Skip to content

Open nowPosted 29 days ago

Information Security Officer

transak-inc13 open roles

Where
Austria
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowInformation Security Officertransak-inc · Austria
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on transak-inc's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.1%30 days
This job: posted 29 days ago

The posting

About the company:

Our mission is that "Any financial application can onboard any user, anywhere in the world, in 1 click." Transak provides onboarding to financial applications through authentication, KYC, risk checks, and fiat on/off ramps. This is a next generation of infrastructure for the next generation of financial applications that are built on blockchain and stablecoin rails. Our API and widget-based solutions are used by top partners like MetaMask, Coinbase, Ledger, and Trust Wallet to enable seamless onboarding of over 10 million users across over 450 active applications.

We have raised over $37M from top-tier investors including Consensys, Tether, and Animoca Brands.

About the Role:

Transak operates regulated entities across the EU, MENA and the US. Security controls are owned and operated by the first line such as DevOps, IT and engineering teams. Independent oversight of whether those controls actually work, whether they satisfy the obligations Transak is licensed under, and what residual risk the business is carrying, sits in the second line with the CISO.

This role joins that second line, reporting to the CISO and working closely with the Risk and Compliance functions. You will not build or operate security controls. You will test whether they work, and say so when they do not. There is no established testing programme to inherit: you will design it, run it, and make it credible to an auditor.

What You'll Be Doing

As Transak's first dedicated second-line information security hire, you will provide independent assurance over the security controls the business relies on. Your responsibilities include:

  • Design and run a risk-based control testing programme over first-line security controls, with a defined cycle, scope and sampling approach.
  • Test the control, pull the evidence, sample the population, re-perform where feasible, and form an independent conclusion.
  • Focus testing where it matters most for a fiat on and off ramp: privileged access and segregation of duties, access recertification, change and release approval, backup and restore, incident response execution, and ICT third-party oversight.
  • Maintain the mapping between regulatory obligation and implemented control across MiCA, DORA, SOC 2 and ISO 27001.
  • Cover the regional regimes applying to the MENA and US entities, rather than assuming EU compliance is a superset, and surface obligations with no owning control as gaps.
  • Run the information security and ICT risk register alongside the Risk function, using the group risk taxonomy rather than a security-only one.
  • Challenge first-line risk ratings and acceptances, including testing whether the compensating controls cited actually operate.
  • Produce assurance reporting for committee and board that distinguishes what has been independently tested from what has been asserted by the first line.
  • Act as the internal counterpart to external audit and regulatory examination, and run readiness assessments so that findings are known internally before they are found externally.
  • Operate as one second line with Risk and Compliance - shared register, shared obligation mapping, and the first line asked once for evidence.
  • Translate between technical control and regulatory obligation, so colleagues in Risk and Compliance do not need to interpret a cloud or identity control themselves.

What We're Looking For

Core Experience:

  • 5+ years in a second-line, technology risk, IT audit or security assurance role, with meaningful time in a regulated financial institution.
  • Has independently tested technical security controls - designed the test, sampled the population, formed an own conclusion.
  • Deep working knowledge of at least one financial services regime, and the ability to translate a specific article into a testable control and the evidence that proves it.
  • Practical understanding of identity and access, cloud, change and resilience controls, sufficient to test them credibly and to recognise an incomplete first-line answer.
  • Risk register ownership: rating methodology, escalation thresholds, and reporting into a governance forum.
  • Experience producing assurance reporting for a committee or board audience.
  • Comfortable acting as the internal counterpart to external audit or a regulatory examination.
  • Willing to hold a finding under pressure from a senior stakeholder, with the judgement to do so without damaging the working relationship.
  • Excellent communication skills, able to move between an engineering audience and a board audience.
  • Comfortable building a programme from nothing rather than inheriting a mature one.

Bonus:

  • Cryptoasset, VASP, payments or neobank experience, particularly under MiCA or an equivalent regime.
  • Multi-jurisdiction experience covering MENA or the US.
  • Familiarity with ICT risk under DORA and its regulatory technical standards.
  • Prior first-line security experience, giving credibility with engineers, provided independence is understood.
  • Experience of a firm going through a licence application or authorisation gateway.
  • Certifications such as CISSP, CISA, CRISC, CISM, CIA or ISO 27001 Lead Auditor.
  • Experience standing up a second-line function where none existed.

Why join us

  • Equity options so you can share in the success of the company
  • A fast-moving, fun, and international company made up of skillful team players
  • Transparent, Open, and Collaborative work environment
  • A competitive compensation package and comprehensive benefits offering
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against transak-inc's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on transak-inc's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    transak-inc's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.