
Head of Information Security
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in Malta.
• Develop and implement the information security strategy, vision, and multi-year roadmap for the entire organization.
• Provide leadership, mentorship, and growth opportunities for the security team, including the Senior Information Security Engineer and additional security personnel.
• Manage the enterprise risk management program, encompassing the identification, assessment, treatment, and reporting of security and technology risks.
• Ensure compliance with PCI DSS, ISO 27001, SOC 2, GDPR, and specific gambling regulations pertinent to different jurisdictions.
• Serve as the primary contact for external auditors, regulators, partners, and customers regarding information security, privacy, and assurance matters.
• Create and uphold security policies, standards, and procedures across engineering, operations, and business functions.
• Oversee the incident response program, which includes tabletop exercises, playbooks, escalation paths, and major incident command.
• Drive vulnerability management, threat intelligence, and penetration testing efforts within AWS cloud and on-premise settings.
• Advocate for security-by-design methodologies throughout the Software Development Life Cycle (SDLC) in collaboration with engineering and SRE leadership.
• Define and manage the security budget, vendor partnerships, and tooling investments.
• Establish and execute security awareness and training programs for staff and contractors.
• Report to the executive team and board regarding security posture, risks, program advancements, and emerging threats.
• Keep abreast of the changing threat landscape, regulatory changes, and best practices within the industry.
• Extensive experience in senior information security leadership roles, preferably including positions such as Head of Security, CISO, or similar in regulated industries.
• Proven success in building and managing high-performing security teams across various geographical locations.
• In-depth knowledge of PCI DSS, ISO 27001, SOC 2, NIST CSF, and GDPR.
• Strong technical background in AWS cloud security, application security, network security, identity and access management, and security operations.
• Experience in leading organization-wide incident response and crisis management, including engagement with regulators and law enforcement when necessary.
• Familiarity with the online gambling, fintech, or other highly regulated industries is highly preferred.
• Relevant certifications such as CISSP, CISM, CISA, CRISC, or equivalent are highly desirable.
• Exceptional communication, influencing, and stakeholder management skills, including the ability to convey complex security issues to executive and board audiences.
• A strategic mindset complemented by practical, hands-on experience.
• Capability to function effectively in a fast-paced, scaling environment.
• A remote and flexible working schedule.
• Generous time off that varies based on the country of residence.
• Discretionary annual performance bonuses.
• Training and development opportunities to assist you in your career advancement.
• Provision of hardware & software allowances or work equipment.
• Access to various well-being programs and initiatives.
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.