Head of Information Security
Summary
Lead global security governance, risk, and compliance for a fintech payments company, driving ISO 27001, PCI DSS, and GDPR compliance while automating GRC with modern platforms.
You will own and evolve the global Information Security GRC strategy across a complex, highly regulated environment You will lead a small but high impact team working closely with Engineering Compliance Legal Privacy Risk Internal Audit and business stakeholders to strengthen governance simplify compliance and enable secure business growth You will transform traditional GRC processes through automation leveraging modern platforms such as Vanta and agentic AI solutions
Responsibilities
- Develop and enhance the Information Security Management System ISMS
- Lead the GRC function and manage the Information Security team
- Drive information security governance across the organization
- Lead and support international audits including ISO 27001, PCI DSS, and other regulatory assessments
- Own Risk Management Third-Party/Vendor Risk Management and Security Awareness initiatives
- Ensure compliance with international standards and regulations including ISO 27001, PCI DSS, DORA, and GDPR
- Improve and automate GRC processes using modern platforms and AI-driven solutions
Requirements
- 7+ years of experience in Information Security, including at least 2 years in a leadership role
- Strong expertise in GRC, ISMS, risk management, and security compliance
- Hands-on experience with ISO 27001 and PCI DSS audits
- Previous experience in fintech, banking, payments, or crypto is highly preferred
- Experience leading teams and working closely with business stakeholders, auditors, and regulators
Benefits
- Relocation support to Belgrade Serbia
- Competitive compensation
- Annual performance bonus
- Comprehensive benefits package