Cybersecurity Lead

Posted 2 days ago

This is a fully remote position, open to applicants in Portugal.

📋 Description

• Proactively identify material security risks and enhance security operations along with third-party assurance.

• Safeguard customer and company information while supporting dependable payment and benefits services.

• Uphold ISO 27001 standards and adhere to contractual obligations.

• Ensure that material security risks are assigned to owners, have treatment decisions, due dates, and are reviewed monthly.

• Create monthly dashboards and conduct quarterly Management Team risk assessments.

• Oversee and maintain the primary ISMS and cybersecurity documentation.

• Develop a risk-ranked 12-month roadmap and management dashboard.

• Collaborate on privacy and GDPR-specific documentation with the DPO and Legal/Compliance teams.

• Define escalation roles, risk thresholds, control ownership, evidence requirements, vulnerability SLAs, and risk-exception workflows.

• Facilitate executive risk exercises and validate technical controls.

• Set up review gates for high-risk launches, architectural modifications, and critical vendor assessments.

• Introduce consistent threat-modelling patterns.

• Classify critical third parties and manage the closure of material gaps.

• Sustain the security roadmap, backlog, operating metrics, tools, targeted specialist support, and core ISMS and cybersecurity strategies and policies.

• Collaborate with Technology Leadership, Engineering, Infrastructure/Platform, Product, IT, Legal/Compliance, the DPO, Finance, Procurement, People, customer-facing teams, auditors, penetration testers, service providers, vendors, and regulated/payment partners.

• Report directly to the CTO as a senior individual contributor and take ownership of the cybersecurity function.


⛳️ Requirements

• Extensive, hands-on security experience in regulated fintech, payments, SaaS, or similarly high-trust environments.

• Directly conducted security investigations, fine-tuned detections, evaluated cloud and identity controls, reviewed architectures, and validated vulnerability remediation efforts.

• Strong judgment in cloud, application/product security, IAM, detection/response, vulnerability management, and third-party risk.

• Proven experience managing ISO 27001 or similar assurance frameworks while maintaining a focus on program outcomes.

• Capability to develop a balanced security program in a growing company.

• Established credibility with engineers and the ability to convert technical details into straightforward business recommendations.

• Fluent in professional English.

• Proficiency in Portuguese, Spanish, or Italian is advantageous.

• Background with payment processors, card ecosystems, regulated partners, or multi-market fintech operations is a plus.

• Experience in effectively utilizing managed security services and specialized providers is beneficial.

• Knowledge of security automation and evidence collection is an advantage.

• Familiarity with conducting executive risk exercises and supplier resilience scenarios is a plus.

• Relevant certifications such as CISSP, CISM, CCSP, OSCP, or ISO 27001 Lead Implementer/Auditor are desirable.

• Understanding of AWS and/or GCP security tools, SIEM, detection/response, EDR/MDM, identity/SSO/MFA, privileged-access tools, vulnerability scanning, application security testing, penetration-testing workflows, Jira/Notion or equivalent, and scripting/automation.


🏝️ Benefits

• Stock Options under our Equity Incentive Plan.

• All Coverflex benefits apply.

• Fully remote setup, with annual on-site gatherings at least once a year.

• Competitive and flexible compensation package.

• Coverflex card.

• MacBook provided.

• €500 onboarding budget.

• €1,000 yearly FlexBudget for professional development and remote work support.

• Health Insurance plans available, with options to add family members and modify conditions (depending on country).

• 25 days of paid vacation.

• 3 caring days per year to work on side projects that positively impact our society.

• 2 additional paid weeks beyond the legal maximum for Parental Leave.

• Time off for your birthday and your children's birthdays.

People also viewed

Sony Interactive Entertainment1 day ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads1 day ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Neo4j1 day ago

Senior Director, Product, Security and Privacy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$260k – $300k/year
ApplyView job
PingWind Inc. (SDVOSB)1 day ago

Cloud Security Architect – Engineer

US flagAlabama, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
CSCI Consulting1 day ago

SAP S/4HANA Defense & Security Functional Lead

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Strategic Systems International1 day ago

AI Security Engineer – AI, Agentic Security

MX flagMexico, +4 more countriesFreelanceCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers