4 дня назад
Head of Information Security (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Head of Information Security (Cybersecurity): Building and leading an information security function across application security, compliance, cloud infrastructure, and business applications with an accent on AI-assisted code reviews, ISO 27001 and SOC 2 audits, and secure Kubernetes environments. Focus on integrating security into CI/CD, securing Microsoft 365, CRM and ERP systems, managing vendor risk, and translating technical risks for engineering and executive stakeholders.
Location: Bulgaria; the role description also states that the position is based in Singapore and follows a hybrid schedule with 2 days in the office and 3 days remote. Remote work is available in locations without offices.
Company
develops an all-in-one digital education and research platform using machine intelligence and data science to improve access, efficiency, and student engagement.
What you will do
- Lead the security function across application security, compliance, infrastructure and cloud security, and business application security.
- Build and operate an AppSec program with AI-assisted code and pull-request reviews, CI/CD security checks, developer training, and secure coding practices.
- Own ISO 27001 and SOC 2 certifications, security audits, policies, controls, evidence, and future certification roadmaps.
- Secure Kubernetes infrastructure, cloud environments, sovereign cloud deployments, infrastructure-as-code, networks, and access controls.
- Protect Microsoft 365, CRM, ERP, and other business applications, including identity, access, data protection, and third-party SaaS risk.
- Represent security to leadership while working hands-on with engineering, DevOps, IT, compliance, and business application teams.
Requirements
- 8+ years of information security experience, including 3+ years in a leadership role.
- Experience leading application security programs with CI/CD-integrated tooling and modern AI-assisted code review.
- Hands-on experience successfully leading ISO 27001 and/or SOC 2 audits.
- Experience securing Microsoft 365, CRM, and ERP systems and managing vendor risk.
- Working knowledge of Kubernetes and cloud security; sovereign cloud experience is a plus.
- English resume required; English is required for the role.
Nice to have
- Experience in all-remote or hybrid international organisations.
- Sovereign cloud security experience.
Culture & Benefits
- Hybrid work in locations with offices: 2 days in-office and 3 days remote.
- Remote work in locations without offices.
- Flexible schedule, usually between 09:00/10:00 and 18:00/19:00.
- Choice of work equipment and paid leave.
- English classes through iTalki with a $130 monthly allowance, plus a €500 newborn bonus per child.
- Inclusive, equal-opportunity environment with a focus on diversity and representation.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →