信息安全官
Information Security Officer
Coinspaid Dev 是 Coinspaid 内部技术、基础设施和研发能力的工程品牌。拥有超过 120 名工程师和 11 年以上的行业经验,Coinspaid Dev 汇集了软件工程、基础设施、安全和研发团队,具备在超过 20 条区块链网络上构建分布式系统和区块链基础设施的经验。
Coinspaid Dev 作为一个独立的工程品牌,使命明确:推动区块链基础设施工程,并将实用的专业知识回馈给行业。架构是新的,但背后的经验并非如此。
职责:
- 担任金融科技的信息安全官。
- 支持信息安全标准(包括 ISO 27001、SOCv2、DORA)的实施和持续维护。
- 协调公司层面的安全活动,并确保与网络安全策略一致。
- 作为安全团队、公司管理层和技术团队之间的联络人。
- 支持安全治理流程,包括政策、流程、风险评估、控制实施和审计证据收集。
- 在安全审计、评估、整改活动和认证项目期间协调内部相关方。
- 跟踪安全风险、差距、行动项和整改进度。
- 确保将安全需求正确传达给业务、产品、IT、工程和基础设施团队。
- 在需要公司层面协调的情况下,支持事件、漏洞、访问管理及合规相关流程。
- 使用 GRC 工具收集证据,自动化风险评估流程,评估控制措施和第三方供应商等。
- 准备定期状态更新、报告和向安全领导层的升级汇报。
要求:
- 3 年以上信息安全、IT 安全、GRC、合规、风险管理或类似岗位的工作经验。
- 具有信息安全标准和框架(包括 ISO 27001、SOCv2、DORA)的实施、维护或审计支持的实际经验。
- 理解信息安全治理、风险管理、政策、流程、控制措施和审计证据收集。
- 能够在技术和业务团队之间协调安全活动。
- 有与内部相关方、审计人员、IT、工程、基础设施、产品和合规团队合作的经验。
- 良好的沟通能力
查看英文原文
Coinspaid Dev is the engineering brand behind the technology, infrastructure, and R&D expertise built within Coinspaid. With more than 120 engineersand over 11 years of industry experience, Coinspaid Dev brings together software engineering, infrastructure, security and R&D teams with experience building distributed systems and blockchain infrastructure operating across more than 20 blockchain networks.
Coinspaid Dev emerges as an independent engineering brand with a straightforward mission: to advance blockchain infrastructure engineering and contribute practical expertise back to the industry. The structure is new. The experience behind it is not.
Responsibilities:
- Act as Information Security Officer for FinTech.
- Support the implementation and ongoing maintenance of information security standards, including ISO 27001, SOCv2, DORA.
- Coordinate security activities at the company level and ensure alignment with cyber security strategy.
- Serve as a link between the Security team, company management, and technical teams.
- Support security governance processes, including policies, procedures, risk assessments, control implementation, and audit evidence collection.
- Coordinate internal stakeholders during security audits, assessments, remediation activities, and certification projects.
- Track security risks, gaps, action items, and remediation progress.
- Ensure proper communication of security requirements to business, product, IT, engineering, and infrastructure teams.
- Support incident, vulnerability, access management, and compliance-related processes where company-level coordination is required.
- Working with GRC-tool to collect evidence, automate risk assessment process, assess the controls and 3rd party vendors etc.
- Prepare regular status updates, reports, and escalations for security leadership.
Requirements:
- 3+ years of experience in Information Security, IT Security, GRC, Compliance, Risk Management, or a similar role.
- Practical experience with implementation, maintenance, or audit support for information security standards and frameworks, including ISO 27001, SOCv2, DORA.
- Understanding of information security governance, risk management, policies, procedures, controls, and audit evidence collection.
- Ability to coordinate security activities across technical and business teams.
- Experience working with internal stakeholders, auditors, IT, engineering, infrastructure, product, and compliance teams.
- Strong communication skills and ability to translate security requirements into clear business and technical actions.
- Experience working with such GRC-tools as: Vanta, Drata etc.
- English level sufficient for written communication, documentation, and audit-related activities.
- Certification CISSP, CISM, ISO27001 Lead Implementer
Why join CryptoProcessing by Coinspaid
You’ll be joining a company that is actively shaping its space – with enough scale to matter and enough room to make an impact.
At Coinspaid, people are expected to think, contribute, and take ownership – and are supported in doing so.
We focus on flexibility, wellbeing, and long-term growth – without overcomplicating how benefits work.
Flexible Benefits
Benefit Bar – up to €230/monthA flexible monthly budget you can use for what matters most to you – from sports and mental health to coworking, home office, or medical-related expenses.
Work & Flexibility
- Fully remote work from almost anywhere
- Optional offices and relocation support
- Flexible, async-friendly environment
Growth & Learning
- Budget for courses, certifications, and professional development
- Language learning support
- Cross-team learning and knowledge sharing
Wellbeing & Support
- Medical insurance or reimbursement depending on location
- Access to mental health support
- Financial support for important life events
Extras
- Merch shop with rewards system
- Team offsites and company events
Sounds good? Well then, we can’t wait to see your resume!
To learn more please visit: &
Originally posted on Himalayas