Chief Information Security Officer
You will establish and mature the information security program, including policies, governance, risk management, DORA readiness, security reporting, and incident response. You will independently audit security controls, review release and architecture risks, oversee testing, and support regulatory and client audits.
Responsibilities
- Establish and maintain security policies and procedures, including SDLC policies, aligned with ISO/IEC 27001:2022
- Act as the independent security gatekeeper under ISO 27001
- Manage the Information Security Risk Register and track technology risk acceptance and structural vulnerabilities
- Own the DORA-ready validation program and ensure compliance with contractual DORA provisions
- Maintain the DORA Data Sheet and subcontractor registers
- Implement and support security dashboards and reporting for DORA-regulated clients
- Govern the security incident response process and define notification targets and SLA thresholds
- Ensure incident workflows escalate root-cause analyses and affected data categories in time for major-incident reporting
- Perform independent quarterly audits of administrative access logs and permission changes
- Review and sign off on technical risk profiles for system releases and architectural changes
- Review and continuously improve the SDLC setup
- Implement and support threat-driven penetration and business continuity testing
- Serve as the technical point of contact for CSSF examiners and external ISO 27001 auditors
- Coordinate client audit teams' annual reviews of the ISMS and BCDR plans
Requirements
- Bachelor's or Master's degree in IT, Computer Science, Cybersecurity, or a related field
- 5+ years of information security leadership experience, preferably as a CISO in regulated financial services or regulated SaaS
- Deep knowledge of ISO/IEC 27001:2022, DORA, ISMS, risk management, and security controls
- Understanding of AWS cloud security, network segregation, VPC design, multi-tenant database isolation, and IAM principles
- CISSP, CISM, CRISC, or equivalent professional certification
- Strong verbal and written English communication skills
Benefits
- Hybrid work arrangement in Cyprus