Chief Information Security Officer (CISO)

HawkMunichArbeitnow٧‏/١٠‏/٢٠٢٦
إعلان
About Us  Hawk is the leading provider of AI-supported anti-money laundering and fraud detection technology. Banks and payment providers globally are using Hawk’s powerful combination of traditional rules and explainable AI to improve the effectiveness of their AML compliance and fraud prevention by identifying more crime while maximizing efficiency by reducing false positives. With our solution, we are playing a vital role in the global fight against Money Laundering, Fraud, or the financing of terrorism. We offer a culture of mutual trust, support and passion – while providing individuals with opportunities to grow professionally and make a difference in the world.  Hawk builds AI-powered financial crime detection (AML, transaction monitoring, and fraud prevention) for global tier-1 banks, payment processors, and high-growth fintechs. Because our platform analyzes real-time payment streams and sensitive financial data, security is not an administrative support function—it is our primary product promise. We are looking for a technically grounded, hands-on CISO to own our global security posture end-to-end. This is a true player-coach leadership role. You will lead a dedicated team of four domain specialists while staying close enough to the technology to review cloud architecture, triage high-severity vulnerabilities, command critical incident responses first-hand, and debate technical security controls peer-to-peer with customer bank CISOs. Why This Role MattersGlobal Regulatory Scrutiny at Scale: We operate across key financial hubs including Germany, the UK, the US, Singapore, and a growing roster of international markets. With DORA enforceable across the EU and heightened ICT risk rules globally, our banking clients expect documented operational resilience, continuous testing, and verified controls across all jurisdictions. Modern Attack Surfaces & Supply Chain Threats: Our multi-tenant and single-tenant cloud environments (AWS/GCP) process massive transaction throughput. Alongside defending against emerging supply chain vulnerabilities—from open-source dependencies to third-party build pipelines—you will need to deeply understand our AI approach and actively help harden our tooling, harnesses, and pipelines. Enterprise Deal Velocity: Enterprise security reviews can either stall deals or close them. You will partner with our commercial teams to turn security questionnaires, risk mitigation, and architecture audits into enterprise trust and closed contracts. Organizational Structure: The Four DomainsYou will lead, mentor, and set technical direction for four specialized functional areas: Application Security: Secure SDLC, automated CI/CD security gates (SAST/DAST/SCA), software supply chain defense, secure coding standards, AI harnesses and pipeline hardening. Corporate Security: Zero Trust architecture, IAM/SSO, distributed endpoint defense (EDR/XDR), threat hunting, infrastructure access. Compliance & Governance: DORA implementation, ISO 27001, SOC 2 Type II, Third-Party Risk Management (TPRM), multi-jurisdiction regulatory audits, risk registry ownership. Data Protection: Solely dedicated to data protection: GDPR compliance, privacy governance, data subject rights, and statutory privacy regulatory requirements. Core Accountabilities1. Hands-On Technical Leadership, Engineering Integration & AI Hardening Secure Coding Standards & SDLC: Establish and enforce secure coding baselines directly within engineering workflows. Ensure automated vulnerability scanning, SBOM tracking, and security gates are integrated into GitHub/GitLab CI/CD pipelines. Software Supply Chain Defense: Protect build systems, dependencies, and deployment pipelines against supply chain tampering, compromised packages, and upstream vulnerabilities. AI Tooling & Pipeline Hardening: Deeply understand our AI approach and work closely with engineering to harden our systems. Personally evaluate and implement protective mechanisms—including sec
إعلان