Head of Technology & Security – Brazil

OSL

São Paulo

Presencial

BRL 720 000 - 1 080 000

Tempo integral

14 dias+
Gerador de candidaturas

Transforma esta função numa entrevista — um currículo e uma carta de apresentação criados à volta do que este empregador procura.

Ultrapassa os filtros ATS

Resumo da oferta

OSL in Austria seeks a Head of Technology & Security to own the ICT, cyber security and compliance framework from day one. You will lead the technology function, oversee security controls and incident response, and ensure alignment with DORA and GDPR in a regulated financial setting.

You will build from the ground up, inheriting a policy framework and a global function, while shaping local security posture and technology delivery for crypto custody and wallet systems.

Qualificações

  • 7–10 years in technology and information security with leadership at senior level (Head/CISO)
  • Experience in regulated financial services, fintech, payments or crypto environments
  • Autonomous leadership and ability to set standards
  • Deep knowledge of DORA and regulatory reporting; familiarity with MiCAR and GDPR
  • Hands-on expertise across cyber security, cloud, network and endpoint security, encryption, IAM
  • Crypto-asset custody tech knowledge is a strong plus
  • Experience managing ICT third-party providers and cloud security in a regulated context
  • Strong policy-to-controls discipline and audit-ready documentation
  • Excellent leadership and communication; fluent English; German is a plus

Responsabilidades

  • Own the cyber security and operational resilience of ICT systems, act as CISO, set security baselines and access controls
  • Lead end-to-end incident response including detection, containment, forensics and recovery
  • Be the senior technology and security voice with access to Management Board
  • Own compliance with DORA and GDPR from tech/security perspective
  • Lead technology/engineering functions: ICT infrastructure, architecture, releases, change management
  • Oversee penetration testing, vulnerability management, monitoring and security events
  • Manage ICT third-party and cloud security, IAM, and least-privilege access reviews
  • Translate tech risk for non-technical stakeholders and report to Senior Representative/Board
  • Build and lead the Technology & Security team as the entity scales

Conhecimentos

Cyber security
Cloud security
Identity & access management
Incident response
Leadership
DORA knowledge
Encryption
Stakeholder communication

Ferramentas

Cloud platforms
Security testing tools

Descrição da oferta de emprego

This is a rare chance to own technology and security end to end at the birth of a regulated European crypto entity, with the autonomy to build it your way and the backing of an established, publicly listed global group. We are looking for a Head of Technology & Security to take full ownership of the technology, infrastructure and cyber security of our newly licensed Austrian entity.

You will act as the entity's CISO and lead the Technology & Security function, covering technology and engineering, IT security, and infrastructure. You will own our compliance with DORA and the wider ICT regulatory framework, set the security baseline, lead incident response, and build the technology function as the entity scales from launch toward its full operating model.

You will not be starting from a blank page. You will inherit a strong policy framework and the backing of an established global technology function, and take local ownership, turning documented controls into a live, operating, audit-ready technology environment. The ideal candidate combines deep technical and security expertise with the judgment to operate in a regulated financial environment and the drive to build a function from the ground up.

Key Responsibilities
  • Own the cyber security and operational resilience of the entity's ICT systems and data, acting as CISO, setting security baselines, access controls, encryption standards and secure configuration across all ICT assets.
  • Lead incident response end to end. Detection, containment, forensic investigation and recovery, ensuring ICT-related incidents are classified, documented and reported in line with DORA.
  • Sit as the senior technology and security voice in the entity, with direct access to the Management Board and genuine authority over technology decisions and priorities.
  • Own the entity's compliance with DORA, the associated Delegated Regulations and GDPR from a technology and security perspective, keeping the policy framework current and demonstrably implemented.
  • Lead the technology and engineering function. ICT infrastructure, system architecture, releases and change management, ensuring stable, scalable and secure operations, and supporting the security of wallet and custody technology alongside the safeguarding function and group.
  • Oversee penetration testing, vulnerability management, continuous monitoring and security event detection, and ensure secure backup, recovery and business continuity measures are in place and regularly tested.
  • Own ICT third-party and cloud security from a technical perspective, and manage identity and access across systems (SSO, MFA, least-privilege, access reviews) as the technical backbone of the control environment.
  • Work across Operations, Legal & Compliance, Risk and group technology, translating technical and security risk into clear terms for non-technical stakeholders, and report on security posture, incidents and ICT risk to the Senior Representative and Management Board, supporting internal and external audits.
  • Build, develop and lead the Technology & Security team as the entity scales.
Requirements
  • 7-10 years of experience in technology and information security, including leadership at Head or CISO level (or equivalent senior security role).
  • Strong background in a regulated financial services, fintech, payments or crypto environment, ideally within the EU or Austria.
  • Able to define what good looks like in this domain and operate autonomously, setting the standard rather than waiting for direction.
  • Deep working knowledge of DORA, including incident classification and regulatory reporting, plus the associated ICT risk-management requirements; familiarity with MiCAR and GDPR.
  • Hands-on expertise across cyber security, cloud infrastructure, network and endpoint security, encryption and identity and access management.
  • Understanding of crypto-asset custody technology such as wallet architecture, key management and signing security is a strong advantage.
  • Experience managing ICT third-party providers and cloud security in a regulated context.
  • Strong process and documentation discipline, able to turn a policy framework into demonstrable, audit-ready controls.
  • Comfortable in a fast-moving, build-from-scratch environment with evolving regulatory requirements.
  • Excellent leadership and communication skills, able to work across functions and report credibly to the board and regulators.
  • Fluency in English is required; German is an advantage.
Why this role

Few roles offer this mix: the autonomy of building a function yourself, the safety of an established global group behind you, and the challenge of getting a regulated crypto platform right from day one. You will take local ownership of a strong regulatory framework, secure the systems that safeguard client assets, and build the technology function that the whole business runs on. If you are a senior technologist who wants genuine ownership, a regulated environment worth getting right, and the chance to build a high-performing team from the start, we would like to hear from you.

Obtém a tua avaliação gratuita e confidencial do currículo.
ou arrasta e larga o ficheiro aqui.
Similar jobs

Ofertas semelhantes que vale a pena comparar

Head of Cyber Security
Head of Cyber Security

OSL • São Paulo

Presencial
BRL 150 000 - 230 000
Head of Risk, Brazil
Head of Risk, Brazil

OSL • Brasil

Presencial
BRL 900 000 - 1 400 000
Security Engineer, Lead
Security Engineer, Lead

DolarApp • São Paulo

Híbrido
BRL 180 000 - 360 000
Competitive salary
Stock options
Discretionary performance bonus
+4
Regulatory Compliance Manager (Crypto)
Regulatory Compliance Manager (Crypto)

Revolut • Nova Santa Rita

Presencial
BRL 250 000 - 350 000
Chief Information Security Officer - Brazil
Chief Information Security Officer - Brazil

Crypto Pro Network • São Paulo

Híbrido
BRL 200 000 - 300 000
Competitive salary
Work-from-home arrangement
Senior DevSecOps Engineer - São Paulo Based
Senior DevSecOps Engineer - São Paulo Based

1GLOBAL • São Paulo

Presencial
BRL 327 690 - 655 380
Growth Opportunities
Dynamic Work Environment
Professional Development
+2
Security Engineer, Mid
Security Engineer, Mid

ARQ • São Paulo

Presencial
BRL 180 000 - 240 000
Stock options
Discretionary performance bonus
Latest tools and technology
+2
Information Security Officer
Information Security Officer

Playtech • São Paulo

Híbrido
BRL 180 000 - 240 000
Health insurance
Food vouchers
Travel allowances
+2
Security Architect
Security Architect

Eurofins • Belo Horizonte

Presencial
BRL 150 000 - 210 000
Security Engineer, Mid
Security Engineer, Mid

DolarApp • São Paulo

Híbrido
BRL 150 000 - 190 000
Stock options
Discretionary performance bonus
In-office 3-4 days a week