Head of Information Security
Job Description
<div class="content-intro"><p>At Bondora, our mission is simple: to make finance easy, transparent, and accessible for everyone.</p> <p>Founded in 2008, we’ve helped more than 700,000 customers across Europe borrow and invest effortlessly through our trusted digital products.</p> <p>As a rapidly growing financial technology company, we’re reaching new heights with a bold vision. We’re set to acquire a banking license, unlocking a world of possibilities for our customers. This transition will allow us to expand our lending across more EU countries and broaden our product suite to deliver even more value.</p> <p>Join us on this journey and let’s build the future of finance together!</p></div><h2><span style="color: rgb(53, 152, 219);">What is this role about?</span></h2> <p>As the <strong>Head of Information Security</strong>, you'll play a key role in ensuring Bondora's systems, data and customers stay protected as we build toward a banking licence — owning security hands-on, including when incidents happen. Collaboration is crucial, as you'll work closely with product engineering, Site Reliability Engineering (SRE), information technology (IT) and compliance teams to maintain robust security controls and optimize processes for peak performance. This position requires a combination of hands-on engineering, regulatory expertise, and process management, making it an exciting and impactful opportunity to enhance our organization's security posture.</p> <ul> <li>Conduct regular security reviews of architecture and significant product changes — as a collaborator in design discussions, not a gate at the end.</li> <li>Perform regular practical hardening work alongside engineering: secrets management, access control, network segmentation, logging and alerting coverage, and continuous integration / continuous delivery (CI/CD) pipeline security.</li> <li>Design and coordinate external penetration tests, red team exercises and the threat-led penetration testing (TLPT) mandated by the Digital Operational Resilience Act (DORA), translating findings into a realistic remediation backlog.</li> <li>Monitor and evaluate the information and communication technology (ICT) risk management framework required by DORA, working with all lines of defence on the practical application of related policies.</li> <li>Maintain accurate documentation of the quality assurance process, audits, results, and action points.</li> <li>Prepare and prioritize business requirements for necessary changes based on findings to improve efficiency and accuracy.</li> </ul> <p><em><span data-ccp-props="{"201341983":0,"335551550":0,"335551620":0,"335559739":160,"335559740":259}">This role location is preferably in Estonia, or remote from EU. </span></em></p> <h2 style="line-height: 1.5;"><span style="color: rgb(53, 152, 219);">What would ensure success in this role?</span></h2> <p>Success in this role is determined by analytical expertise, process oversight, and data accuracy management. The ideal candidate will have:</p> <ul> <li>Proven experience in working with ICT regulations such as European Central Bank (ECB) requirements, DORA, and Estonian Financial Supervision Authority (EFSA) expectations.</li> <li>Strong skills in writing and reading code, and in security hardening practices in a cloud environment.</li> <li>Ability to work fluently with industry-standard security tooling — code analysers, network analysers, vulnerability scanners.</li> <li>Experience with penetration testing practices and standards.</li> <li>Ability to use large language model (LLM) powered security tools in daily work, and to reason with practical examples about their be