{"id":1325337,"url":"https://alion.io/job/coverflex-cybersecurity-lead","title":"Cybersecurity Lead","company":{"id":54021,"name":"Coverflex","domain":"coverflex.com","url":"https://alion.io/company/coverflex","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Teamtailor","truth_index":{"grade":"B","score":75,"open_postings":5,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-28T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"lead","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"posting_text","remote_working_hours":{"label":"CET","utc_offset_min":1,"utc_offset_max":1},"hiring_geo_confidence":"explicit","locations":[],"countries":[],"hiring_countries":["PT"],"hiring_countries_total":1,"salary":{"min":65000,"max":95000,"currency":"EUR","period":"year","gross":true,"usd_annual":108476},"salary_estimate":null,"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":true,"technologies":[{"name":"AWS","optional":false},{"name":"GCP","optional":false},{"name":"GDPR","optional":false},{"name":"IAM","optional":false},{"name":"ISO 27001","optional":false},{"name":"Jira","optional":false},{"name":"Notion","optional":false},{"name":"SIEM","optional":false},{"name":"SLI/SLO/SLA","optional":false},{"name":"ChatGPT","optional":true}],"status":"live","first_seen_at":"2026-09-22T16:06:16Z","employer_posted_date":"2026-09-22","last_verified_at":"2026-09-27T07:25:44Z","board_verified":true,"closed_at":null,"days_open":5,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":5},"description":"Coverflex\nWork changed. Pay didn’t.\nCoverflex exists to make compensation work for everyone.\nPay is still rigid, fragmented, and hard to feel.\nWe turn compensation into choice - one platform, one card, one app - for benefits, meal allowance, insurance and more.\nOur platform is simple for HR and meaningful for employees.\nWe provide choice, smarter compensation tools and empowerment.\nTL;DR (The Essentials)\nRole: Cybersecurity Lead\nSeniority Level: Lead\nType: Individual Contributor\nLanguages: English (main) / Portuguese or Spanish or Italian a plus\nMain Tools: AWS and/or GCP security tooling, SIEM, detection/response, EDR/MDM, identity/SSO/MFA, and privileged-access tooling, Vulnerability scanning, application security testing, and penetration-testing workflows, Jira/Notion or equivalent risk, remediation, evidence, and roadmap tracking, Scripting/automation for control operation and evidence collection\nLocation: Remote (Europe only)\nCompensation:\nBase Salary: 65.000€ to 95.000€ gross yearly\n\nBonus / Commissions: No\n\nEquity: Yes - Stock Options under our Equity Incentive Plan\n\nBenefits: All Coverflex benefits apply\n\nContract Type: Permanent\n\nYour Impact\nYour role will play a major role in our success because…\nThe Cybersecurity Lead will help Coverflex grow as a trusted, resilient multi-market fintech. By identifying material risks earlier, strengthening security operations and third-party assurance, and making security evidence reusable, this role will protect customers and company data, support reliable payment and benefits services, preserve ISO 27001 and contractual commitments, and reduce friction in launches, enterprise sales, renewals, and audits.\nYou’ll know you’re successful if, after 90 days...\n\n100% of material security risks have an owner, treatment decision, due date, and monthly review; a monthly dashboard and quarterly Management Team risk review are in place; and all required ISMS, cybersecurity, and related privacy documentation has a named owner, review cadence, and current approved version.\n\nAt least one executive risk exercise and one technical control validation are completed, with ≥90% of resulting actions closed by their due dates; ≥95% of critical/high vulnerabilities are remediated within policy SLA and all exceptions are formally approved and time-bound.\n\n100% of defined high-risk changes receive a risk-based review before launch; 100% of critical suppliers are tiered and the highest-risk suppliers are assessed, with contractual and technical gaps tracked.\n\nHow we’ll measure success:\nEstablish ownership and visibility: consolidate material security risks, findings, exceptions, critical suppliers, security actions, tooling, spend, and key-person dependencies; own and maintain the core ISMS and cybersecurity documentation, including the Information Security Policy and Cybersecurity Risk Management Plan; and publish a risk-ranked 12-month roadmap and management dashboard. Privacy- and GDPR-specific documentation remains jointly coordinated with the DPO and Legal/Compliance, with explicit ownership agreed for each document.\n\nOperationalise security governance and resilience: clarify escalation roles, risk thresholds, control ownership, evidence requirements, vulnerability SLAs, and the risk-exception workflow; run an executive risk exercise and technical control validation covering a critical payment partner.\n\nEmbed proportionate assurance into growth: establish review gates for high-risk launches, architecture changes, and critical vendors; introduce repeatable threat-modelling patterns; tier critical third parties and track material gaps to closure.\n\nReality Check - What Makes This Role Hard\nLet’s be real - here’s what makes this role challenging:\nThis is a broad, hands-on role in a scaling, regulated, multi-market environment. The person must move comfortably between technical investigation, cloud and product security, risk and assurance, partner management, and executive communication. They will need to influence teams without taking ownership away from Engineering, Product, Legal/Compliance, the DPO, or business leaders; prioritise ruthlessly with limited dedicated capacity; and build useful guardrails without becoming a gatekeeper. Third-party dependencies, an evolving threat surface, remote-first operations, and fragmented security ownership add complexity.\nYou\nMust-haves (evidence, not years)\nSenior, hands-on security experience in a regulated fintech, payments, SaaS, or similarly high-trust environment\n\nPersonally conducted security investigations, tuned detections, assessed cloud and identity controls, reviewed architectures, and validated vulnerability remediation\n\nStrong cloud, application/product security, IAM, detection/response, vulnerability management, and third-party risk judgement\n\nExperience owning ISO 27001 or comparable assurance while keeping the programme outcome-focused\n\nAbility to build a proportionate security programme in a scaling company, not only operate within a mature enterprise function\n\nCredibility with engineers and the ability to translate technical detail into clear business recommendations\n\nFluent professional English\n\nNice-to-have\nExperience with payment processors, card ecosystems, regulated partners, or multi-market fintech operations\n\nExperience using managed security services and specialist providers effectively\n\nSecurity automation and evidence-collection experience\n\nExperience with executive risk exercises and supplier resilience scenarios\n\nRelevant certifications such as CISSP, CISM, CCSP, OSCP, or ISO 27001 Lead Implementer/Auditor; practical evidence matters more than certificates\n\nYour DNA\nPragmatic, calm under pressure, curious, and evidence-driven. You combine sound judgement with a bias for action, challenge constructively, and communicate risk without fearmongering. You are comfortable doing the work yourself while creating leverage through standards, automation, and collaboration. You understand commercial trade-offs, make clear recommendations, and escalate material risks appropriately rather than seeking universal control.\nYou should add dedicated security depth and consistent ownership while preserving clear accountability in the teams that own systems and decisions. You will make Engineering, Product, IT, Legal/Compliance, the DPO, and leadership more effective through prioritisation, expert challenge, reusable patterns, direct technical support, and reliable follow-through. You should reduce key-person dependency on Technology Leadership and become the trusted bridge between technical evidence and business risk decisions.\nManager & Team\nMeet Your Manager\nHiring Manager: Tiago Fernandes, CTO\nLocation: Portugal\nLinkedIn Profile\nProfile Snapshot:\nWho you are as a person: Curious and motivated by solving meaningful problems with durable systems rather than theatre. My approach can be pragmatic, but I also enjoy exploring a problem deeply before converging on the answer.\n\nWho you are as a manager: I give experienced people autonomy and trust them to bring judgement, ownership, and a point of view. I do not always provide perfectly clear context at the outset, so I value people who ask questions, help structure ambiguity, and confirm shared outcomes and priorities.\n\nYour type of energy: Calm, analytical, low-ego, and action-oriented-particularly in high-pressure and ambiguous situations.\n\nYour communication style: Candid and context-rich. I sometimes provide more context than necessary or do not land the clearest version immediately, so I appreciate people who synthesise, ask clarifying questions, and help turn discussion into explicit decisions and next steps.\n\nYour feedback style: Thoughtful and conversational, focused on learning and improving the work rather than assigning blame. I value a two-way dialogue and expect people to ask for clarification when the feedback is not sufficiently clear or actionable.\n\nWhat is it like to work with you?\nYou will have meaningful autonomy, access to leadership, and support when a risk requires escalation. I expect you to bring a point of view, go deep enough to understand the facts, and be comfortable creating structure from ambiguity. We will not always begin with perfectly packaged context, so asking questions, summarising what you heard, and making decisions explicit are important. Healthy challenge is welcome, as is helping me simplify or sharpen the framing. The goal is to build a trusted security function that enables the business while being honest about material risk.\nYour Team\nTeam structure: This is initially a senior individual-contributor role reporting to the CTO and owning the cybersecurity function. It is a hands-on position rather than a people-management layer. You will maintain the security roadmap, backlog, operating metrics, tooling, targeted specialist support, and core ISMS and cybersecurity policies and plans. You will partner with the DPO and Legal/Compliance on GDPR- and privacy-related documentation, with explicit ownership agreed per document. Engineering and other system-owning teams remain responsible for implementation, remediation, service ownership, and recovery.\n\nOther stakeholders: Technology Leadership; Engineering and Infrastructure/Platform; Product; IT; Legal/Compliance; the DPO/Privacy; Finance and Procurement; People; Customer-facing teams; the Management Team; external auditors, penetration testers, managed security providers, cloud/SaaS vendors, and critical regulated/payment partners. The Management Team remains the final decision-maker for material residual-risk acceptance and major business trade-offs.\n\nAccess & Belonging (Equal Opportunity)\nWe hire for impact and potential, not pedigree.\nWe welcome applications from people with non-linear careers, career breaks, caregiving gaps, and those changing fields.\nNo discrimination on the basis of age, disability, gender identity/expression, marital or family status, pregnancy, neurodivergence, race/ethnicity, religion/belief, sexual orientation, or any other protected ground.\nAssessment fairness:\nWe anchor on evidence of outcomes (what you shipped, moved, or influenced).\nWe actively de-bias by using structured rubrics, multiple assessors, and blind screening most of the time (we won’t know your name, gender, or personal info until the interview stage).\nApplication Clarity\nNo cover letter required.\nApply with your LinkedIn or upload your CV.\nYou may be asked a few short, relevant questions.\nTotal candidate time investment: ~3-5 hours end-to-end.\nHiring Stages (What to Expect, Why & How Long)\n1. CV / LinkedIn Screen - Signal check vs must-haves\nDone by People + Hiring Manager.\nYou’ll hear from us within 7 business days.\n2. Role-Fit Questionnaire (async)\nPurpose: capture signals your CV can’t (languages, tools, scenario judgement) and calibrate seniority.\nFormat: multiple choice + short answers.\nAccessibility: prefer a call? Tell us - we’ll swap for a short chat.\n3. Hiring Manager Interview - Deep dive into your work\n45-60 min\nStructured around outcomes, decisions, and collaboration.\n4. Behavioural Interview - Show how you think\n45-60 min\nUse our case or bring a real artefact (deck, PR, analysis, playbook).\nWe assess clarity, decision quality, stakeholder thinking, and ethics.\n5. Case / Work Sample - Show how you think\n≤90 min\nUse our case or bring a real artefact (deck, PR, analysis, playbook).\nWe assess clarity, decision quality, stakeholder thinking, and ethics.\n6. Case Review & Team Chat - Walkthrough + Q&A\n20-30 min\nYou’ll get actionable feedback either way.\n7. Final Conversation (CEO / C-Level) - Values, strategy, and your growth\n30-45 min\nOptional: References (2-3 people who’ve seen your recent work) - async.\nAI & Hiring Tools Transparency\nWe use a few tools to reduce bias and improve documentation, not to make hiring decisions.\nTeamtailor anonymisation: profiles are reviewed without relying on names/personal identifiers.\n\nMeeting recording tools (e.g., Talka.ai): may...","description_format":"text","description_chars":12665,"description_truncated":true,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[{"language":"Portuguese","level":"All levels","optional":false},{"language":"Italian","level":"All levels","optional":false},{"language":"Spanish","level":"All levels","optional":false},{"language":"English","level":"All levels","optional":false}]},"benefits":["Equity","Stock options"],"hiring_locations":[{"name":"Portugal","iso":"PT","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Cards & Card Issuing","HR & Payroll Software"],"lifecycle":[{"event":"open","at":"2026-09-27T02:51:16Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":5,"expected_fill_days":46,"reasons":["conf:22","win:early"],"computed_at":"2026-09-28T05:45:00Z"},"pay":{"stated_usd_annual":108476,"is_top_pay":false},"html_url":"https://alion.io/job/coverflex-cybersecurity-lead","json_url":"https://alion.io/job/coverflex-cybersecurity-lead.json","meta":{"generated_at":"2026-09-28T06:31:42Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4539,"day_limit":5000,"remaining_today":461,"minute_limit":60,"resets_at":"2026-09-29T00:00:00Z"}}}