Information Security Officer
Transak is payments infrastructure for stablecoins and crypto, enabling financial applications to provide fiat-to-crypto and crypto-to-fiat flows, virtual-account payments, compliance, and settlement.
Maintainer signals as of 9/2/2026
Funding history
Projects
About Transak
Transak provides API- and widget-based crypto payment infrastructure for financial applications. Its offering covers on-ramp, off-ramp, NFT checkout, virtual-account payments, OTC trading, KYC, compliance, payment-method integration, and stablecoin settlement across multiple jurisdictions and blockchain networks.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will design and operate a risk-based security control testing programme. You will test controls, assess evidence, sample populations, document independent conclusions, maintain regulatory control mappings, manage information security and ICT risk registers, challenge risk decisions, produce assurance reports, support audits and examinations, and translate technical controls into clear regulatory obligations.
Requirements
- 5+ years in second-line technology risk IT audit or security assurance roles
- Meaningful experience in a regulated financial institution
- Experience independently testing technical security controls
- Deep knowledge of at least one financial services regulatory regime
- Ability to translate regulatory articles into testable controls and evidence
- Practical understanding of identity and access cloud change and resilience controls
- Experience owning risk registers and reporting to governance forums
- Experience producing assurance reports for committee or board audiences
- Experience supporting external audits or regulatory examinations
- Judgement to maintain findings under senior stakeholder pressure
- Excellent communication skills for engineering and board audiences
- Ability to build a programme from scratch
- Cryptoasset VASP payments or neobank experience is advantageous
- Multi-jurisdiction experience covering MENA or the US is advantageous
- Familiarity with ICT risk under DORA is advantageous
- Prior first-line security experience is advantageous
- Experience with licence applications or authorisation gateways is advantageous
- CISSP CISA CRISC CISM CIA or ISO 27001 Lead Auditor certification is advantageous
- Experience establishing a second-line function is advantageous
Responsibilities
- Design and run a risk-based security control testing programme
- Test controls gather evidence sample populations and re-perform procedures
- Assess privileged access segregation of duties and access recertification
- Test change and release approval backup and restore and incident response controls
- Assess ICT third-party oversight
- Map regulatory obligations to implemented controls
- Identify obligations without an owning control
- Maintain information security and ICT risk registers
- Challenge first-line risk ratings and risk acceptances
- Verify the operation of compensating controls
- Produce assurance reporting for committees and boards
- Run readiness assessments for audits and regulatory examinations
- Coordinate evidence requests across Risk and Compliance
- Translate technical controls into regulatory requirements
Benefits
- Equity options
- Comprehensive benefits offering
