Cybersecurity Lead

Coverflex · Location unlisted · 3 days ago
ad in EnglishEngineeringvia teamtailor
Apply
🧡 Coverflex Work changed. Pay didn’t. Coverflex exists to make compensation work for everyone. Pay is still rigid, fragmented, and hard to feel. We turn compensation into choice — one platform, one card, one app — for benefits, meal allowance, insurance and more. Our platform is simple for HR and meaningful for employees. We provide choice, smarter compensation tools and empowerment. ⚙️ TL;DR (The Essentials) Role: Cybersecurity Lead Seniority Level: Lead Type: Individual Contributor Languages: English (main) / Portuguese or Spanish or Italian a plus Main Tools: AWS and/or GCP security tooling, SIEM, detection/response, EDR/MDM, identity/SSO/MFA, and privileged-access tooling, Vulnerability scanning, application security testing, and penetration-testing workflows, Jira/Notion or equivalent risk, remediation, evidence, and roadmap tracking, Scripting/automation for control operation and evidence collection Location: Remote (Europe only) Compensation: • Base Salary: 65.000€ to 95.000€ gross yearly • Bonus / Commissions: No • Equity: Yes – Stock Options under our Equity Incentive Plan • Benefits: All Coverflex benefits apply • Contract Type: Permanent 💥 Your Impact Your role will play a major role in our success because… The Cybersecurity Lead will help Coverflex grow as a trusted, resilient multi-market fintech. By identifying material risks earlier, strengthening security operations and third-party assurance, and making security evidence reusable, this role will protect customers and company data, support reliable payment and benefits services, preserve ISO 27001 and contractual commitments, and reduce friction in launches, enterprise sales, renewals, and audits. You’ll know you’re successful if, after 90 days... • 100% of material security risks have an owner, treatment decision, due date, and monthly review; a monthly dashboard and quarterly Management Team risk review are in place; and all required ISMS, cybersecurity, and related privacy documentation has a named owner, review cadence, and current approved version. • At least one executive risk exercise and one technical control validation are completed, with ≥90% of resulting actions closed by their due dates; ≥95% of critical/high vulnerabilities are remediated within policy SLA and all exceptions are formally approved and time-bound. • 100% of defined high-risk changes receive a risk-based review before launch; 100% of critical suppliers are tiered and the highest-risk suppliers are assessed, with contractual and technical gaps tracked. How we’ll measure success: • Establish ownership and visibility: consolidate material security risks, findings, exceptions, critical suppliers, security actions, tooling, spend, and key-person dependencies; own and maintain the core ISMS and cybersecurity documentation, including the Information Security Policy and Cybersecurity Risk Management Plan; and publish a risk-ranked 12-month roadmap and management dashboard. Privacy- and GDPR-specific documentation remains jointly coordinated with the DPO and Legal/Compliance, with explicit ownership agreed for each document. • Operationalise security governance and resilience: clarify escalation roles, risk thresholds, control ownership, evidence requirements, vulnerability SLAs, and the risk-exception workflow; run an executive risk exercise and technical control validation covering a critical payment partner. • Embed proportionate assurance into growth: establish review gates for high-risk launches, architecture changes, and critical vendors; introduce repeatable threat-modelling patterns; tier critical third parties and track material gaps to closure. ⚡ Reality Check - What Makes This Role Hard Let’s be real - here’s what makes this role challenging: This is a broad, hands-on role in a scaling, regulated, multi-market environment. The person must move comfortably between technical investigation, cloud and product security, risk and assurance, partner management, and executive communication. They will need to influence teams without taking ownership away from Engineering, Product, Legal/Compliance, the DPO, or business leaders; prioritise ruthlessly with limited dedicated capacity; and build useful guardrails without becoming a gatekeeper. Third-party dependencies, an evolving threat surface, remote-first operations, and fragmented security ownership add complexity. 👤 You Must-haves (evidence, not years) • Senior, hands-on security experience in a regulated fintech, payments, SaaS, or similarly high-trust environment • Personally conducted security investigations, tuned detections, assessed cloud and identity controls, reviewed architectures, and validated vulnerability remediation • Strong cloud, application/product security, IAM, detection/response, vulnerability management, and third-party risk judgement • Experience owning ISO 27001 or comparable assurance while keeping the programme outcome-focused • Ability to build a proportionate security programme in a scaling company, not only operate within a mature enterprise function • Credibility with engineers and the ability to translate technical detail into clear business recommendations • Fluent professional English Nice-to-have • Experience with payment processors, card ecosystems, regulated partners, or multi-market fintech operations • Experience using managed security services and specialist providers effectively • Security automation and evidence-collection experience • Experience with executive risk exercises and supplier resilience scenarios • Relevant certifications such as CISSP, CISM, CCSP, OSCP, or ISO 27001 Lead Implementer/Auditor; practical evidence matters more than certificates 🧬 Your DNA Pragmatic, calm under pressure, curious, and evidence-driven. You combine sound judgement with a bias for action, challenge constructively, and communicate risk without fearmongering. You are comfortable doing the work yourself while creating leverage through standards, automation, and collaboration. You understand commercial trade-offs, make clear recommendations, and escalate material risks appropriately rather than seeking universal control. You should add dedicated security depth and consistent ownership while preserving clear accountability in the teams that own systems and decisions. You will make Engineering, Product, IT, Legal/Compliance, the DPO, and leadership more effective through prioritisation, expert challenge, reusable patterns, direct technical support, and reliable follow-through. You should reduce key-person dependency on Technology Leadership and become the trusted bridge between technical evidence and business risk decisions. 👥 Manager & Team Meet Your Manager Hiring Manager: Tiago Fernandes, CTO Location: Portugal LinkedIn Profile Profile Snapshot: • Who you are as a person: Curious and motivated by solving meaningful problems with durable systems rather than theatre. My approach can be pragmatic, but I also enjoy exploring a problem deeply before converging on the answer. • Who you are as a manager: I give experienced people autonomy and trust them to bring judgement, ownership, and a point of view. I do not always provide perfectly clear context at the outset, so I value people who ask questions, help structure ambiguity, and confirm shared outcomes and priorities. • Your type of energy: Calm, analytical, low-ego, and action-oriented—particularly in high-pressure and ambiguous situations. • Your communication style: Candid and context-rich. I sometimes provide more context than necessary or do not land the clearest version immediately, so I appreciate people who synthesise, ask clarifying questions, and help turn discussion into explicit decisions and next steps. • Your feedback style: Thoughtful and conversational, focused on learning and improving the work rather than assigning blame. I value a two-way dialogue and expect people to ask for clarification when the feedback is not suf

Get the passFilters for ad language, visa sponsorship and level, translation of any ad, from €5 — cancel anytime.