20 часов назад
Information Security Manager (m/f/d) (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Information Security Manager (Fintech): Building automated security and compliance evidence pipelines across AWS, IAM, and the security stack with an accent on SOC 2, PCI DSS, HIPAA, DORA, and continuous control monitoring. Focus on integrating compliance checks into CI/CD, extending Vanta with custom integrations, managing audits and third-party risk, and turning regulatory requirements into engineering-ready specifications.
Location: Helsinki, Finland (hybrid)
Company
is a European fintech providing B2B payment solutions through an API-first platform, embedded finance, and white-label credit card products.
What you will do
- Build automated evidence pipelines across AWS, IAM, Wiz, Vanta, SentinelOne, Datadog, and other security systems.
- Integrate compliance checks into CI/CD to detect security and control drift early.
- Extend Vanta with custom integrations for controls not covered by default functionality.
- Own the security and compliance program covering ISO 27001, SOC 2 Type 2, PCI DSS v4.0.1, and HIPAA.
- Manage audits, control testing, risk registers, and relationships with QSAs and external auditors.
- Manage vendor and third-party risk under DORA and support incident response from the compliance perspective.
Requirements
- 3+ years of experience in security compliance.
- Ownership of at least one complete SOC 2 or PCI DSS audit cycle.
- Working knowledge of at least two of SOC 2, PCI DSS, HIPAA, and DORA in a real environment.
- Experience collaborating with technology and engineering teams.
- Experience managing external auditors or QSAs through delivery of a final report.
- Excellent written communication for engineering, audit, and executive audiences.
Nice to have
- Experience in a regulated fintech, EMI, PSP, or bank.
- CISSP, CISA, CISM, or ISO 27001 Lead Auditor/Implementer certification.
- Experience with LLM-based tooling for security and compliance workflows.
Culture & Benefits
- Direct access to the CISO, substantial autonomy, and influence over security strategy.
- Flexible work options with hybrid collaboration in Helsinki.
- Choice of Windows or Mac operating system.
- Flat hierarchy, transparent communication, and a knowledge-sharing environment.
- Company card with a monthly allowance for lunches, coffee, and team activities.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →