Head of Information Security
1 нед. назад
9000–12k EURCyprusSeniorOnsiteB1
iammfassocloudsdlcappsecsecurityarchitecture
Head of Information Security role at Scorewarrior with 8+ years experience required, based in Cyprus with relocation support, salary 9,000-12,000 EUR, English Intermediate B1.
Responsibilities
- Build a viable security system across the core domains: IAM (access management, MFA, SSO), infrastructure security (cloud, services, network), foundational SDLC/AppSec (security in the development process and in the code), and the processes and training around them. We expect you to start with a proper diagnosis of our landscape — and design the system for this company, rather than replaying a project from a previous job.
- Own security risks and speak both languages: business language with the CTO and CEO — risk, cost, and priorities; technology language with developers and infrastructure teams — architecture, trade-offs, and practical solutions.
- Make the right build-vs-buy calls: you know the security product market well enough to tell when a problem needs a tool, when a simpler method will do, and when the problem isn't in the tooling at all — it's in habits and heads.
- Introduce security as a partner, not a blocker: embed baseline practices so smoothly that teams barely notice them; for everything on top of that — inform, help when asked, and don't push when it's not the team's priority right now.
- Define how AI tools are used safely: own the policy and guardrails for the company-wide adoption of AI tools — what data can go where, and how teams can use them productively without creating new risks.
- Build the team: hire the first security engineers deliberately — knowing who you're hiring and why — and grow the function as the company's needs grow.
Requirements
- 8+ years of hands-on experience in security — real projects you designed, implemented, and stayed around long enough to see working. At the interview, we'll ask about specific cases, decisions, and their consequences — not about frameworks in theory.
- A background that gave you real systems experience. Two paths work equally well for us: a stable security engineering career from university onwards, or a transition into security from system administration, technical support, or network engineering. What matters is the result — you understand infrastructure and architecture from the inside, not from diagrams.
- Proven experience hiring and building a team — even a small one (2+ people). What matters is that it was deliberate: you can explain who you hired, why them, and how the team was structured around the actual problems.
- Experience building a security function, not just running one. You've taken security in an organization from an unclear state to a working system: assessed the landscape, set priorities, chose what to implement and what to skip — and can show what changed as a result.
- Strong awareness of the security product market. You can tell when a problem needs a tool, when a simpler method will do, and when the problem is in habits rather than tooling — and you have real examples of each call.
- A partner's operating style. You work through engineering teams, not above them: no separate authority demands, no blocking by default. Your practices get adopted because they make sense, not because they're mandatory.
Conditions
- Локация: Кипр
- Relocation support
- English Level: B1 — Intermediate
- Salary: 9 000 — 12 000 €