emerchantpay
Information Security Lead
Remote role where the employee must remain based in a particular country.
Bulgaria only
Employer listed it 3 months ago · Added today
Been open since 3 months ago. Long-running listings are sometimes left up after the role is filled.
Salary
Not stated
Location
Bulgaria only
Timezone
Not stated
Contract
Full-time
Experience
Lead
Category
Software
This employer didn't state pay. Jobs like this usually pay around $205k–$275k a year, a typical range taken from 599 lead-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Work from home
This is a remote role, but the employee must be based in Bulgaria. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Sofia, Bulgaria, Sofia, Sofia City Province, Bulgaria, Sofia, Sofia City Province, Bulgaria, Remote"
What Nomaders makes of it
- Residency required in Bulgaria
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
emerchantpay is a leading global payment service provider and acquirer for online, mobile, in-store and over the phone payments. Our global payments solution is available through a simple integration, offering a diverse range of features, including global acquiring, global and local payment methods, advanced fraud management and performance optimisation. We empower businesses to design seamless and engaging payment experiences for their consumers.
We are looking for an experienced Information Security Lead to own the design, implementation, and continuous improvement of information security across our cloud-native, DevOps-driven engineering environment, as well as our corporate IT and office infrastructure.
The role combines hands-on technical delivery with security leadership. The Information Security Lead will set security direction and personally drive its execution - securing our cloud platform, delivery pipelines, and microservices, leading security operations and incident response, and embedding security into how engineering builds and ships.
The role works closely with Engineering, DevOps, and the IT Governance, Risk & Compliance (GRC) function.
The role has a strong focus on AWS and cloud-native security across a modern microservices architecture.
Responsibilities
Define and maintain the information security strategy, standards, and roadmap, aligned to applicable regulations, rules, and security best practices.
Steer security architecture across a cloud-native environment, defining secure-by-design patterns for microservices, APIs, and shared platform services.
Establish and govern secure software development lifecycle (secure SDLC) practices, embedding automated security controls into CI/CD pipelines.
Define and drive adoption of cloud security guardrails - identity, network segmentation, encryption, secrets management, and configuration baselines.
Build and run security monitoring, logging, and threat detection across cloud, infrastructure, and application layers.
Lead the security incident response lifecycle - preparation, detection, containment, eradication, recovery, and post-incident review - and act as incident commander for security events.
Own vulnerability and threat management: scanning, risk-based prioritization, remediation tracking, and reporting across infrastructure, containers, and application code.
Plan and coordinate penetration testing and offensive-security exercises (in-house or co-sourced) and drive findings to closure.
Govern identity and access management, privileged access, and least-privilege principles across cloud and corporate systems.
Define and oversee data protection controls - encryption, key management, data classification, and loss prevention - for sensitive and cardholder data.
Secure corporate IT and office infrastructure, including endpoints, networks, and productivity and collaboration platforms.
Partner with Engineering and DevOps teams to make the secure path the easy path, providing tooling, standards, threat modelling, and design reviews.
Provide security input into architecture and change decisions, including the adoption of new technologies and third-party services.
Run security awareness and phishing-resilience programs for technical and non-technical staff.
Implement and evidence the technical security controls underpinning PCI DSS, ISO 27001, and SOC audits.
Monitor the evolving threat landscape and emerging security technologies.
Act as a key member of the internal security center of excellence and contribute to cross-functional security working groups.
Build, lead, and mentor a small security team.
Requirements
- ·Bachelor’s or master’s degree in computer science, information security, or a related field, or equivalent practical experience.
- ·At least 10 years in information / cyber security, including a minimum of 2-3 years in a leadership role, with hands-on experience securing cloud-native environments at scale.
- ·Deep, practical public-cloud security knowledge (AWS strongly preferred): identity, networking, encryption, logging, and configuration management.
- ·Strong experience securing DevOps / CI/CD pipelines and modern microservices architectures - containers, APIs, and infrastructure-as-code.
- ·Working knowledge of application security and secure SDLC across modern programming languages and web frameworks.
Benefits
- ·Fast-growing payment company;
- ·Excellent working conditions, casual atmosphere, and state-of-the-art hardware;
- ·Modern, challenging, constantly growing business;
- ·Professional development - books, trainings, certifications, etc.;
- ·Team buildings and fun activities;
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at emerchantpay, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 15h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $205k to $275k per year · You'll be taken to the employer's careers page.