Remotery

Information Security Lead

Posted Jul 19

This is a fully remote position, open to applicants in Bulgaria.

đź“‹ Description

• Formulate and sustain the information security strategy, standards, and roadmap that aligns with relevant regulations, guidelines, and security best practices.

• Guide security architecture within a cloud-native environment, establishing secure-by-design patterns for microservices, APIs, and shared platform services.

• Create and manage secure software development lifecycle (secure SDLC) practices, incorporating automated security controls into CI/CD pipelines.

• Define and promote the adoption of cloud security guardrails, including identity, network segmentation, encryption, secrets management, and configuration baselines.

• Develop and manage security monitoring, logging, and threat detection across cloud, infrastructure, and application layers.

• Oversee the security incident response lifecycle—preparation, detection, containment, eradication, recovery, and post-incident review—and serve as the incident commander for security events.

• Manage vulnerability and threat assessments: conducting scans, prioritizing risks, tracking remediation, and reporting across infrastructure, containers, and application code.

• Organize and coordinate penetration testing and offensive-security exercises (either in-house or co-sourced) and ensure findings are resolved.

• Administer identity and access management, privileged access, and least-privilege principles across cloud and corporate systems.

• Define and supervise data protection controls—encryption, key management, data classification, and loss prevention—for sensitive and cardholder information.

• Secure corporate IT and office infrastructure, which includes endpoints, networks, and productivity and collaboration platforms.

• Collaborate with Engineering and DevOps teams to facilitate a secure path, offering tools, standards, threat modeling, and design reviews.

• Contribute security insights into architecture and change decisions, encompassing the adoption of new technologies and third-party services.

• Conduct security awareness initiatives and phishing-resilience programs for both technical and non-technical personnel.

• Implement and demonstrate the technical security controls that support PCI DSS, ISO 27001, and SOC audits.

• Keep abreast of the evolving threat landscape and emerging security technologies.

• Act as an integral member of the internal security center of excellence and engage in cross-functional security working groups.

• Build, lead, and mentor a small security team.

• Report on security posture, key risks, and relevant metrics.


⛳️ Requirements

• Bachelor’s or master’s degree in computer science, information security, or a related discipline, or an equivalent level of practical experience.

• A minimum of 10 years in information/cyber security, including at least 2-3 years in a leadership position, with hands-on experience in securing scalable cloud-native environments.

• Extensive, practical knowledge of public cloud security (AWS preferred), encompassing identity, networking, encryption, logging, and configuration management.

• Strong experience in securing DevOps/CI/CD pipelines and modern microservices architectures, including containers, APIs, and infrastructure-as-code.

• Familiarity with application security and secure SDLC principles across contemporary programming languages and web frameworks.

• Practical experience in security operations, incident response, and vulnerability management.

• Comprehensive understanding of security frameworks and compliance standards pertinent to payments, such as ISO 27001, PCI DSS, SOC 2, and NIST CSF.

• Proficient AI security literacy, with practical use of AI-assisted security tools (e.g., GenAI coding assistants, AI-augmented SAST/DAST, and SIEM/SOC analytics), along with a solid grasp of securing AI/LLM and agentic applications, including AWS AI services like Amazon Bedrock and the OWASP Top 10 risks for LLMs (e.g., prompt injection and data leakage).

• Strong analytical and problem-solving skills, coupled with high integrity and sound judgment.

• Exceptional verbal and written communication skills, fluent in English, with the ability to influence engineers using data, logic, and best practices.


🏝️ Benefits

• Fast-growing payment company;

• Excellent working conditions, casual atmosphere, and state-of-the-art hardware;

• Modern, challenging, and constantly evolving business;

• Professional development opportunities, including books, trainings, and certifications;

• Team-building activities and enjoyable events;

• 25 days of paid holiday, plus 1 additional day for every 2 years with us;

• Fully distributed and remote work environment.

People also viewed

Lime2 days ago

Senior Security Engineer

CA flagCanada OnlyFull-timeCybersecurity / Security Engineer$120k/year
ApplyView job
Threatscape2 days ago

Associate Consultant – Microsoft Security, Purview, Data Security and Governance, AI

GB flagUnited Kingdom OnlyFull-timeCybersecurity / Security Engineer£35k – £47k/year
ApplyView job
GFT Technologies2 days ago

Senior IT Security Project Manager

CR flagCosta Rica OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
BeyondTrust2 days ago

VP, Product Management, AI Security – Strategy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Quisitive2 days ago

Digital Security Coach

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
GEICO2 days ago

Senior Field Security Investigator

US flagFlorida OnlyFull-timeCybersecurity / Security Engineer$3,200 – $5,000/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers