Bachelor's or Master's degree in IT, Computer Science, Cybersecurity, or a related field
5+ years of experience in Information Security, including leadership or management responsibility within regulated financial services or regulated SaaS environments such as fintech, banking, payments, or EMI
Deep knowledge of ISO/IEC 27001:2022, ISMS, information security risk management, and security controls
Solid understanding of AWS cloud security, network segregation, VPC design, multi-tenant database isolation, and IAM principles
Strong understanding of Secure Software Development Lifecycle (Secure SDLC) and application security principles
Independent-minded and objective in risk evaluation, with the ability to communicate technical risks in business terms
Hands-on mindset with a practical approach to solving security challenges and the ability to balance strategic ownership with day-to-day execution
Strong verbal and written communication skills in English
Experience with crypto, crypto-assets, or related regulated products
Experience supporting DORA implementation or operational resilience programs within regulated financial institutions
Familiarity with DORA requirements, ICT risk management, third-party risk governance, and regulatory reporting
Experience supporting regulatory examinations, client security due diligence, or ISO 27001 certification audits
CISSP, CISM, CRISC, or equivalent professional certifications
AWS Security certifications
Russian language skills are considered a strong asset