Head of Information Security (f/m/d)
Job Description:
Our client is a premium Merchant of Record (MoR) that processes software sales for companies all over the world. That makes Information Security less of a checkbox and more of a trust layer the whole business runs on. They're looking for someone to own that layer — and to turn security into an engineering-aligned capability, not a gatekeeper. A build-and-shape role, reporting straight to the VP IT & Infrastructure.
THE ROLE
You own the company's security posture end to end — strategy, standards, and the day-to-day reality of keeping a payments platform safe. You don't write policies that sit in a wiki; you embed security into how software actually gets built and operated: secure-by-design with Engineering, audit-readiness for PCI-DSS and SOC 2, and a risk landscape made visible through KPIs people act on. You lead a small team and act as the trusted voice on security — internally, and when it counts, in front of customers, partners, and auditors.
WHAT YOU'LL DO
- Own and continuously improve the overall security posture, with measurable KPIs that keep risk transparent.
- Define and evolve the information security strategy in lockstep with business goals and a moving threat landscape.
- Embed security into the SDLC and platform operations with Engineering — secure-by-design as the default.
- Set pragmatic, risk-based standards and guardrails so teams ship secure solutions without slowing down.
- Get the organisation audit-ready for PCI-DSS and SOC 2 by translating compliance into practical, scalable controls.
- Strengthen detection and response through logging, monitoring, and alerting across apps and infrastructure.
- Drive build-versus-buy decisions on security tooling, and represent security to customers, partners, and auditors.
WHAT YOU BRING
The real must-haves:
- 7+ years in Information Security or Security Engineering, ideally in cloud-based or SaaS environments.
- Deep understanding of how modern applications and platforms are built and operated — credible with engineers.
- Hands-on grasp of application architectures, APIs, IAM, and distributed-system vulnerabilities.
- Working familiarity with PCI-DSS and SOC 2 (or comparable) and how to turn them into controls that scale.
- Experience leading and developing small teams.
- Fluent English, written and spoken.
Nice-to-haves:
- Background in environments handling sensitive, payment-related data.
- Exposure to security considerations in AI-enabled environments.
- A degree in Computer Science, IT, Cybersecurity — or equivalent depth earned in practice.
- German.
WHAT'S IN IT FOR YOU
- A genuine shape-it mandate, reporting directly to the VP IT & Infrastructure.
- Work hybrid or fully remote — with flexible hours.
- A personal L&D budget and structured development programs.
- Health & well-being benefits, pension/retirement plans, referral bonuses, and more.
- A 200+ person, 30+ nationality team where people tend to stay.
This role is placed by Characters Connection. We don't fill seats — we connect Characters. Every application is handled with discretion; the client's identity is disclosed upon mutual interest.
Interested — or know someone who fits? Apply directly via this page or reach out to [email protected].