VP Information Security
Lead cybersecurity strategy and operational security for Finoa, owning the cybersecurity framework, cyber risk management, regulatory incident notifications, security standards, vendor due diligence, security awareness, SIEM operations, and incident response.
Responsibilities
- Own and continuously improve cybersecurity strategy, policies, risk register, and controls.
- Maintain asset inventory, conduct risk assessments, monitor risks, and report to the Board.
- Lead regulatory incident notifications and coordinate with the Data Protection Officer when personal data is involved.
- Maintain security-configuration and access-control standards.
- Commission independent vulnerability scans and penetration tests.
- Own vendor and outsourcing security due diligence, including cloud providers.
- Run a group-wide security awareness programme and ensure adequate security resources.
- Support Board approval of the security audit plan and independent cyber-resilience reviews.
- Represent the regulated entity to the regulator on IT security matters.
Requirements
- Ideally 5+ years of information security experience combining hands-on SOC or detection-engineering work with governance or senior-management accountability.
- Experience owning a cybersecurity framework in a regulated environment with senior-level reporting and regulatory incident notification.
- Practical SIEM design, tuning, and operational experience.
- Experience leading incident response.
- Ability to serve as an accountable CISO to a regulator and present directly to a Board.
- Clean regulatory and criminal record, no disqualification from director or senior-management roles, and sound personal finances.
- Demonstrable security experience, ideally in regulated environments.
- Ability to work from the Vilnius office 2–3 days per week.
- CISSP, CISM, SANS/GIAC, or equivalent operational security certifications are nice to have.
Benefits
- Develop an established security setup as the product and customer base grow.
- Shape the founding Lithuania team and influence collaboration across engineering, compliance, and risk.
- Grow the scope of the role as the business scales.
- Direct exposure to the Board and broad cross-functional stakeholder engagement.