Information Security

Álvaro Torres

Information Security Manager · ISO/IEC 27001 Senior Lead Implementer · ISMS, Risk Management & GRC

Convierto la seguridad de la información en una ventaja competitiva. Lideré la certificación ISO/IEC 27001:2022 end-to-end de una empresa SaaS como único recurso de seguridad. Ahora ayudo a otras organizaciones a conseguirlo.

Álvaro Torres Blanco, Information Security Manager based in Madrid
Available · Remote
📍 Madrid, Spain
20+
Years in tech and security
9+
Years in Information Security
3
Languages spoken

Security strategy
meets business vision

I specialize in ISO/IEC 27001 and information risk management, leading security strategies aligned with business objectives. From ISMS design to certification roadmaps, I bridge the gap between technical security and corporate governance.

I also work independently as a vCISO and ISO 27001 consultant for organisations that need to build their security function from scratch or prepare for certification without hiring a full in-house team.

I also integrate generative AI into my day-to-day security work as a productivity multiplier, not as a buzzword.

Basado en Madrid con doble nacionalidad española/venezolana. Disponible de forma inmediata para posiciones remotas.

ISO/IEC 27001
ISO/IEC 27005
Risk Management
ISMS
GRC
vCISO Services
Gap Analysis
Vendor Risk Management
Internal Auditing
Security Awareness
Cloud Security
NIS2

Three ways
to work together

Whether you're starting from a blank page or preparing for an external audit, I plug in as the security function you need — without the cost of a full team.

02

Fractional CISO

Ongoing security leadership for organisations that need expertise but not a full-time hire.

  • Security strategy & roadmap
  • Vendor & customer assessments
  • Board-level reporting
  • Incident response oversight
For growing companies
03

Risk Assessment

Targeted information-risk engagements when you need clarity, not a full programme.

  • Asset & threat inventory
  • Quantified risk register
  • Treatment plan with owners
  • Executive readout
For investors, due diligence & commercial operations

Continuous learning
as a practice

PECB ISO/IEC 27001 Senior Lead Implementer badge
Certified
ISO/IEC 27001 Senior Lead Implementer
PECB · Verify on Credly →
April 2026
In progress
ISO/IEC 27005 Lead Risk Manager
PECB
Expected · 2026

A career built on
trust and resilience

Sep 2022 — PresentRemoto (España)
Information Security Manager
Voovio Technologies Actual SaaS
  • Led end-to-end ISO/IEC 27001:2022 certification as the sole security resource (achieved January 2026), including current-state assessment, certification roadmap and policy framework
  • Security policies, cloud security, awareness and risk management, reporting directly to the CEO
  • Management of customer security assessments and security questionnaires related to the company product
Nov 2023 — Dic 2025Remoto (Chile)
Freelance vCISO & ISO 27001 Consultant
Inside Security Consultoría de Ciberseguridad
  • ISO/IEC 27001 gap analysis, compliance audits and virtual CISO support for multiple clients
  • Security awareness program development: content, guidance and policies aligned with best practices
  • Technical vulnerability management and security documentation for client engagements
Jul 2020 — Sep 2022Madrid, España
Tier 2 Team Lead
Excem Technologies Servicios TI
  • Management of Tier 2 support team (3 engineers) with KPI oversight and performance reviews
  • Management of the National Security Scheme for the company and clients; 24/7 incident resolution
  • Training programs for internal Tier 1 staff and customer technical teams
Ago 2016 — Jun 2020Madrid, España
Customer Support Engineer
Excem Technologies Servicios TI
  • Tier 2 support for Lawful Interception platform (Verint/Cognyte) for telecom operators and Law Enforcement Agencies (police, military, intelligence)
  • Technical incident resolution and customer escalation handling with 24/7 on-call rotation
Feb 2016 — Jul 2016Madrid, España
Control and Compliance Consultant
Novanotio Outsourcing BBVA
  • Vulnerability remediation management from the Security Technical Verification department reports for BBVA Madrid
Mar 2013 — Dic 2015Caracas, Venezuela
Senior Information Security Compliance Consultant
Bancaribe Banca
  • Security policy design and implementation for Windows Server (Domain Controllers, Member Servers) and workstations
  • Automated compliance validation using PowerShell scripts and checklists for Windows Server and SQL Server
  • Vulnerability remediation from internal, external and Venezuelan banking regulatory audits
Jul 2012 — Nov 2012Madrid, España
Systems Administrator
Redcom Cibernético Outsourcing Repsol
  • Windows Server administration and monitoring for Repsol Spain and worldwide locations
  • VMware vSphere virtual infrastructure support and maintenance

Earlier experience (2005–2012) available on request →

Speaking the same
language as your team

Spanish
Native
English
Advanced
Portuguese
Basic

Request my CV
by email

Envío mi CV a petición, adaptado al rol o proyecto correspondiente. Disponible en inglés y español.

Open to opportunities

Need ISO 27001 expertise
or a virtual CISO?

From ISO 27001 implementation to vCISO services, I help organizations build security that works for the business. Available immediately for remote positions.

Get in touch →

Let's build something
secure together

Open to remote opportunities in information security management, consulting, and vCISO roles. I bring strategic mindset and hands-on expertise to every engagement.

Send a message

✕ No se pudo enviar el mensaje. Revisa el formulario e intenta de nuevo.

✓ Message sent! I'll be in touch shortly.

Protected by reCAPTCHA · Privacy · Terms