Role in brief
Bitpanda is seeking a Director of Information Security to lead and expand its Governance, Risk, and Compliance (GRC) function. This role involves defining security strategy, overseeing security programs, and ensuring regulatory compliance within a fintech environment. Candidates with extensive experience in information security leadership, regulated industries, and GRC frameworks should apply to protect Bitpanda's information assets and scale its security posture.
About the role
This Director of Information Security will be responsible for safeguarding Bitpanda's information assets, ensuring their protection, integrity, and confidentiality. The role involves leading and developing the GRC function, managing the operating rhythm for risk, controls, audits, and third-party oversight. The director will ensure continuous audit readiness while scaling security practices responsibly.
The position requires a hands-on leader who can define the multi-year information security strategy and roadmap, aligning it with business objectives and regulatory requirements. This includes establishing security governance, managing enterprise security risks, and reporting to the board. The director will also lead and scale security capabilities across various domains like Security Operations, Application Security, Cloud Security, and Identity and Access Management.
A key aspect of this role is overseeing compliance and regulatory engagement, including external and internal assurance programs such as ISO 27001 and SOC 2. The director will lead regulatory interactions, integrate security requirements with broader compliance obligations, and manage third-party and supply chain security. Success in this role involves effective stakeholder management, communicating security risks in business terms, and fostering a strong security culture across the company.
The salary for this position ranges from $185,000 to $284,000 USD annually, in addition to participation in a stock option plan.
Skills that matter here
- information security: The role requires 10-15+ years of experience in this field, including leadership and stakeholder management.
- GRC: This role will manage and grow the GRC function, overseeing its operating rhythm including risk, controls, audits, and third-party oversight.
- regulated environments: The candidate needs demonstrated success building security programs in regulated settings, preferably fintech or financial services.
- ICT related regulatory frameworks: Experience with implementing frameworks like DORA and BaFin is required for compliance.
- ISO 27001: Extensive experience with this assurance framework is needed, including translating its requirements into operational programs.
- SOC 2: The role requires extensive experience with this assurance framework, including translating its requirements into operational programs.
Who this role suits
- A leader with a proven track record of building and scaling security programs in regulated financial environments.
- Someone who can effectively communicate complex security risks and strategies to both technical teams and executive leadership.
- An individual who thrives in a hands-on leadership role, balancing strategic direction with direct team development and operational oversight.
- A professional adept at navigating and ensuring compliance with various security frameworks and regulatory requirements.
From the employer
Your mission
As a Director, Information Security your mission will be to ensure the protection, integrity, and confidentiality of our organisation’s information assets. You will manage and grow our GRC function in a regulated fintech environment. You’ll lead a small team (e.g., Associates to Senior Specialists), own the GRC operating rhythm (risk, controls, audits, third-party oversight), and ensure we stay continuously audit-ready while scaling responsibly. This is a hands-on leadership role: you will set direction, coach and develop the team, and partner with senior stakeholders across Technical Operations, Engineering, IT, Compliance, Risk, Legal, and Procurement to drive effective, proportionate security governance.
What you’ll do
- Strategy, governance & risk accountability: Define and maintain the multi-year information security strategy and roadmap aligned with business objectives, risk appetite, and regulatory requirements. Establish security governance: decision forums, risk acceptance thresholds, exception processes, and clear accountability across the organization. Ensure effective enterprise security risk management, including identification of material risks, treatment plans, and board-level reporting.
- Security program leadership (end-to-end): Lead, scale and oversee security capabilities across domains (GRC/ISMS, Security Operations, AppSec, Cloud/Infrastructure Security, IAM, Security Architecture). Ensure security is embedded into product and engineering delivery (secure SDLC, threat modeling, security-by-design guardrails). Define security standards, controls and minimum baselines; drive consistent implementation across entities, regions, and critical systems.
- Compliance, audits & regulatory engagement: Oversee external and internal assurance programs (e.g., ISO 27001, SOC 2, PCI DSS, partner assurance) and ensure continuous audit readiness. Lead/coordinate security-facing regulatory engagement: examinations, requests for information, remediation commitments, and follow-ups. Ensure security requirements are integrated with broader compliance obligations and operational resilience expectations.
- Third-party & supply chain security: Set third-party security strategy for critical suppliers (due diligence, ongoing monitoring, contractual security requirements, and exit/continuity considerations). Ensure oversight of outsourcing/critical ICT providers consistent with regulatory expectations and business criticality.
- Stakeholder management & security culture: Act as an advisor at all levels: communicate security risk in business terms and drive alignment on tradeoffs. Partner with Engineering, Product, IT, Compliance, Risk, Legal, Procurement, and Internal Audit to deliver outcomes. Champion security awareness and accountability across the company.
Who you are
- Typically 10–15+ years in information security, including leadership of multiple security domains and senior stakeholder management.
- Demonstrated success building and scaling security programs in regulated environments (fintech/financial services preferred).
- Experience in implementing ICT related regulatory frameworks (e.g. DORA, BaFin).
- Strong grasp of security governance and risk management, plus practical understanding of modern cloud/security architecture and engineering practices.
- Proven experience with incident leadership and crisis management.
- Extensive experience with assurance and frameworks (e.g., ISO 27001, SOC 2, NIST), including translating requirements into operating programs.
- Excellent executive and technical communication: able to brief board/executive audiences and represent the company externally, as well as being able to discuss technical requirements and implementations with the First Line of Defence (1LoD).
What’s in it for you
- Flexibility to work where you thrive – Enjoy the freedom of our Hybrid working model, combining onsite collaboration and remote work, with an additional 25 days per year to work from a city or country of your choice.
- Reward for your impact – Receive a competitive total compensation package aligned with Bitpanda’s pay-for-impact policy, including participation in our stock option plan.
- Support for your mental wellbeing – Access confidential coaching, counselling, and mental health resources whenever you need them through OpenUP.
- Time to recharge – Take extra time off to rest, reset, and recharge, with 3 additional days off in 2026 to prioritise your wellbeing.
- Continuous learning and growth – Grow your skills and stay ahead in your career with unlimited access to Udemy’s library of online courses at your own pace.
- Exclusive perks and rewards – Enjoy discounts, rewards, and perks from partners worldwide across lifestyle, wellness, tech, and travel.
- Support during life milestones – Take advantage of our additional 8 weeks of gender-neutral new parent leave to welcome and bond with your new addition to the family.
- Create a productive workspace at home – Set up your home office exactly how you want it with a dedicated budget for comfort and productivity.
- Fuel and focus on-site – Pandas in Vienna, Bucharest, Barcelona, and Berlin can enjoy free onsite dining, with freshly prepared lunches and snacks to keep you fuelled and focused all day long.
- Recognition for your contributions – Celebrate milestones and achievements with recognition and rewards for your Tenure at Bitpanda.
- Show your Bitpanda pride – Access exclusive Bitpanda-branded merchandise and gear to represent.
- Connect and celebrate with your team – Join unforgettable company events, from our Winter Party in Vienna to summer gatherings worldwide, fostering fun, connection, and celebration.
Questions about this role
What is the remote work policy for this role?
This role offers a hybrid working model, combining onsite collaboration with remote work, plus 25 days per year to work from a location of your choice.
What level of seniority is this position?
This is a head-level position, specifically a Director of Information Security.
What kind of experience is required for this role?
Candidates should typically have 10-15+ years in information security, with leadership experience in multiple security domains and senior stakeholder management, particularly in regulated fintech environments.