5 часов назад
Security Architect (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Architect (Fintech): Designing and governing an enterprise security GRC framework for a regulated global fintech company with an accent on multi-jurisdiction compliance, regulatory resilience, and security risk management. Focus on mapping controls to ISO 27001, PCI-DSS, DORA, and NIS2, interpreting regulatory obligations, and advising C-suite stakeholders on complex security investments.
Location: Hybrid in Warsaw, Poland; Sofia, Bulgaria; or Limassol, Cyprus
Company
is a global fintech company providing CFD trading across more than 5,000 markets through a proprietary AI-powered platform.
What you will do
- Own the enterprise security governance, risk, and compliance framework, including policy hierarchy, risk registers, control ownership, and audit evidence.
- Map security controls to DORA, NIS2, ISO 27001, and PCI-DSS; identify gaps and prioritize remediation.
- Lead regulatory interpretation and obligation management across FCA, CySEC, ASIC, SCB, and SCA jurisdictions.
- Represent the company in regulatory discussions and advise the CISO, CHRO, Risk, and Compliance teams.
- Define security architecture standards, human-risk and security-awareness principles, and approve significant framework changes.
- Support third-party risk management, business continuity, crisis management, and supply-chain risk initiatives from a security perspective.
Requirements
- 8+ years of security experience with significant focus on GRC, regulatory compliance, or risk management, including enterprise-level program ownership.
- Experience designing enterprise security architectures or frameworks; regulated financial-services experience is advantageous.
- Deep knowledge of ISO 27001 and PCI-DSS, with working knowledge of DORA and NIS2 and the ability to translate regulations into controls.
- Multi-jurisdiction compliance experience; FCA or CySEC exposure is a strong advantage.
- Ability to advise and influence C-suite stakeholders on complex security and regulatory matters.
- Fluent written and spoken English required.
Nice to have
- Experience with regulatory submissions and supervisory authorities such as FCA, CySEC, ASIC, SCB, or SCA.
- Third-party risk management, DORA ICT risk, supply-chain risk, and business continuity experience.
- Security-awareness program design with measurable behavior-change outcomes.
- Experience scaling a Corporate Security function and relevant certifications such as CISSP, CISM, or CRISC.
Culture & Benefits
- Hybrid work model with location-specific benefits and perks.
- Annual leave, comprehensive health insurance, and pension benefits.
- Up to 30 additional days of remote work from anywhere in the world through the workation policy, subject to restrictions.
- Two additional paid volunteer days each year.
- Employee referral rewards and opportunities to work in a rapidly expanding fintech environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →