全球首席信息安全官(CISO)
Global Chief Information Security Officer (CISO)
我们正在寻找一位具有前瞻性、积极主动并亲力亲为的全球首席信息安全官(CISO),负责设计、实施并扩展我们的全球信息安全战略。随着公司的发展,您将负责从零开始建立安全流程,确保在受监管市场中达到无可挑剔的信息安全合规性,并领导一个分布式的远程团队。
这是一项专注于公司全球信息安全态势的领导职位。
关键职责:
信息安全管理与治理:
- 制定、推动并执行与业务目标一致的全球信息安全路线图
- 评估并定义CEX.IO当前及未来的信息安全需求
- 在监管考量和行业基准的背景下识别能力差距
流程管理:
- 从零开始构建、实施并优化整个组织的稳健安全流程、框架和政策
- 确保所有目标团队都能获得完成工作所需的培训和资源
合规、认证与审计:
- 监督行业特定许可和认证(如SOC 2、PCI-DSS、DORA、MiCA/加密法规)的成功获取和维护。管理定期的内部/外部安全审计和高管汇报。
- 为此,您将密切合作:
- 外部审计师和监管机构,在企业认证过程和监管审查期间担任主要技术联系人和专业领域专家。
- 法律和数据保护团队,确保信息安全政策严格符合欧洲GDPR合规性、数据隐私法律和公司治理标准。
- 英国、美国和西班牙地区的董事和高管,以弥合全球信息安全框架与当地监管要求和许可条件之间的差距。
- 工程和产品团队,将安全直接嵌入软件开发生命周期和产品路线图。您将协作制定安全编码实践、漏洞管理,并确保产品架构(尤其是加密/钱包功能)在发布前具备安全性设计。
团队领导:
- 领导、指导并扩大一支高效、完全远程的安全团队。
- 培养责任意识和主动性文化。
- 根据公司的规定履行所有管理职能。
查看英文原文
We are looking for a forward-thinking, driven, and hands-on Global Chief Information Security Officer (CISO) to design, implement, and scale our global information security strategy. As we expand, you will be responsible for building security processes from scratch, ensuring unimpeachable information security compliance across the regulated markets, and leading a distributed remote team.
This is a leadership role focused entirely on the company's global information security posture.
Key Responsibilities:
InfoSecurity Strategy & Governance:
- Define, drive, and execute the global information security roadmap aligned with business goals
- Assess and define CEX.IO’s current and future requirements in terms of information security
- Identify capability gaps in the context of regulatory considerations and industry benchmarks
Process Management:
- Build, implement, and optimise robust security processes, frameworks, and policies across the entire organisation from the ground up.
- Ensure all target teams are provided with the training and resources needed to perform their jobs to the highest degree possible
Compliance, Certifications & Audits:
- Oversee the successful acquisition and maintenance of industry-specific licenses and certifications (e.g., SOC 2, PCI-DSS, DORA, MiCA/crypto regulations). Manage regular internal/external security audits and executive reporting.
- To achieve this, you will closely collaborate with:
- External auditors and regulators, acting as the primary technical point of contact and subject matter expert during corporate certification processes and regulatory reviews.
- Legal and data protection team to ensure information security policies strictly map to European GDPR compliance, data privacy laws, and corporate governance standards.
- Managing Directors and Officers within the UK, US, and ES locations to bridge global information security frameworks with local regulatory mandates and licensing requirements.
- Engineering and Product teams to embed security directly into the software development lifecycle and product roadmap. You will collaborate on secure coding practices, vulnerability management, and ensuring that product architectures (especially crypto/wallet features) are secure by design before release.
Team Leadership:
- Lead, mentor, and scale a high-performing, fully remote security team.
- Foster a culture of accountability and proactiveness.
- Lead all managerial functions in accordance with the company’s policies and procedures (hiring, training, setting goals, appraising performance, budgeting)
Risk & Incident Management:
- Act as the ultimate point of escalation for global security incidents, ensuring proactive threat hunting and rapid mitigation.
- Manage the oversight of technical risk assessments, such as vulnerability scanning, penetration testing, risk reviews for new applications, and third-party risk assessments
Requirements (Must-Haves)
- Experience: Proven track record in a senior security leadership role (CISO, Director of Security, or Head of Information Security) within the Financial Services or FinTech sector.
- Direct experience steering organisations through complex information security audits, certifications, licensing, and international regulatory compliance.
- Demonstrated experience in creating, implementing, and managing group-level security processes and frameworks.
- Exceptional leadership skills with a proven ability to manage remote, distributed teams. Strong sense of ownership, proactiveness, and high responsibility.
- Language: Fluent English with excellent communication and reporting skills; Ukrainian or Russian will be an advantage.
- Location: Must be physically located and legally authorised to work remotely within Europe.
Preferred (Nice-to-Haves)
· Hands-on experience in the Cryptocurrency, Web3, or Blockchain industry, understanding specific security vectors (custody, cold/hot wallet security)
Originally posted on Himalayas