VP Information Security
Finoa is a technology infrastructure provider that helps regulated custodians and institutional investors manage digital assets securely.
Funding history
About Finoa
Finoa provides technology infrastructure enabling regulated virtual asset service providers to store and manage client digital assets. Users can access fully segregated wallets, multi-signature workflows for governance policies, and on-chain transaction verification across a wide range of digital assets. Formerly a BaFin-licensed crypto-asset custodian, the company rebranded to Finoa Technical Services following the surrender of its custody license in December 2025.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will lead cybersecurity strategy and operational security. You will maintain the cybersecurity framework, manage cyber risk, report to the Board, lead regulatory incident notifications, set security standards, oversee vendor due diligence, run security awareness activities, and operate SIEM and incident-response processes.
Requirements
- Ideally 5+ years of information security experience combining hands-on SOC or detection-engineering work with governance or senior-management accountability
- Experience owning a cybersecurity framework in a regulated environment with senior-level reporting and regulatory incident notification
- Practical SIEM design, tuning, and operational experience
- Experience leading incident response
- Ability to serve as an accountable CISO to a regulator and present directly to a Board
- Clean regulatory and criminal record, no disqualification from director or senior-management roles, and sound personal finances
- Demonstrable security experience, ideally in regulated environments
- Ability to work from the Vilnius office 2–3 days per week
Responsibilities
- Own and continuously improve the cybersecurity strategy, policies, risk register, and controls
- Maintain the asset inventory, conduct risk assessments, monitor risks, and report to the Board
- Lead regulatory incident notification and coordinate with the Data Protection Officer when personal data is involved
- Maintain baseline security-configuration and access-control standards
- Commission independent vulnerability scans and penetration tests
- Own vendor and outsourcing security due diligence, including cloud providers
- Run a group-wide security awareness programme and ensure security resources are adequate
- Support Board approval of the security audit plan and independent cyber-resilience reviews
- Act as the primary contact for cyber risk and represent the regulated entity to the regulator on IT security matters
