Chief Information Security Officer (CISO) / Information Security Officer & ICT Risk Manager (m/f/d) & BCMO

Berlin / On-SiteFull-timeInformation Security

About FLIZ

FLIZpay is a payment method from Germany that lets businesses radically reduce the cost of accepting payments — and gives shoppers cashback and discounts in return. Instead of storing a card, shoppers securely connect their bank account and pay with the FLIZ app at participating merchants. Merchants keep the saving or turn it into offers that drive conversion and loyalty. Built in Germany for Europe: a local alternative to the international payment networks, with customer data staying in the EU. We're seed-stage, based in Berlin, and we work in a regulated payments environment. One small cross-functional team builds and runs all of it: the checkout merchants add via plugin, SDK or API, the FLIZ app, and our business platform. Three stand-alone products are live today, more are launching.

The role

As CISO/ISO you are responsible for our information security and cyber resilience. With DORA coming into force in 2025/2026, you are the architect of our "Digital Operational Resilience". You own the identification, assessment, management and monitoring of ICT risks across all business processes and ensure that our security and risk strategy is closely interlocked with the company's objectives. You establish security standards that do not slow us down but actually make our digital business model possible, pragmatic, automated and state-of-the-art.

Your responsibilities

  • Taking on the independent function of Information Security Officer (ISO), reporting directly to management.
  • Building, certifying (e.g. ISO 27001) and developing the information security management system (ISMS) and the ICT risk management framework in line with DORA (Art. 6).
  • Implementing lean security-by-design and privacy-by-design principles in our software development lifecycle (CI/CD pipelines, DevSecOps).
  • Developing and testing business continuity management (BCM) and IT disaster recovery plans.
  • Building and managing ICT incident reporting to BaFin in accordance with DORA.
  • Carrying out threat-intelligence analyses, vulnerability scans and penetration tests (TLPT).
  • Performing the role of ICT risk manager under DORA, including building and continuously developing holistic ICT risk management.
  • Identifying, assessing, managing and monitoring ICT risks, including defining risk tolerances and reporting to management.
  • Establishing and maintaining a company-wide ICT risk register and running regular risk analyses and assessments.
  • Managing ICT third-party risks (e.g. cloud providers), including risk analyses, contractual requirements and monitoring.

Who you are

  • Degree in computer science, IT security or comparable technical expertise.
  • Relevant certifications (CISM, CISSP, ISO 27001 Lead Auditor).
  • Experience building ISMS and ICT risk management in regulated financial companies (ZAIT, BAIT, DORA).
  • Understanding of modern cloud environments (AWS, GCP, Azure), containerisation (Kubernetes) and zero-trust architectures.
  • Ability to translate IT and ICT risks for developers and management not as scaremongering but as calculable business risks.
  • Sound knowledge of identifying, assessing and managing ICT risks and of regulatory requirements for risk management.
  • Experience dealing with supervisory authorities and preparing risk reports at management and board level.
  • Business-fluent English, German a big plus.

Perks

  • Meaningful equity in an early-stage company
  • Central Berlin office with flexible hybrid working
  • Real ownership and direct impact on the product
Apply now