamoDB, RedShift, AWS Organizations, Cognito, Amazon Macie, Config, Security Hub, and Lambda. Infrastructure as Code (IaaC): Implementation and management of IaaC solutions using Terraform and CloudFormation. Scripting and Automation: Expertise in PowerShell, Bash, and Python to automate tasks and improve efficiency. Security Tool Implementation: Deployment and management of advanced security tools, including CASB, Cloud DLP, vulnerability analysis platforms, next-generation antivirus, and next-generation firewalls. Network and Infrastructure Security: Ensuring robust security measures across networks and cloud infrastructure. Compliance and Governance: Implementation and management of compliance frameworks such as CIS, PCI DSS, ISO 27001, ISO 27032, NIST CSF, and COBIT. Incident Response and Monitoring: Handling incident response, fraud detection, security monitoring with Splunk, incident investigation, and forensic analysis. Penetration Testing and Vulnerability Management: Resolution of penetration testing findings and strengthening the organization’s security posture. Cross-Departmental Collaboration: Providing cybersecurity insights for projects across various teams, ensuring best practices for handling personal and confidential data. Cloud-Focused Project Management: Leading and developing projects hosted entirely on cloud infrastructure with integrated security measures at every stage.

  • Senior Cyber Security Specialist at Algeiba
    Sep 2019 - May 2020 · 9 mos

    Technical Specialist in Information Security with expertise in Microsoft technologies across cloud, hybrid, and on-premises environments, delivering comprehensive solutions to enhance organizational security." Key highlights include: Extensive experience in secure identity synchronization, information protection, identity protection, and advanced threat management. Proficiency in SCCM, Intune, MDM, MAM, Conditional Access, Azure Information Protection, and Hybrid Identity Management. Skilled in Azure, Azure Active Directory, Office 365, and Microsoft 365 Security Administration, with a focus on securing user identities and data. Multi-cloud expertise, including Azure, Google Cloud Platform (GCP), and Amazon Web Services (AWS), ensuring robust security across diverse infrastructures. Proven success in implementing security solutions to protect identities, sensitive information, and critical systems.

  • Ssr. Cyber Security Specialist & Sr. Support Analyst at Bridgestone Americas
    Apr 2015 - Oct 2019 · 4 yrs 7 mos

    Sr. Technical support, performing support tasks for servers, switches and routers, analysis and monitoring of incidents with the Remedy tool. Networking support for industrial machines, Coordination of local support team. Ssr Cybersecurity Specialist managing Firewall, Proxy and VPN, Integration of Junos Pulse Secure, implementation of Cisco Umbrella, resolution of computer security incidents in regional teams depending on United States.