# Lead, Information Security at Bitpanda

Bitpanda is hiring a Lead, Information Security in Vienna, Austria. Level rates it Little AI ●○○○; you can [apply on Level](https://jobsbylevel.com/go/78c6ed8e-f725-45dc-be43-0c88029440c5).

AI Level 1, AI centrality 38 out of 100. Vienna, Vienna, Austria.

## Details

- Company: [Bitpanda](https://jobsbylevel.com/companies/bitpanda)
- AI level: AI Level 1 (score 38 out of 100)
- Location: Vienna, Vienna, Austria
- Posted: October 9, 2026
- Apply: https://jobsbylevel.com/go/78c6ed8e-f725-45dc-be43-0c88029440c5

## Description

Who we are We simplify wealth creation. Founded in 2014 in Vienna, Austria by Eric Demuth, Paul Klanschek and Christian Trummer, we’re here to help people trust themselves enough to build their financial freedom — for now and the future. Our user-friendly, trade-everything platform empowers both first-time investors and seasoned experts to invest in the cryptocurrencies, crypto indices, stocks*, precious metals and commodities* they want — with any sized budget, 24/7. Our global team works across different cultures and time zones, bringing our products to more than 7 million customers, making us one of Europe’s safest and most secure platforms that powers modern investing. Headquartered in Austria but operating across Europe, our products are built by fast-moving, talented, “roll-up-your-sleeves-and-make-it-happen” kind of people. It’s these diverse perspectives and innovative minds operating as ONE TEAM that keep Bitpanda at the cutting edge of our industry. So if you’re someone who thinks big, moves fast and wants to make an impact right from day one, then get ready to join our industry-changing team. Let’s go! Your mission As an Information Security Expert, you are a senior individual contributor who sets direction and solves the hardest GRC problems in a regulated fintech environment. You shape our security governance strategy, ensure our control framework remains effective as the business scales, and act as a key advisor to security leadership and senior business stakeholders on risk and compliance decisions. You’ll lead complex, high-impact initiatives (multi-entity, multi-region, regulator/customer-facing), influence across the organisation, and raise the bar for how we design, test, and evidence security controls. What you’ll do GRC strategy & roadmap: Define multi-year GRC roadmap aligned to business strategy, risk appetite, and regulatory expectations (e.g., DORA readiness, audit strategy, control maturity targets). Drive control framework evolution: rationalize controls, reduce duplication, and ensure proportionality based on criticality, data sensitivity, and business impact. Establish “north star” principles for governance (e.g., minimum control baselines, exception governance, evidence-by-design). Executive advisory & decision support: Advise leadership on material risk decisions: risk acceptance, remediation prioritisation, control investments, and scope decisions. Produce executive-grade outputs: risk narratives, board/committee materials, and regulator/customer responses with defensible rationale. Facilitate senior stakeholder alignment when priorities conflict (delivery speed vs control rigor; cost vs assurance depth). Regulatory, audit & assurance leadership (complex scope): Own strategy and approach for major audits/assurance activities (ISO 27001, SOC 2, regulatory examinations, key client due diligence), including scope, positioning, and negotiation. Lead responses to complex audit/regulatory issues: root-cause analysis, corrective action programs, and sustained effectiveness verification. Domain SME ownership (one or more, depending on needs): You may be the SME for one or more of: ISMS/ISO 27001 at scale (multi-entity scope, continuous compliance); DORA / operational resilience governance (control mapping, ICT risk integration, testing oversight); Third-party risk for critical ICT providers (oversight model, ongoing monitoring, exit/continuity governance); Security control assurance (testing program design, evidence standards, control health metrics). Enablement, standards & mentorship: Set standards and reusable artifacts: control narratives, evidence templates, testing methodologies, and playbooks. Mentor specialists and associates; raise organisation-wide capability through coaching and review. Partner with Security Engineering/IT/Compliance to embed controls into workflows (policy-to-automation where possible). Who you are Typically 7–10+ years of experience in information security GRC,

The description is cut here. Read the full offer: https://jobsbylevel.com/jobs/lead-information-security-at-bitpanda-f55958

Source: https://jobsbylevel.com/jobs/lead-information-security-at-bitpanda-f55958

## Cite this page

Level. https://jobsbylevel.com/jobs/lead-information-security-at-bitpanda-f55958.

Get job alerts: https://jobsbylevel.com/newsletter
