Chief Information Security Officer (CISO)

Cybermindspace

München

Hybrid

EUR 150,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Hawk is seeking a technically grounded, hands-on CISO to own our global security posture end-to-end. You will lead a four-domain security organization including Application Security, Corporate Security, Compliance & Governance, and Data Protection, and work closely with banking CISOs to drive secure, compliant growth.

You will review cloud architecture, triage high‑severity vulnerabilities, and command critical incident responses. A strong background in ISO 27001, SOC 2, and DORA is essential.

Qualifications

  • Hands-on security leadership with CISO experience in regulated markets.
  • Experience with ISO 27001, SOC 2 Type II, and DORA compliance.
  • Ability to translate security into enterprise value and sales enablement.
  • Strong collaboration with executive leadership and customers.

Responsibilities

  • Lead security engineering, AI hardening, and secure SDLC practices.
  • Own Zero Trust, IAM/SSO and cloud infrastructure security.
  • Manage risk registry, audits, and multi‑jurisdiction governance.
  • Act as incident commander during Sev‑1/Sev‑2 security events.

Skills

Hands-on security
CISO leadership
Zero Trust
IAM/SSO
Cloud security
Incident response
Threat hunting
Secure SDLC
CI/CD security
Compliance governance

Tools

AWS
GCP
Kubernetes
EDR/XDR

Job description

About Us

Hawk is the leading provider of AI-supported anti-money laundering and fraud detection technology. Banks and payment providers globally are using Hawk’s powerful combination of traditional rules and explainable AI to improve the effectiveness of their AML compliance and fraud prevention by identifying more crime while maximizing efficiency by reducing false positives. With our solution, we are playing a vital role in the global fight against Money Laundering, Fraud, or the financing of terrorism. We offer a culture of mutual trust, support and passion – while providing individuals with opportunities to grow professionally and make a difference in the world.

Hawk builds AI-powered financial crime detection (AML, transaction monitoring, and fraud prevention) for global tier-1 banks, payment processors, and high-growth fintechs. Because our platform analyzes real-time payment streams and sensitive financial data, security is not an administrative support function—it is our primary product promise.

We are looking for a technically grounded, hands‑on CISO to own our global security posture end‑to‑end. This is a true player‑coach leadership role. You will lead a dedicated team of four domain specialists while staying close enough to the technology to review cloud architecture, triage high‑severity vulnerabilities, command critical incident responses first‑hand, and debate technical security controls peer‑to‑peer with customer bank CISOs.

Why This Role Matters
  • Global Regulatory Scrutiny at Scale: We operate across key financial hubs including Germany, the UK, the US, Singapore, and a growing roster of international markets. With DORA enforceable across the EU and heightened ICT risk rules globally, our banking clients expect documented operational resilience, continuous testing, and verified controls across all jurisdictions.

  • Modern Attack Surfaces & Supply Chain Threats: Our multi‑tenant and single‑tenant cloud environments (AWS/GCP) process massive transaction throughput. Alongside defending against emerging supply chain vulnerabilities—from open‑source dependencies to third‑party build pipelines—you will need to deeply understand our AI approach and actively help harden our tooling, harnesses, and pipelines.

  • Enterprise Deal Velocity: Enterprise security reviews can either stall deals or close them. You will partner with our commercial teams to turn security questionnaires, risk mitigation, and architecture audits into enterprise trust and closed contracts.

Organizational Structure: The Four Domains

You will lead, mentor, and set technical direction for four specialized functional areas:

  1. Application Security: Secure SDLC, automated CI/CD security gates (SAST/DAST/SCA), software supply chain defense, secure coding standards, AI harnesses and pipeline hardening.

  2. Corporate Security: Zero Trust architecture, IAM/SSO, distributed endpoint defense (EDR/XDR), threat hunting, infrastructure access.

  3. Compliance & Governance: DORA implementation, ISO 27001, SOC 2 Type II, Third‑Party Risk Management (TPRM), multi‑jurisdiction regulatory audits, risk registry ownership.

  4. Data Protection: Solely dedicated to data protection: GDPR compliance, privacy governance, data subject rights, and statutory privacy regulatory requirements.

Core Accountabilities

1. Hands‑On Technical Leadership, Engineering Integration & AI Hardening

  • Secure Coding Standards & SDLC: Establish and enforce secure coding baselines directly within engineering workflows. Ensure automated vulnerability scanning, SBOM tracking, and security gates are integrated into GitHub/GitLab CI/CD pipelines.

  • Software Supply Chain Defense: Protect build systems, dependencies, and deployment pipelines against supply chain tampering, compromised packages, and upstream vulnerabilities.

  • AI Tooling & Pipeline Hardening: Deeply understand our AI approach and work closely with engineering to harden our systems. Personally evaluate and implement protective mechanisms—including secure AI harnesses, container sandboxing, and runtime guardrails around AI tooling and workflows.

  • Vulnerability Lifecycle Management: Set strict remediation SLAs for CVEs and cloud misconfigurations. Directly arbitrate vulnerability severity, triage zero‑days, and collaborate with engineering leads to ensure rapid remediation without stalling release velocity.

  • Zero Trust & Cloud Infrastructure: Architect and drive our group‑wide Zero Trust roadmap across AWS and GCP environments, enforcing least‑privilege IAM policies, network micro‑segmentation, and secure developer access.

2. Commercial Trust & Customer Engagement

  • Peer‑to‑Peer Customer Dialogue: Act as the senior technical authority in enterprise sales cycles, engaging directly with bank CISOs, InfoSec panels, and procurement leads to validate Hawk's architecture, threat models, and operational controls.

  • Accelerating Enterprise Deal Velocity: Modernize vendor due diligence by replacing reactive security questionnaires with standardized evidence packages, continuous compliance portals, and pre‑packaged architectural audits that win customer confidence quickly.

  • Converting Security into a Value Driver: Turn our robust security baseline into a core sales differentiator, helping commercial teams demonstrate to prospect banks why Hawk's defense posture makes us their lowest‑risk vendor.

3. Risk Registry, Compliance & Governance Leadership

  • Company Risk Registry Ownership: Act as the executive owner of the company‑wide Risk Registry. Go beyond cataloging risks: prioritize exposures dynamically, secure cross‑functional executive buy‑in to fund and execute mitigations, and transform risk management into concrete business enablement and revenue protection.

  • Third‑Party Risk Management (TPRM): Oversee vendor risk tiering, supply chain vetting, and continuous monitoring for third‑party vendors and cloud sub‑processors, executed directly through the Compliance function.

  • Audit & Regulatory Leadership: Maintain existing ISO 27001 and SOC 2 Type II programs with zero major non‑conformities across an expanding international perimeter.

  • DORA Implementation: Enforce end‑to‑end compliance with the EU Digital Operational Resilience Act—specifically ICT risk management, third‑party vendor oversight, operational resilience testing, and ICT incident reporting.

  • Multi‑Jurisdiction Alignment: Adapt policies proactively to meet global financial standards across the EU, UK, US, Singapore, and upcoming expansion markets.

  • Executive & Board Reporting: Translate technical cyber risk into clear business metrics (KRIs, risk heat maps, burn‑down rates) for the CEO and Board of Directors.

4. Frontline Incident Response & Operational Resilience

  • First‑Hand Incident Commander: Serve as the hands‑on incident commander during Sev‑1/Sev‑2 security incidents. Lead technical investigations, root‑cause analyses, log forensics, and technical debriefs directly alongside your team.

  • Breach Notification & External Escalation: Direct regulator, law enforcement, and client communications within mandatory statutory windows under GDPR and DORA guidelines.

  • Testing & Tabletop Drills: Design and execute technical red team engagements, threat‑led penetration tests (TLPT), and crisis simulations with both technical engineers and the executive board.

12‑Month Success Metrics:

  1. Commercial Velocity: Enterprise bank security assessments clear with zero high‑severity blockers, accelerating enterprise contract closures.

  2. Proactive Risk Registry: The company risk registry is fully operationalized with executive buy‑in, systematically driving down enterprise risk while supporting business expansion.

  3. Regulatory & Audit Record: DORA compliance program is operational; ISO 27001 and SOC 2 renew cleanly across all operating regions.

  4. Engineering & AI Hardening: Software supply chain security controls, secure coding standards, and AI harness guard rails are fully integrated into engineering CI/CD workflows.

  5. Resilient Team Operations: The four‑person security team executes with high autonomy, defined KPIs, and high cross‑functional trust across the company.

Candidate Profile:
  • Practitioner Foundations: Proven background as a hands‑on security practitioner (e.g., former security engineer, AppSec specialist, cloud security architect, or technical penetration tester) who has advanced into security leadership.

  • Player‑Coach Track Record: Demonstrated ability to manage and grow a small team of domain experts while personally reviewing technical configurations, auditing cloud policies, or investigating an alert.

  • Commercial & CISO-to-CISO Fluency: Experience debating architecture, supply chain controls, and threat postures directly with enterprise bank CISOs and security evaluation boards to clear deal roadblocks.

  • AI & Supply Chain Defense Fluency: Ability to quickly understand our AI architecture, implement hands‑on controls to harden AI tooling (including AI harnesses and sandboxing), and protect CI/CD pipelines against software supply chain risks.

  • Risk Registry Execution: Demonstrated ability to maintain a living risk registry, articulate risk trade‑offs to non‑technical executives, and rally engineering and commercial buy‑in to remediate risks.

  • FinTech & Regulated SaaS Background: Multi‑year leadership experience in a B2B SaaS, FinTech, or banking platform handling sensitive financial or transactional data under regulatory oversight (e.g., DORA, ISO 27001, SOC 2, GDPR).

  • Technical Breadth: Strong practical understanding of AWS and GCP security primitives, container and Kubernetes security, modern IAM/SSO, API gateways, and EDR/XDR toolchains.

Bonus:
  • Industry certifications reflecting technical or managerial competence (e.g., CISSP, CISM, CCSP, OSCP).

  • Direct experience securing real‑time event‑streaming architectures.

  • German language proficiency (conversational or fluent) is a strong advantage.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Chief Information Security Officer (CISO) arbeitnow Hawk Munich · 10/7/2026
Chief Information Security Officer (CISO) arbeitnow Hawk Munich · 10/7/2026

Primetime • München

Hybrid
EUR 140,000 - 190,000
(Senior) Information Security Officer (German)
(Senior) Information Security Officer (German)

Hawk • Germany

On-site
EUR 65,000 - 85,000
Lead Security Engineer (m/w/d)
Lead Security Engineer (m/w/d)

Recare Deutschland GmbH • Berlin

Hybrid
EUR 90,000 - 130,000
Remote-friendly
Flexible hours
Edenred card
+2
Cloud Security Engineer at YGO GmbH
Cloud Security Engineer at YGO GmbH

YGO GmbH • Germany

On-site
EUR 90,000 - 120,000
Solution Architect (German Speaking)
Solution Architect (German Speaking)

Hawk • Germany

On-site
EUR 90,000 - 130,000
Remote Channel Solution Architect — DACH (Cybersecurity)
Remote Channel Solution Architect — DACH (Cybersecurity)

CrowdStrike • Germany

On-site
USD 150,000 - 210,000
Market-leading compensation
Comprehensive wellness programs
Generous vacation
+3
AI Architect (AI for Security)
AI Architect (AI for Security)

Neurons Lab • Germany

On-site
EUR 120,000 - 180,000
Competitive compensation
Regulated industry exposure
Cloud & AppSec Engineer: Secure AI/ML Pipelines
Cloud & AppSec Engineer: Secure AI/ML Pipelines

NEURA Robotics • Germany

Remote
USD 120,000 - 160,000
Channel Solution Architect, DACH (Remote, DEU)
Channel Solution Architect, DACH (Remote, DEU)

CrowdStrike • Germany

On-site
EUR 120,000 - 180,000
Equity awards
Wellness programs
Parental leaves
+2
Founding Engineering Team Lead (HandsOn)
Founding Engineering Team Lead (HandsOn)

Cygrid GmbH • Berlin

On-site
Confidential
Founding Team Member Equity
Competitive Compensation
High Autonomy
+1