
Cybersecurity Lead
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Portugal.
• Proactively identify material security risks and enhance security operations along with third-party assurance.
• Safeguard customer and company information while supporting dependable payment and benefits services.
• Uphold ISO 27001 standards and adhere to contractual obligations.
• Ensure that material security risks are assigned to owners, have treatment decisions, due dates, and are reviewed monthly.
• Create monthly dashboards and conduct quarterly Management Team risk assessments.
• Oversee and maintain the primary ISMS and cybersecurity documentation.
• Develop a risk-ranked 12-month roadmap and management dashboard.
• Collaborate on privacy and GDPR-specific documentation with the DPO and Legal/Compliance teams.
• Define escalation roles, risk thresholds, control ownership, evidence requirements, vulnerability SLAs, and risk-exception workflows.
• Facilitate executive risk exercises and validate technical controls.
• Set up review gates for high-risk launches, architectural modifications, and critical vendor assessments.
• Introduce consistent threat-modelling patterns.
• Classify critical third parties and manage the closure of material gaps.
• Sustain the security roadmap, backlog, operating metrics, tools, targeted specialist support, and core ISMS and cybersecurity strategies and policies.
• Collaborate with Technology Leadership, Engineering, Infrastructure/Platform, Product, IT, Legal/Compliance, the DPO, Finance, Procurement, People, customer-facing teams, auditors, penetration testers, service providers, vendors, and regulated/payment partners.
• Report directly to the CTO as a senior individual contributor and take ownership of the cybersecurity function.
• Extensive, hands-on security experience in regulated fintech, payments, SaaS, or similarly high-trust environments.
• Directly conducted security investigations, fine-tuned detections, evaluated cloud and identity controls, reviewed architectures, and validated vulnerability remediation efforts.
• Strong judgment in cloud, application/product security, IAM, detection/response, vulnerability management, and third-party risk.
• Proven experience managing ISO 27001 or similar assurance frameworks while maintaining a focus on program outcomes.
• Capability to develop a balanced security program in a growing company.
• Established credibility with engineers and the ability to convert technical details into straightforward business recommendations.
• Fluent in professional English.
• Proficiency in Portuguese, Spanish, or Italian is advantageous.
• Background with payment processors, card ecosystems, regulated partners, or multi-market fintech operations is a plus.
• Experience in effectively utilizing managed security services and specialized providers is beneficial.
• Knowledge of security automation and evidence collection is an advantage.
• Familiarity with conducting executive risk exercises and supplier resilience scenarios is a plus.
• Relevant certifications such as CISSP, CISM, CCSP, OSCP, or ISO 27001 Lead Implementer/Auditor are desirable.
• Understanding of AWS and/or GCP security tools, SIEM, detection/response, EDR/MDM, identity/SSO/MFA, privileged-access tools, vulnerability scanning, application security testing, penetration-testing workflows, Jira/Notion or equivalent, and scripting/automation.
• Stock Options under our Equity Incentive Plan.
• All Coverflex benefits apply.
• Fully remote setup, with annual on-site gatherings at least once a year.
• Competitive and flexible compensation package.
• Coverflex card.
• MacBook provided.
• €500 onboarding budget.
• €1,000 yearly FlexBudget for professional development and remote work support.
• Health Insurance plans available, with options to add family members and modify conditions (depending on country).
• 25 days of paid vacation.
• 3 caring days per year to work on side projects that positively impact our society.
• 2 additional paid weeks beyond the legal maximum for Parental Leave.
• Time off for your birthday and your children's birthdays.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.