Transak

Information Security Officer

Full-Time in Austria - Information Security - €100,000 – €130,000 / year

About the company:

Our mission is that "Any financial application can onboard any user, anywhere in the world, in 1 click." Transak provides onboarding to financial applications through authentication, KYC, risk checks, and fiat on/off ramps. This is a next generation of infrastructure for the next generation of financial applications that are built on blockchain and stablecoin rails. Our API and widget-based solutions are used by top partners like MetaMask, Coinbase, Ledger, and Trust Wallet to enable seamless onboarding of over 10 million users across over 450 active applications.

We have raised over $37M from top-tier investors including Consensys, Tether, and Animoca Brands.

About the Role:

Transak operates regulated entities across the EU, MENA and the US. Security controls are owned and operated by the first line such as DevOps, IT and engineering teams. Independent oversight of whether those controls actually work, whether they satisfy the obligations Transak is licensed under, and what residual risk the business is carrying, sits in the second line with the CISO.

This role joins that second line, reporting to the CISO and working closely with the Risk and Compliance functions. You will not build or operate security controls. You will test whether they work, and say so when they do not. There is no established testing programme to inherit: you will design it, run it, and make it credible to an auditor.

What You'll Be Doing

As Transak's first dedicated second-line information security hire, you will provide independent assurance over the security controls the business relies on. Your responsibilities include:

  • Design and run a risk-based control testing programme over first-line security controls, with a defined cycle, scope and sampling approach.
  • Test the control, pull the evidence, sample the population, re-perform where feasible, and form an independent conclusion.
  • Focus testing where it matters most for a fiat on and off ramp: privileged access and segregation of duties, access recertification, change and release approval, backup and restore, incident response execution, and ICT third-party oversight.
  • Maintain the mapping between regulatory obligation and implemented control across MiCA, DORA, SOC 2 and ISO 27001.
  • Cover the regional regimes applying to the MENA and US entities, rather than assuming EU compliance is a superset, and surface obligations with no owning control as gaps.
  • Run the information security and ICT risk register alongside the Risk function, using the group risk taxonomy rather than a security-only one.
  • Challenge first-line risk ratings and acceptances, including testing whether the compensating controls cited actually operate.
  • Produce assurance reporting for committee and board that distinguishes what has been independently tested from what has been asserted by the first line.
  • Act as the internal counterpart to external audit and regulatory examination, and run readiness assessments so that findings are known internally before they are found externally.
  • Operate as one second line with Risk and Compliance - shared register, shared obligation mapping, and the first line asked once for evidence.
  • Translate between technical control and regulatory obligation, so colleagues in Risk and Compliance do not need to interpret a cloud or identity control themselves.

What We're Looking For

Core Experience:

  • 5+ years in a second-line, technology risk, IT audit or security assurance role, with meaningful time in a regulated financial institution.
  • Has independently tested technical security controls - designed the test, sampled the population, formed an own conclusion.
  • Deep working knowledge of at least one financial services regime, and the ability to translate a specific article into a testable control and the evidence that proves it.
  • Practical understanding of identity and access, cloud, change and resilience controls, sufficient to test them credibly and to recognise an incomplete first-line answer.
  • Risk register ownership: rating methodology, escalation thresholds, and reporting into a governance forum.
  • Experience producing assurance reporting for a committee or board audience.
  • Comfortable acting as the internal counterpart to external audit or a regulatory examination.
  • Willing to hold a finding under pressure from a senior stakeholder, with the judgement to do so without damaging the working relationship.
  • Excellent communication skills, able to move between an engineering audience and a board audience.
  • Comfortable building a programme from nothing rather than inheriting a mature one.

Bonus:

  • Cryptoasset, VASP, payments or neobank experience, particularly under MiCA or an equivalent regime.
  • Multi-jurisdiction experience covering MENA or the US.
  • Familiarity with ICT risk under DORA and its regulatory technical standards.
  • Prior first-line security experience, giving credibility with engineers, provided independence is understood.
  • Experience of a firm going through a licence application or authorisation gateway.
  • Certifications such as CISSP, CISA, CRISC, CISM, CIA or ISO 27001 Lead Auditor.
  • Experience standing up a second-line function where none existed.

Why join us

  • Equity options so you can share in the success of the company
  • A fast-moving, fun, and international company made up of skillful team players
  • Transparent, Open, and Collaborative work environment
  • A competitive compensation package and comprehensive benefits offering