Назад
Company hidden
22 дня назад

Senior Manager Information Security (Fintech)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Kazakhstan
Вакансия из списка Hirify.GlobalВакансия из Hirify RU Global, списка компаний с восточно-европейскими корнями
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Manager Information Security (Fintech): Leading Tabby’s information security function and team across cloud security, security architecture, application security, vulnerability management, threat detection, and incident response with an accent on AWS and GCP controls, DevSecOps, and regulated fintech security. Focus on designing security programmes, investigating complex incidents, developing security tooling, and managing cross-functional security initiatives.

Location: Kazakhstan; workplace type: onsite

Company

hirify.global is a fintech company providing flexible payment solutions that help shoppers split payments online and in stores.

What you will do

  • Lead the information security function and manage a team of security engineers and analysts.
  • Conduct security architecture and technical reviews across cloud, infrastructure, and product initiatives.
  • Design and implement security controls across AWS and GCP, including IAM, CSPM, and cloud-native security.
  • Drive Secure SDLC and DevSecOps initiatives, including SAST, DAST, SCA, and container security.
  • Lead vulnerability management, penetration testing, VAPT, red and purple team engagements, and incident response.
  • Develop threat detection, SIEM use cases, security monitoring, endpoint and network security, and security tooling.

Requirements

  • Senior technical or management experience leading information security or cybersecurity functions.
  • Deep expertise in cloud security, security architecture, VAPT, application security, DevSecOps, and defensive security.
  • Strong knowledge of AWS, GCP, IAM, CSPM, SIEM, EDR/XDR, vulnerability management, and CI/CD security.
  • Experience with penetration testing, red and purple teaming, threat hunting, incident response, and threat modelling.
  • Experience in a regulated fintech or banking environment, with knowledge of CBUAE, UAE PDPL, PCI-DSS, ISO 27001, and SOC 2.
  • Proven people leadership, stakeholder management, and strategic decision-making skills.

Nice to have

  • CISSP, CISM, OSCP, or equivalent certifications.

Culture & Benefits

  • Cross-functional collaboration with Engineering, Infrastructure, Product, IT, Legal, and Compliance teams.
  • Opportunity to shape security standards, best practices, operating procedures, and programmes.
  • Full-time onsite work in Kazakhstan.

Hiring process

  • Application and review.
  • HR call followed by a technical interview.
  • Final interview and hiring decision.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →