
Information Security Lead
Posted Jul 19

Posted Jul 19
This is a fully remote position, open to applicants in Bulgaria.
• Formulate and sustain the information security strategy, standards, and roadmap that aligns with relevant regulations, guidelines, and security best practices.
• Guide security architecture within a cloud-native environment, establishing secure-by-design patterns for microservices, APIs, and shared platform services.
• Create and manage secure software development lifecycle (secure SDLC) practices, incorporating automated security controls into CI/CD pipelines.
• Define and promote the adoption of cloud security guardrails, including identity, network segmentation, encryption, secrets management, and configuration baselines.
• Develop and manage security monitoring, logging, and threat detection across cloud, infrastructure, and application layers.
• Oversee the security incident response lifecycle—preparation, detection, containment, eradication, recovery, and post-incident review—and serve as the incident commander for security events.
• Manage vulnerability and threat assessments: conducting scans, prioritizing risks, tracking remediation, and reporting across infrastructure, containers, and application code.
• Organize and coordinate penetration testing and offensive-security exercises (either in-house or co-sourced) and ensure findings are resolved.
• Administer identity and access management, privileged access, and least-privilege principles across cloud and corporate systems.
• Define and supervise data protection controls—encryption, key management, data classification, and loss prevention—for sensitive and cardholder information.
• Secure corporate IT and office infrastructure, which includes endpoints, networks, and productivity and collaboration platforms.
• Collaborate with Engineering and DevOps teams to facilitate a secure path, offering tools, standards, threat modeling, and design reviews.
• Contribute security insights into architecture and change decisions, encompassing the adoption of new technologies and third-party services.
• Conduct security awareness initiatives and phishing-resilience programs for both technical and non-technical personnel.
• Implement and demonstrate the technical security controls that support PCI DSS, ISO 27001, and SOC audits.
• Keep abreast of the evolving threat landscape and emerging security technologies.
• Act as an integral member of the internal security center of excellence and engage in cross-functional security working groups.
• Build, lead, and mentor a small security team.
• Report on security posture, key risks, and relevant metrics.
• Bachelor’s or master’s degree in computer science, information security, or a related discipline, or an equivalent level of practical experience.
• A minimum of 10 years in information/cyber security, including at least 2-3 years in a leadership position, with hands-on experience in securing scalable cloud-native environments.
• Extensive, practical knowledge of public cloud security (AWS preferred), encompassing identity, networking, encryption, logging, and configuration management.
• Strong experience in securing DevOps/CI/CD pipelines and modern microservices architectures, including containers, APIs, and infrastructure-as-code.
• Familiarity with application security and secure SDLC principles across contemporary programming languages and web frameworks.
• Practical experience in security operations, incident response, and vulnerability management.
• Comprehensive understanding of security frameworks and compliance standards pertinent to payments, such as ISO 27001, PCI DSS, SOC 2, and NIST CSF.
• Proficient AI security literacy, with practical use of AI-assisted security tools (e.g., GenAI coding assistants, AI-augmented SAST/DAST, and SIEM/SOC analytics), along with a solid grasp of securing AI/LLM and agentic applications, including AWS AI services like Amazon Bedrock and the OWASP Top 10 risks for LLMs (e.g., prompt injection and data leakage).
• Strong analytical and problem-solving skills, coupled with high integrity and sound judgment.
• Exceptional verbal and written communication skills, fluent in English, with the ability to influence engineers using data, logic, and best practices.
• Fast-growing payment company;
• Excellent working conditions, casual atmosphere, and state-of-the-art hardware;
• Modern, challenging, and constantly evolving business;
• Professional development opportunities, including books, trainings, and certifications;
• Team-building activities and enjoyable events;
• 25 days of paid holiday, plus 1 additional day for every 2 years with us;
• Fully distributed and remote work environment.
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.