Spain’s largest companies tend to keep their security leaders for a very long time. One of the six below has been Global CISO of the same company since 2007. Another has spent 24 years at Spain’s national telecom operator, and a third has worked inside the same utility group since 2001, starting as an analyst on systems for nuclear power plants. Several did not start in security at all, coming instead from IT strategy, software quality assurance, and network engineering. Today they protect a global bank, an energy company, a utility, a telecom technology business, a banking group’s technology arm, and an international infrastructure group.
Hazel DÃez Castaño – Global CISO, Banco Santander
Hazel DÃez Castaño began her career at Deloitte in Madrid, spending nearly five years as a consultant. She joined Aviva Spain in 2006 as information security manager, then led IT and regulatory risk. At Aviva’s European level she spent more than four years heading business continuity, disaster recovery, and crisis management, followed by nearly three years leading security consultancy, architecture, and design across Madrid and London. Her experience spans all three lines of defense. After a year as Global CISO of Dufry Group, she joined Santander Global Tech as CISO in 2018. At Santander she went on to lead CISO central services and IT SOX, then global cyber governance, risk, and compliance. She has served as the bank’s Global CISO since June 2023.
Javier GarcÃa Quintela – CISO, Repsol
Javier GarcÃa Quintela is a communications engineer by training. He started in Unix systems sales support at Hewlett-Packard, then spent nearly a decade as a strategic IT consultant and manager at Arthur Andersen. After three years managing telecom and oil and gas client portfolios at Indra, he joined Repsol in 2007 as director of IT strategy and architecture. Over the next 13 years he led IT strategy, architecture, procurement, global solutions and services, and global services strategy before becoming CISO in June 2020. He sits on the External Advisory Committee of UC Berkeley’s Center for Long-Term Cybersecurity and is a member of the Team8 CISO Village.
Rafa Ceres – Global CISO, Iberdrola
Rafa Ceres began as a programmer in Seville and then developed J2EE applications at Indra. He joined Iberdrola’s engineering and construction business in 2001 as an analyst. He later managed projects including a fuel cycle management system for nuclear power plants and document management for power station construction. He moved into security in 2014 as a cybersecurity analyst and local incident commander, then became the group’s cyber incident response manager, reporting to the Global CISO. After leading global cyber threat intelligence and response and then the Global Cybersecurity Office, Ceres was named Global CISO in November 2023. He describes security as a service and an enabler, never an end in itself, and argues that complexity is a vulnerability. In his view, a practical control that works beats a perfect one that never happens.
Leonardo Amor – CISO, Telefónica Tech
Leonardo Amor joined Telefónica in 2002 after working as a PKI and electronic signature consultant. As a security project manager he built the company’s anti-phishing service from scratch, launching it in 2004 and making it fully operational in 2005, and helped develop its clean email and anti-DDoS services. He went on to develop security services sold through up to 25 of Telefónica’s local operators. From 2014 to 2017 he served as head of security for Telefónica Business Solutions, the global B2B unit, protecting 2,000 servers, 50 offices in 24 countries, and a Tier-1 internet backbone with 1,000 points of presence. After leading security for Telefónica’s chief data and digital units, Amor became CISO of Telefónica Tech in January 2020. He has now spent 24 years at Telefónica.
MarÃa Guillamón Bagán – CISO, CaixaBank Tech
MarÃa Guillamón Bagán started as a network engineer at ANCERT and spent the next seven years as a network security engineer at SCC and everis. There she worked across firewalls, intrusion prevention, proxies, VPNs, and SIEM platforms from Cisco, Check Point, Juniper, and Palo Alto. She joined CaixaBank’s information security team in Barcelona in 2014 and spent more than 11 years there. In June 2026 CaixaBank created a new cybersecurity unit within CaixaBank Tech, its technology subsidiary, to build defense and digital resilience into every phase of technology projects. Guillamón was appointed its CISO, working in coordination with the CaixaBank Group CISO. She holds certifications from Cisco, Check Point, Palo Alto Networks, and Juniper.
Juan Cobo Páez – Global CISO, Ferrovial
Juan Cobo Páez has been Global CISO of Ferrovial since May 2007, more than 19 years in the role. He started as a software developer and IT manager at V Group, then worked as a software analyst at Indra and a software engineering consultant at Informática El Corte Inglés and Telefónica. There he defined and deployed IT control and quality assurance frameworks. He joined Ferrovial in 2005 as head of IT quality assurance and security, designing its IT control program, security governance, and data privacy compliance. As Global CISO he holds overall responsibility for the strategy, governance, and delivery of the company’s global information security and cybersecurity programs. He holds CISA, CISM, CRISC, and CDPSE certifications and has completed management programs at IESE and ESADE business schools.
Careers Measured in Decades
Tenure is the defining feature of this group. Cobo has held the Global CISO title at Ferrovial for 19 years, Amor has spent 24 at Telefónica, and Ceres has worked inside Iberdrola’s group for a quarter century. GarcÃa Quintela led IT at Repsol for 13 years before taking over its security, and Guillamón spent more than a decade at CaixaBank before being asked to build a new unit. DÃez Castaño is the exception that proves the rule, moving between Deloitte, Aviva, and Dufry before settling at Santander, where she has now spent nearly seven years. These leaders know their companies from the inside, and in large, regulated Spanish institutions, that knowledge is the job.
Discover more CISOs securing their organizations:
- From Visby to Gothenburg: Sweden’s CISOs to Watch
- From Audit Rooms to Smart Cards: France’s CISOs to Watch
- Beyond the Ringstrasse: Austria’s Cybersecurity Leaders to Watch
- From the Carabinieri to the Grid: Italy’s Cybersecurity Leaders to Watch
- Beyond the Silicon Docks: Ireland’s Cybersecurity Leaders to Watch
John Kevin Hao is a news and feature writer covering cybersecurity, technology, and business targeted for professional audiences.

