
Specialist, Information Security
Bitpanda · Vienna
Job description
Who we are We simplify wealth creation. Founded in 2014 in Vienna, Austria by Eric Demuth, Paul Klanschek and Christian Trummer, we’re here to help people trust themselves enough to build their financial freedom — for now and the future. Our user-friendly, trade-everything platform empowers both first-time investors and seasoned experts to invest in the cryptocurrencies, crypto indices, stocks*, precious metals and commodities* they want — with any sized budget, 24/7. Our global team works across different cultures and time zones, bringing our products to more than 7 million customers, making us one of Europe’s safest and most secure platforms that powers modern investing. Headquartered in Austria but operating across Europe, our products are built by fast-moving, talented, “roll-up-your-sleeves-and-make-it-happen” kind of people. It’s these diverse perspectives and innovative minds operating as ONE TEAM that keep Bitpanda at the cutting edge of our industry. So if you’re someone who thinks big, moves fast and wants to make an impact right from day one, then get ready to join our industry-changing team. Let’s go! Your mission As an Information Security Specialist, you will own and mature significant parts of our governance, risk, and compliance program in a regulated fintech environment. You’ll be the go-to person for one or more GRC domains (e.g., ISMS and ISO 27001, audit & assurance, third-party risk, risk management, regulatory mapping), driving outcomes end-to-end: control design, operationalization with stakeholders, testing, metrics, and continuous improvement. You’ll operate with high autonomy, influence across teams, and help shape how we scale security governance as the company grows. What you’ll do GRC domain ownership & program maturity : Own one or more GRC domains (e.g., ISO 27001/ISMS, control testing, TPRM, risk governance, BCM), including yearly plans, cadence, and measurable outcomes; Build scalable processes and playbooks that reduce audit friction and improve control consistency across teams/entities. Assurance, audits & regulatory readiness: Coordinate internal and external audits end-to-end (readiness planning, walkthroughs, evidence strategy, auditor Q&A, remediation verification); translate new regulatory and customer requirements into control impacts, implementation guidance, and tracked delivery plans; draft and quality-review formal materials: audit responses, management action plans, risk acceptances, and control descriptions. Risk management & decision support: Facilitate and challenge risk assessments for systems, products, and material changes; ensure consistent scoring and clear treatment decisions; drive risk treatment plans with accountable owners; escalate when timelines or residual risk are not acceptable; improve risk reporting for leadership: themes, systemic issues, KRIs/KPIs, and clear prioritization based on business criticality. Third-party risk management (if in your scope): Lead due diligence for critical vendors: define minimum security requirements, review evidence, and track remediation; Partner with Legal/Procurement to embed security requirements into contracts and ensure ongoing oversight (renewals, periodic reviews, SLA/security obligations) Control testing & continuous improvement: Design and run a risk-based control testing plan (design and operating effectiveness), ensuring repeatability and traceability; identify recurring control failures and drive cross-functional improvements (e.g., clearer ownership, automation, better tooling, updated standards); introduce automation and dashboards where useful (e.g., evidence collection, control health reporting, risk and audit tracking). Who you are Typically 4-7 years of experience in GRC, audit/assurance, security risk management, compliance, or information security. Strong working knowledge of ISO 27001 (or comparable frameworks) and ability to map requirements to controls, evidence, and real operational processes. Experience leading audits/assessments or significant parts of them (planning through closure). Security fundamentals across IAM, SDLC governance, incident management, vulnerabi
Verified and listed by ActiveJobs. Applications are made directly on Bitpanda's own career page — we never sit in the middle.