сегодня

information security engineer in fintech

ориентир по рынку
вакансия зп не указана
в среднем 403 605 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовься к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузи резюме

Рекламный баннер: ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ"
О рекламодателе
ОБЩЕСТВО С ОГРАНИЧЕННОЙ ОТВЕТСТВЕННОСТЬЮ "ЦЕНТР НАЦИОНАЛЬНЫХ ИНТЕЛЛЕКТУАЛЬНЫХ СИСТЕМ"
ИНН: 9704271170

описание

Do you currently possess an EU passport or a valid work permit that authorises you to work in the specified hiring location? • Are you happy to make yourself available for the required hybrid model of 3 days in office per week?

Bitpanda operates a trade-everything investment platform that enables more than 7 million customers to invest in cryptocurrencies, crypto indices, stocks, precious metals, and commodities. Headquartered in Austria, it operates across Europe.

задачи

  • Define a multi-year GRC roadmap aligned with business strategy, risk appetite, and regulatory expectations
  • Evolve the control framework by rationalizing controls, reducing duplication, and ensuring proportionality based on criticality, data sensitivity, and business impact
  • Establish governance principles, including minimum control baselines, exception governance, and evidence-by-design
  • Advise leadership on material risk decisions, including risk acceptance, remediation prioritization, control investments, and scope decisions
  • Produce executive-grade risk narratives, board and committee materials, and regulator and customer responses with defensible rationale
  • Facilitate senior stakeholder alignment when priorities conflict
  • Own the strategy and approach for major audits and assurance activities, including ISO 27001, SOC 2, regulatory examinations, and key client due diligence
  • Lead responses to complex audit and regulatory issues, including root-cause analysis, corrective action programs, and sustained effectiveness verification
  • Serve as an SME in one or more areas: ISMS/ISO 27001 at scale, DORA and operational resilience governance, third-party risk for critical ICT providers, or security control assurance
  • Set standards and reusable artifacts, including control narratives, evidence templates, testing methodologies, and playbooks
  • Mentor specialists and associates through coaching and review
  • Partner with Security Engineering, IT, and Compliance to embed controls into workflows, using policy-to-automation where possible

требования

  • Typically 7–10+ years of experience in information security GRC, audit/assurance, security risk, compliance, software engineering, and/or financial services risk roles
  • Demonstrated ownership of complex, multi-stakeholder GRC programs and successful navigation of audits and regulatory scrutiny
  • Deep working knowledge of ISO 27001 and DORA, and strong familiarity with SOC 2, NIST CSF, BaIT, and COBIT, including control testing and evidence
  • Strong technology risk understanding across cloud, IAM, SDLC governance, incident management, vulnerability management, logging/monitoring, and crypto/fintech operational processes as relevant
  • Ability to influence across the organization and resolve conflicts with a risk-based, outcome-oriented approach

условия

  • Competitive total compensation package aligned with Bitpanda’s pay-for-impact policy, including participation in its stock option plan
  • Confidential coaching, counselling, and mental health resources through OpenUP
  • Three additional paid days off in 2027 after six months with the company
  • Unlimited access to Udemy’s online course library
  • Discounts, rewards, and perks from partners worldwide across lifestyle, wellness, tech, and travel
  • Up to eight additional weeks of gender-neutral new parent leave
  • Free onsite dining, freshly prepared lunches, and snacks for employees in Vienna, Bucharest, Barcelona, and Berlin
  • Tenure recognition and rewards, Bitpanda-branded merchandise, and company events
  • 25 Additional days per year to work from a city or country of choice
  • Hybrid model: three days onsite and two days from home; exceptions apply to shift-schedule teams and roles requiring office presence

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.

Спроси Хайрика про вакансию

Сверит с твоим резюме, подскажет вилку и вопросы на собесе.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайся: это мошенничество.