Senior Security Lead
3 giorni fa
Hercle is a fast-growing fintech building institutional-grade infrastructure that bridges fiat, stablecoins, and digital assets, enabling cross-border transactions at scale and in real time.Serving over 200 clients globally, Hercle provides banks, brokers, payment service providers, and fintechs with seamless solutions for cross-border payments, trading, and treasury management.Working at HercleBeing a technology-first fintech company, driven by young, passionate people, we value our employees as our greatest asset, giving them a lot of responsibility from the very start and all the support they need to make a difference and grow together with the company.Our flat structure fosters a culture of openness, inclusivity and collaboration, encouraging the sharing of ideas and knowledge across a wide range of top-level expertise.Everyone at Hercle is a self-starter, outstanding professional who owns his/her tasks and schedule.As a member of the team, you are in charge to achieve your goals and fulfill your mission with the added support, network and knowledge of everyone else.We look for people who thrive on deep personal growth motives, a passion for collaborating on new, cutting-edge ideas, and are highly intelligent and adaptive in their own sphere of knowledge and expertise, to share a mutual benefit and passion in between all team members.About The RoleThe Senior Security Lead (Threat & Risk) plays a crucial role in strengthening Hercle's resilience to technology, cyber, and information security risks.You'll operate as part of the second line of defense, giving independent challenge, direction, and oversight to how security and technology risks are managed in the first line in a way that fits a fast-moving scale-up, not a bank.This is a hands-on role.You'll bring deep expertise in information security, technology risk, and cyber resilience, and you'll use it to help shape how Hercle builds a stronger and more mature security capability.You'll be involved across the spectrum – from threat intelligence and incident readiness to control design, cloud security, and security operations – supporting the evolution of the CISO function as we scale.You'll work closely with engineering, product, and operations to identify risks early, understand how attackers think, and challenge teams constructively when something isn't where it needs to be.Your goal is to help the first line build secure systems and processes without slowing the business down.A key part of your work will be leading the design and rollout of Hercle's ICT & Security Risk Management Framework, making sure it reflects our business model, aligns with regulatory expectations where relevant, and follows modern industry practices – without unnecessary overhead.This role is a great fit for someone with a strong technical security background who enjoys balancing practical, hands-on security work with the broader mindset required to operate effectively in the second line of defense.Key ResponsibilitiesThreat Intelligence & Security FoundationsWork closely with the CISO and engineering leads to shape how we approach cybersecurity and technology risk in a fast-moving environment.Help build, evolve, and maintain a security framework that actually works in real life – combining threat intelligence, hands-on controls, and lightweight processes.Contribute to defining how much risk we're comfortable taking, and help turn that into clear, simple metrics the business can understand and act on.Make sure key security and tech risks are surfaced, shared, and understood across teams without slowing anyone down.Keep governance practical and minimal, focusing on what helps us move faster and stay secure at the same time.Risk Assessment & Security AssuranceLead hands-on assessments of systems, applications, and cloud services – focusing on what matters most.Partner with IT and Security teams to design and improve controls; act as a friendly challenger, not a blocker.Stay ahead of emerging threats and vulnerabilities, and translate them into real impact for our environment.Strengthen our incident response readiness by reviewing playbooks, testing scenarios, and embedding lessons learned.Run focused assurance checks to ensure our security controls work as expected and evolve as we scale.Collaboration & EnablementWork with product, engineering, and business teams to help them adopt new tech securely – cloud, AI, automation, new platforms, you name it.Partner closely with the CISO office to define and track meaningful security metrics and KRIs that support smart decision-making.Drive simple, engaging training and awareness efforts that naturally lift our security culture without resorting to box-ticking.RequirementsBackground & ExperienceYou're deeply comfortable in the worlds of InfoSec, Computer Science, Engineering, or Technology Risk – you've lived in these spaces, not just studied them.You've actually hunted threats and run penetration tests in real environments.You bring 3–6 years of hands-on experience in areas such as Security Operations, Incident Response, Detection Engineering, Red Team/Offensive Security, or Cyber Threat Intelligence.You can investigate system, network, and application logs and spot attack patterns across the full kill chain.You've previously owned or strongly contributed to security or risk responsibilities – for example as an Information Security Officer, Cyber Risk Manager, or senior IT/Sec specialist.Bonus points if you've helped build or mature a CISO function, Security Operations capability, or broader security program.Extra nice: experience working in regulated or high-stakes environments (fintech, telco, critical infrastructure, etc.).Technical SkillsStrong hands-on understanding of modern security tooling and cloud security, especially:AWS security services: GuardDuty, Security Hub, IAM, CloudTrail, WAF, KMSAWS Directory Services and Azure EntraSIEM platforms, IDS/IPS, firewalls, and endpoint protection toolsScripting: Python, Bash, or PowerShellInfrastructure as Code: Terraform or CloudFormationNice to have: broader security domains – vuln management, network security, cloud/app security, endpoint security, data protection, IAMCybersecurity frameworks: NIST CSF, ISO *****, CIS Controls, COBITRisk frameworks: ISO *****, COSO ERM, Basel II/IIIExperience with incident response, threat intelligence, disaster recovery, and business continuityYou're comfortable using security assessment tools and can translate technical findings into clear, practical risk insights.Certifications (Optional but Valued)CISSP, CISM, CRISC, CISA, or ISO ***** Lead ImplementerSoft SkillsClear, confident communication – able to work with engineers and non-technical stakeholders alike.Strong analytical and problem-solving mindset; able to connect technical risks to real business impact.High initiative, autonomy, and ownership – you're effective in fast-moving, less-structured environments.Natural collaborator with a track record of driving cross-team improvements.Why Joining Hercle?Competitive salary.Career and personal growth opportunities.The opportunity to shape risk management strategies in a fast-growing scale-up.Flexible working arrangements (remote/hybrid).Collaborative and forward-thinking work environment.If you're interested, feel free to reach out and send us your CVBy submitting this application, I confirm that all the information given by me in this application for employment and any additional documents attached are true to the best of my knowledge and that I have not wilfully suppressed any material fact.I confirm I have disclosed if applicable any previous employment with Hercle.I accept that if any of the information given by me in this application is in any way false or incorrect, my application may be rejected, any offer of employment may be withdrawn or my employment with Hercle may be terminated summarily or I may be dismissed.By submitting this application, I agree that my personal data will be processed in accordance with Hercle's Candidate Privacy Notice.#J-*****-Ljbffr
-
Senior Information Security Consultant
2 settimane fa
Lazio, Italia Aisec Security Advisory Company A tempo pienoPosizione: Consulente Senior Information Security Certificazioni richieste: ISO***** Lead Auditor (conseguita/e o in corso di conseguimento)Seniority: 3 - 5 anni di esperienza presso società di consulenza in progetti in ambito Cyber Security e/o Physical Security e/o Security Governance, Risk & ComplianceCompetenze:Laurea specialistica o formazione...
-
Senior Threat
3 giorni fa
Lazio, Italia Altro A tempo pienoA fast-growing fintech company in Italy is looking for a Senior Security Lead to strengthen its resilience to technology and cyber risks.This hands-on role involves shaping security strategies, conducting assessments, and collaborating with teams to build secure systems.Candidates should have 3–6 years of experience in security operations, a strong...
-
Lead Cloud Security Architect
1 giorno fa
Lazio, Italia Informatica Software A tempo pienoA tech-focused company is seeking a Senior Infrastructure Security Engineer to lead security initiatives and embed security practices in cloud-native systems.The role requires strong cloud infrastructure security, programming skills in Go or Python, and proficiency in Kubernetes.Benefits include comprehensive health support, flexible paid time off, equity...
-
Senior Security Lead
3 giorni fa
Lazio, Italia Altro A tempo pienoHercle is a fast-growing fintech building institutional-grade infrastructure that bridges fiat, stablecoins, and digital assets, enabling cross-border transactions at scale and in real time.Serving over 200 clients globally, Hercle provides banks, brokers, payment service providers, and fintechs with seamless solutions for cross-border payments, trading, and...
-
Senior Pm, Identity Protection
3 giorni fa
Lazio, Italia Malwarebytes A tempo pienoA cybersecurity solutions company located in Italy is seeking a Senior Product Manager to lead its Identity Protection product line.The ideal candidate will have over 5 years of experience in software product management, strong technical aptitude, and excellent communication skills.Responsibilities include driving product strategy, optimizing user...
-
Industrial Ot Security
2 settimane fa
Lazio, Italia Bayer Cropscience Limited A tempo pienoA leading pharmaceutical company in Milan seeks an Operational Technology Security Expert to lead cybersecurity governance and compliance for its Italian production site.The ideal candidate will have over 5 years of experience, a degree in a relevant field, and strong skills in risk management and project coordination.This role emphasizes fostering a strong...
-
Senior Software Engineer
24 ore fa
Lazio, Italia Leonardo A tempo pienoUn'importante azienda nel settore Aerospazio e Sicurezza cerca un Software Engineer a Roma.Il candidato ideale ha una laurea in discipline STEM e almeno 3 anni di esperienza come Senior Developer.Le competenze richieste includono conoscenze di linguaggi di programmazione e Cyber Security, oltre a capacità di lavorare in team e problem solving.Sono previste...
-
Senior Network
2 settimane fa
Lazio, Italia Altro A tempo pienoRicerca di un Senior Network & Security Architect a Roma con esperienza in networking, sicurezza informatica, Cisco e Fortinet, per la progettazione e gestione di architetture complesse.
-
Consultant/Senior Consultant
1 settimana fa
Lazio, Italia Altro A tempo pienoChi siamo Siamo un gruppo multinazionale di consulenza direzionale, leader nell'analisi e nella progettazione di modelli di Governance, Organizzazione e Controllo.Aiutiamo i nostri clienti ad esplorare nuove opportunità di sviluppo e crescita del valore, identificando rischi e definendo le migliori strategie di gestione e controllo.Abbiamo una significativa...
-
Senior Security Solutions Architect
1 settimana fa
Lazio, Italia Amazon A tempo pienoSenior Security Solutions Architect , Security SA, ASEANJob ID: ******* | Amazon Web Services Singapore Private LimitedDo you have the passion for helping customers and partners design and create robust security architectures to address their enterprise risk management requirements using cloud computing?Do you enjoy helping customers become more secure...