Skip to content

Open nowPosted 81 days ago

VP Information Security (m/f/d)

finoa5 open roles

Where
Vilnius
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowVP Information Security (m/f/d)finoa · Vilnius
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on finoa's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.0%30 days
This job: posted 81 days ago

The posting

About us:

At Finoa, we are on a mission to enable institutions and individuals globally to migrate their capital into the onchain economy. We are actively engineering the platform that makes this possible.

We believe great products are built by people who are eager to leave their mark on the world. We are looking for ambitious, curious, and hard-working individuals who want to learn quickly, take ownership, and help us grow in a fast-moving market.

If you are excited by fintech, digital assets, AI, and the future of institutional finance, we would love to hear from you.

Your mission:

We are looking for a VP Information Security to lead security for the Group — someone equally comfortable setting security strategy and reporting to a regulated Board as they are running the SOC day to day.

This is a hybrid role by design: for one of our regulated entities, you'll act as the appointed CISO, owning the cybersecurity framework and the regulatory relationship. Across the wider Group, you'll build and run operational security day to day — the SIEM, detection, and incident response.

In this role, you will:

Security leadership & regulatory ownership

  • Own the cybersecurity framework Continuously improve strategy, policies, risk register and controls, reviewing and updating them at least annually against the evolving threat landscape.
  • Run the cyber risk-management lifecycle Maintain the asset inventory, run risk assessments, monitor on an ongoing basis, and report regularly to the Board on the risks that matter, working closely with Risk Controlling on second-line risk oversight.
  • Lead regulatory incident notification Notify our regulator when required, keep affected parties informed, and work closely with our Data Protection Officer whenever personal data is involved.
  • Set security standards Maintain baseline security-configuration and access-control standards, and commission independent vulnerability scans and penetration tests at least annually and after major changes.
  • Own vendor and outsourcing security due diligence Including for cloud providers.
  • Build our security culture Run a group-wide security awareness programme, and make sure the security function is properly resourced.
  • Support independent assurance Help the Board approve the security audit plan and enable independent reviews of our cyber resilience.
  • Be the voice of security Act as the primary point of contact for the Board and all internal functions on cyber risk, and act as CISO in representing the relevant regulated entity to our regulator on IT security matters.

What you need to be successful:

  • Ideally 5+ years in information security or similar roles, with a genuine mix of hands-on SOC / detection-engineering work and governance or senior-management-level accountability. We need both, not one alone.
  • A track record owning a cybersecurity framework in a regulated environment that requires senior-level reporting and regulatory incident notification (financial services, VASP, e-money or comparable).
  • Real, practical experience owning a SIEM (design, tuning, operation) and leading incident response, not just overseeing a vendor who does this.
  • You're comfortable being a named, accountable CISO to a regulator, subject to fit and proper assessment, and presenting directly to a Board.
  • Some major parts of fit-and-proper assessment are: a clean regulatory and criminal record (probity checks cover criminal history, sanctions and disciplinary action), no disqualification from a director or senior-management role, and sound personal finances; experiences in security roles, ideally in regulated environments, must be demonstrable.
  • We expect you to be in our office in Vilnius for 2-3 days per week, as we are growing a local team incl. an in-office culture

Nice to have

  • CISSP, CISM or equivalent.
  • SANS/GIAC or other operational security certifications.
  • Prior exposure to regulatory regimes.

What’s in it for you:

  • Build on a mature foundation Inherit an established security setup and develop it further as our product and customer base grow.
  • Shape a founding LT culture Be one of the early members of Finoa's LT Team, with real influence over how security collaborates with our groups engineering, compliance and risk teams.
  • Grow with the role As the business scales, the scope grows with you rather than staying fixed.
  • Move fast, stay rigorous Work in a fast-paced environment while holding the line on regulatory and security requirements.
  • Direct exposure to the Board Unfiltered reporting lines give you real visibility and feedback at the highest level.
  • A broad set of stakeholders Work daily across engineering, compliance, legal and risk, and across our different jurisdictions and entities.

The salary band for this role is €5,500 - €6,600 a month (before tax deduction).

The final offer will depend on the experience and competencies of the selected candidate. The overall remuneration package consists of the salary together with other benefits.

Diversity & Inclusion:

Finoa is an equal opportunity employer devoted to diversity and inclusion in the workplace. We genuinely welcome and encourage applications from people of all backgrounds, cultures, genders, sexual orientations, abilities, neurodiversities, and ages.

Data Privacy:

Finoa processes candidate data in accordance with GDPR.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against finoa's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on finoa's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    finoa's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.