Description
About the role
We’re looking for a Senior ICT Risk & Information Security Manager to join our Payments Governance, Risk & Compliance team.
In this role, you’ll shape and strengthen the information security and ICT risk frameworks that support Payments’ growth as a regulated, cloud-based payments business. You’ll design scalable governance processes, translate regulatory requirements into practical controls, and help ensure our security and risk practices evolve alongside the business and the changing threat landscape.
You’ll work closely with Engineering, Product, Legal, Compliance, Internal Audit, and external partners to assess risks, improve security processes, and drive compliance with regulations such as DORA, GDPR, NIS2, and PCI DSS. This is a hands-on role focused on building and improving frameworks rather than maintaining the status quo, while providing expert guidance across the organisation.
Main tasks and responsibilities
- Design, implement, and continuously improve the Information Security Management System (ISMS), ICT risk framework, policies, and controls, ensuring they scale with the business and meet regulatory requirements, including DORA and PCI DSS.
- Define ICT and security risk assessment methodologies and taxonomy, independently challenging and assuring assessments carried out for new products, technologies, and business initiatives to ensure risks are identified and managed effectively.
- Define the scope, frequency, and approach for security assurance and resilience testing, including control reviews and penetration testing, and independently challenge testing outcomes and remediation plans to ensure risks are addressed effectively.
- Partner with Engineering, Product, Compliance, Legal, and third-party providers to strengthen security practices and third-party assurance, while running security awareness and training programmes that build a strong risk-aware culture.
- Develop clear risk reporting, security dashboards, and governance materials that give senior stakeholders visibility into our security posture, key risks, regulatory compliance, and priorities for improvement.
- Take on broader ICT risk leadership responsibilities as you demonstrate strong delivery and judgement, with a clear path towards functional leadership supported by defined objectives, mentoring, and exposure to senior governance forums.
About you
- You have strong expertise in information security governance, ICT risk management, and designing security frameworks that enable business growth while managing risk.
- You enjoy translating complex regulatory and cybersecurity requirements into practical processes, controls, and guidance that teams can successfully implement.
- You approach challenges with a structured, risk-based mindset, balancing security, compliance, and business needs while identifying opportunities for continuous improvement.
- You communicate clearly with both technical and non-technical stakeholders, building trusted relationships and explaining complex security topics in an accessible way.
- You thrive in collaborative, fast-moving environments, taking ownership of strategic initiatives while working effectively across multiple teams and priorities.
- You bring experience in regulated environments such as financial services, fintech, or payments, and are confident working with security standards, governance frameworks, and industry best practices. Professional certifications in information security or risk management are considered a strong advantage.
Why you’ll love it here
- Accelerate your professional growth with unique career opportunities.
- Enjoy a rewarding salary and stock options, knowing that as we succeed, so do you.
- Take care of your physical and mental health with our wellness perks.
- Celebrate 5 years with a 1-month paid sabbatical to recharge.
- Connect with colleagues at annual company events and smaller team gatherings.
- Balance flexibility and in-person collaboration with our hybrid model, including at least 12 monthly in-office days.
Are you interested in this position?
Apply by clicking on the “Apply Now” Button below!
#JobsHubEstonia #GlobalRecrument
#CareerOpportunities #HiringNow
#JobSeekersNetwork #EstoniaJobs
#RecruitmentServices #EmploymentPortal