- Company Name
- sunday
- Job Title
- Head of Security
- Job Description
-
**Job Title**
Head of Security
**Role Summary**
Lead and scale the integrated security and compliance function for a fintech payments platform. Own strategy, governance, risk management, and day‑to‑day operations across product, infrastructure, cloud, and corporate security.
**Expectations**
- Deliver a modern, performance‑driven security organization that aligns with business goals and regulatory demands.
- Maintain PCI DSS, SOC 2, ISO 27001, and other certifications with minimal external support.
- Act as the trusted advisor to executive stakeholders, technical teams, and external partners on security posture and risk.
**Key Responsibilities**
- Define and execute global security strategy, risk management, and governance frameworks.
- Lead end‑to‑end PCI DSS audits and maintain readiness for SOC 2, ISO 27001, NIST, and related standards.
- Build, operate, and continuously improve a Security Operations Center (SOC) with EDR monitoring, alert triage, incident response playbooks, and post‑incident reviews.
- Set and enforce corporate security policies: mobile device management, data loss prevention, and cloud access controls.
- Conduct vendor and supplier risk assessments, audits, and contract reviews to mitigate third‑party exposure.
- Partner with Legal, DPO, Engineering, SRE, RevOps, and ITSM to embed security into processes, product development, and deployments.
- Collaborate on cloud and application security, ensuring secure-by‑design SDLC practices and secure cloud architecture.
- Maintain risk registers, track KPIs, and report security posture to executive leadership.
- Drive security awareness and culture through training, enablement, and policy communication.
**Required Skills**
- Deep expertise in GRC, PCI DSS, SOC, ISO 27001, and cloud security.
- Hands‑on experience with EDR/SOC tooling, CSPM/vulnerability scanners (e.g., Wiz), MDM platforms (Workspace One), Google Workspace security, DLP, and data governance.
- Proven ability to operate PCI DSS audits with minimal external partner reliance.
- Strong risk judgment and pragmatic prioritization in fast‑paced fintech/payments environments.
- Excellent communication, cross‑functional collaboration, and stakeholder management skills.
- Fluent in English (written and spoken).
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Relevant certifications: PCI DSS Lead Assessor (or equivalent), CISSP, CISM, or similar high‑level security credentials preferred.