Chief Information Security Officer
Cryptopay provides crypto-payment services for businesses. Its offerings include accepting cryptocurrency, payment-gateway integrations, account management, corporate crypto cards, and mass crypto payouts for businesses ranging from startups to enterprises.
Funding history
Investors
About Cryptopay
Cryptopay is a crypto payments company offering businesses a payment gateway for accepting 19 major cryptocurrencies, with real-time conversion, bank settlement, reporting, payment tools, and account management. It also provides payment APIs and integrations, corporate crypto cards, and mass payout capabilities. The company serves e-commerce, SaaS, iGaming, Web3, consulting, gaming, tourism, real estate, and other business clients.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will establish and mature the information security program, including policies, governance, risk management, DORA readiness, security reporting, and incident response. You will independently audit security controls, review release and architecture risks, oversee testing, and support regulatory and client audits.
Requirements
- Bachelor's or Master's degree in IT, Computer Science, Cybersecurity, or a related field
- 5+ years of information security leadership experience, preferably as a CISO in regulated financial services or regulated SaaS
- Deep knowledge of ISO/IEC 27001:2022, DORA, ISMS, risk management, and security controls
- Understanding of AWS cloud security, network segregation, VPC design, multi-tenant database isolation, and IAM principles
- CISSP, CISM, CRISC, or equivalent professional certification
- Strong verbal and written English communication skills
Responsibilities
- Establish and maintain security policies and procedures, including SDLC policies, aligned with ISO/IEC 27001:2022
- Act as the independent security gatekeeper under ISO 27001
- Manage the Information Security Risk Register and track technology risk acceptance and structural vulnerabilities
- Own the DORA-ready validation program and ensure compliance with contractual DORA provisions
- Maintain the DORA Data Sheet and subcontractor registers
- Implement and support security dashboards and reporting for DORA-regulated clients
- Govern the security incident response process and define notification targets and SLA thresholds
- Ensure incident workflows escalate root-cause analyses and affected data categories in time for major-incident reporting
- Perform independent quarterly audits of administrative access logs and permission changes
- Review and sign off on technical risk profiles for system releases and architectural changes
- Review and continuously improve the SDLC setup
- Implement and support threat-driven penetration and business continuity testing
- Serve as the technical point of contact for CSSF examiners and external ISO 27001 auditors
- Coordinate client audit teams' annual reviews of the ISMS and BCDR plans
Benefits
- Hybrid work arrangement in Cyprus
