InfoSec Manager

2 hours, 27 minutes ago
Full-time
Lead
DevOps and Infrastructure
First Circle

First Circle

First Circle is a leading FinTech company offering non-collateral business loans up to ₱20 million to SMEs in Southeast Asia, enabling rapid growth through B2B trade financing.

Diversified Financial Services
51-250
Founded 2015
$28M raised

Description

  • Define the security strategy, priorities, and operating model aligned to business goals.
  • Own ISO 27001 certification from scoping through audit completion.
  • Implement and manage external penetration testing and remediation, ensuring findings are closed or formally risk-accepted.
  • Stand up and oversee the MSSP and SOC, including alerting, SLA tracking, and escalation processes.
  • Design, implement, and maintain security policies, standards, and procedures aligned with global standards and local regulations.
  • Embed secure-by-design practices into engineering and product development in collaboration with engineering and DevOps teams.
  • Lead vulnerability management, including regular scanning, prioritisation, and remediation tracking.
  • Build and maintain the security risk register for internal, external, vendor, and supply chain risks.
  • Develop security awareness and training programs, including phishing simulations and incident response drills.
  • Own incident response, third-party risk management, and cybersecurity engagement with regulators and payment/security frameworks.

Requirements

  • Experience building a security function from scratch in a regulated fintech, payments business, or bank.
  • Hands-on security leadership experience, not just advisory or consulting experience.
  • Experience taking an organisation through ISO 27001 as the responsible owner.
  • Experience leading a Sev-1 incident from initial response through post-mortem.
  • Experience selecting, standing up, and tuning an MSSP, including dismissing an underperforming vendor if needed.
  • Experience writing IAM policy that works in a real engineering environment.
  • Azure-native experience and the ability to work directly in cloud consoles and read Terraform.
  • Ability to contribute hands-on in code and debugging; this role is not for someone whose last line of code was more than 5 years ago.
  • Certifications such as CISSP, CISM, CRISC, or ISO 27001 Lead Implementer/Auditor are preferred as useful signals.
  • Experience working with regulated banks, card processors, payment rails, KYC providers, or similar third-party risk environments is important.

Benefits

  • Competitive compensation with no fixed budget; offers are adjusted based on experience and market rate.
  • Equity ownership in a fast-growing, profitable NeoBank.
  • Flexible working hours and location, with remote work available.
  • Optional access to offices in London, Manila, Singapore, Hong Kong, and Belgrade.
  • MacBook provided.
  • Private health insurance.
  • Training budget and other perks.
  • Periodic travel to headquarters in Southeast Asia.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Manager, IT

Adoreal 1-10 Health Care Providers & Services

Adoreal is seeking a hands-on Senior Manager, IT to build and lead its IT function for a fast-growing vertical SaaS company supporting elective medicine, with ownership of security, compliance, infrastructure, and overall IT strategy.

AWS Cloudflare Datadog DevSecOps HIPAA Network Security
2 hours, 11 minutes ago

Senior Information Technology Engineer

Engine.com 1-10 Machinery

Engine is hiring a Senior IT Engineer to lead enterprise-scale IT applications and automation systems that support secure, efficient operations for a fast-growing travel and fintech platform.

2 hours, 36 minutes ago

Cybersecurity AI Specialist

Weekday 11-50 Construction & Engineering

A leading AI lab’s client is seeking experienced cybersecurity and low-level programming professionals for a short-term project focused on reviewing technical content for security vulnerabilities and improving AI-driven threat classification.

C C++ Cybersecurity Java OWASP
2 hours, 56 minutes ago

Embedded Software Engineer, OS/Platform (Starshield)

SpaceX 10K-50K Aerospace & Defense

SpaceX is hiring an Embedded Software Engineer for the Starshield program to develop and support OS/platform software for satellites, ground systems, and secure communications on embedded hardware.

C C++ CI/CD Embedded Systems Linux Python Rust
3 hours, 17 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers