Chief Information Security Officer
CPS IT Solutions is seeking a Chief Information Security Officer to establish and govern information security policies, risk management, DORA readiness, security reporting, incident response, audits, and compliance for an AWS-hosted multi-tenant SaaS platform.
Responsibilities
- Establish and maintain security policies and procedures aligned with ISO/IEC 27001:2022, including SDLC policies.
- Act as the independent security gatekeeper under ISO 27001.
- Manage the information security risk register and track technology risk acceptance and vulnerabilities.
- Own the DORA-ready validation program and maintain DORA data sheets and subcontractor registers.
- Implement security dashboards and reporting for regulated clients.
- Govern security incident response, notification targets, SLA thresholds, and major-incident reporting readiness.
- Audit administrative access logs and permission changes quarterly.
- Review and approve technical risk profiles for releases and architectural changes.
- Lead threat-driven penetration testing and business continuity testing.
- Serve as technical contact for CSSF examiners and external ISO 27001 auditors.
- Coordinate client ISMS and BCDR plan audits.
Requirements
- Bachelor's or Master's degree in IT, Computer Science, Cybersecurity, or a related field.
- 5+ years of information security leadership experience, preferably as a CISO in regulated financial services or SaaS.
- Deep knowledge of ISO/IEC 27001:2022, DORA, ISMS, risk management, and security controls.
- Understanding of AWS cloud security, network segregation, VPC design, multi-tenant database isolation, and IAM.
- CISSP, CISM, CRISC, or equivalent professional certification.
- Strong English verbal and written communication skills.
- AWS security certifications and Russian language skills are advantageous.
Benefits
- Opportunity to build and shape the information security function from an early stage.
- High ownership and direct impact on ISO 27001 readiness, DORA processes, security governance, and client trust.
- Exposure to regulated financial services, core banking, payments, EMI, and crypto-asset topics.
- Close collaboration with senior stakeholders across product, technology, compliance, and business functions.
- Hybrid work arrangement in Cyprus.