617,667open jobs
29,889companies
85,625added this week
Browse all
Salary
$29k – $73k per year (Estimated)
Location
Remote (Bulgaria)
Seniority
Staff · 10+ years exp
Overview
Company
Impact
Profile match
emerchantpay is a London payments company founded in 2001 that provides global acquiring and a gateway for online and in-store merchants. Its platform supports cards and a wide range of alternative payment methods with fraud and chargeback management built in. The company works with retail, travel and digital goods businesses trading internationally.

emerchantpay is a leading global payment service provider and acquirer for online, mobile, in-store and over the phone payments. Our global payments solution is available through a simple integration, offering a diverse range of features, including global acquiring, global and local payment methods, advanced fraud management and performance optimisation. We empower businesses to design seamless and engaging payment experiences for their consumers.

We are looking for an IT Governance, Risk, and Compliance Manager to provide oversight of our ICT and information security risk profile, ensuring those risks are identified, managed, and reported within the company's risk appetite, and that governance, risk management, compliance, and resilience are embedded into the way the company operates and grows.

The role owns the integrated control framework, multi-standard certifications (ISO 27001, PCI DSS, and SOC), enterprise and third-party risk, business continuity, and key regulatory readiness programs - including the RBI licensing application in India, NIS 2, and the EU AI Act for AI governance and compliance - while acting as a trusted advisor to the Leadership Team.

The role sits within the IT function and is part of the Risk Management and Oversight Committee. It works closely with Engineering, IT, Legal, Finance, and the wider business.

Responsibilities

  • Define and maintain the information security strategy, standards, and roadmap, aligned to applicable regulations, rules, and security best practices.
  • Steer security architecture across a cloud-native environment, defining secure-by-design patterns for microservices, APIs, and shared platform services.
  • Establish and govern secure software development lifecycle (secure SDLC) practices, embedding automated security controls into CI/CD pipelines.
  • Define and drive adoption of cloud security guardrails - identity, network segmentation, encryption, secrets management, and configuration baselines.
  • Build and run security monitoring, logging, and threat detection across cloud, infrastructure, and application layers.
  • Lead the security incident response lifecycle - preparation, detection, containment, eradication, recovery, and post-incident review - and act as incident commander for security events.
  • Own vulnerability and threat management: scanning, risk-based prioritization, remediation tracking, and reporting across infrastructure, containers, and application code.
  • Plan and coordinate penetration testing and offensive-security exercises (in-house or co-sourced) and drive findings to closure.
  • Govern identity and access management, privileged access, and least-privilege principles across cloud and corporate systems.
  • Define and oversee data protection controls - encryption, key management, data classification, and loss prevention - for sensitive and cardholder data.
  • Secure corporate IT and office infrastructure, including endpoints, networks, and productivity and collaboration platforms.
  • Partner with Engineering and DevOps teams to make the secure path the easy path, providing tooling, standards, threat modelling, and design reviews.
  • Provide security input into architecture and change decisions, including the adoption of new technologies and third-party services.
  • Run security awareness and phishing-resilience programs for technical and non-technical staff.
  • Implement and evidence the technical security controls underpinning PCI DSS, ISO 27001, and SOC audits.
  • Monitor the evolving threat landscape and emerging security technologies.
  • Act as a key member of the internal security center of excellence and contribute to cross-functional security working groups.
  • Build, lead, and mentor a small security team.
  • Report security posture, key risks, and metrics.

Requirements

  • Bachelor’s or master’s degree in computer science, information security, or a related field, or equivalent practical experience.
  • At least 10 years in information / cyber security, including a minimum of 2-3 years in a leadership role, with hands-on experience securing cloud-native environments at scale.
  • Deep, practical public-cloud security knowledge (AWS strongly preferred): identity, networking, encryption, logging, and configuration management.
  • Strong experience securing DevOps / CI/CD pipelines and modern microservices architectures - containers, APIs, and infrastructure-as-code.
  • Working knowledge of application security and secure SDLC across modern programming languages and web frameworks.
  • Hands-on experience with security operations, incident response, and vulnerability management.
  • Solid understanding of security frameworks and compliance standards relevant to payments: ISO 27001, PCI DSS, SOC 2, and NIST CSF.
  • Working AI security literacy, with hands-on use of AI-assisted security tooling (e.g., GenAI coding assistants, AI-augmented SAST/DAST and SIEM/SOC analytics) and a practical understanding of securing AI/LLM and agentic applications, including AWS AI services such as Amazon Bedrock and the OWASP Top 10 risks for LLMs (e.g., prompt injection and data leakage).
  • Strong analytical and problem-solving ability, with high integrity and sound judgement.
  • Excellent verbal and written communication skills, fluent English, and the ability to influence engineers with data, logic, and best practices.

Considered as an Advantage

  • Professional certification such as CISSP, CCSP, OSCP, AWS Security Specialty, or CISM.
  • Experience in a payments, fintech, banking, or other regulated environment.
  • Familiarity with operational-resilience expectations (e.g. DORA-style requirements).
  • Experience standing up a security function.

Benefits

  • Fast-growing payment company;
  • Excellent working conditions, casual atmosphere, and state-of-the-art hardware;
  • Modern, challenging, constantly growing business;
  • Professional development - books, trainings, certifications, etc.;
  • Team buildings and fun activities;
  • 25 days paid holiday, 1 day for every 2 years with us;
  • Fully distributed and remote.

If you are interested, please apply with your CV in English only. Only short-listed candidates will be contacted.

Personal data of the applicants will be processed in strict confidentiality by emerchantpay ltd. UIC 175117520 solely for the purposes of selection and recruitment and will not be transferred to other data controllers unless required by law. Applicants provide their personal data on a voluntary basis and will have the right to access and correct their personal data within a reasonable time upon filing a written request.

emerchantpay is an equal opportunity employer. We appreciate people with different backgrounds and mindsets, and we honor diversity and inclusion.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
617,667 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Sofia
In office • 5+ years exp
JavaScript
Java
TypeScript
SQL
Node JS
Java
Spring Boot
Node JS
Nest.JS
AI/ML
Copilot
Claude Code
Model Context Protocol
Prompt Engineering
OpenAI Codex
Frontend
Angular
React.js
DevOps
Azure
CI/CD
Git
AWS
Management
Agile
Apply
In office • 6+ years exp • Master's Degree
Python
JavaScript
SQL
Databases
Databricks
AI/ML
Copilot
Claude Code
MLFlow
Time Series Forecasting
OpenAI Codex
Frontend
React.js
DevOps
CI/CD
AWS
Docker
Kubernetes
Amazon ECS
Management
Agile
Apply
In office
Python
AI/ML
AI Agents
Analytics
Power BI
Apply
Performance Analyst 10 hours ago
In office
Databases
Databricks
AI/ML
AI Agents
Apply
In office • Contractor • 7+ years exp
JavaScript
C#
C#
ASP.NET Core
WPF
Frontend
npm
Mobile
MVVM
DevOps
Azure
Git
AWS
Apply
$35k – $91k per year (Estimated) • Remote/Hybrid • 5+ years exp • Sofia
Apply
$38k – $94k per year (Estimated) • Remote • 10+ years exp • Sofia
JavaScript
Node JS
Node JS
Commander.js
AI/ML
AI Agents
AWS Bedrock
LLM
LLM Guardrails
DevOps
CI/CD
AWS
Configuration Management
Cybersecurity
ISO 27001
NIST CSF
OWASP Top 10
PCI DSS
SOC 2
Least Privilege
Apply
Senior AI Engineer 4 months ago
$35k – $89k per year (Estimated) • Remote • 7+ years exp • Sofia
Python
JavaScript
Python
Flask
FastAPI
Django
Databases
PostgreSQL
pgvector
Pinecone
OpenSearch
AI/ML
AutoGen
LangChain
LlamaIndex
Fine-tuning
Embeddings
RLHF
Prompt Engineering
Function Calling
AI Agents
Semantic Kernel
AWS Bedrock
Transformers
TensorFlow
PyTorch
CrewAI
Gemini
LLM
RAG
Hallucination
Reranking
OpenAI
Anthropic
Hugging Face
Amazon SageMaker
AWS Bedrock AgentCore
Feature Store
Human-in-the-Loop
LLM Guardrails
Agentic Workflows
Tool Use
Reward Modeling
Frontend
React.js
DevOps
Terraform
AWS CDK
CloudFormation
AWS
Docker
Kubernetes
Amazon EKS
Vector
Amazon ECS
Analytics
ETL/ELT
Apply
AI Tech Lead 4 months ago
$42k – $101k per year (Estimated) • Remote • 10+ years exp • Sofia
Python
Python
Flask
FastAPI
Django
Databases
PostgreSQL
pgvector
Pinecone
OpenSearch
AI/ML
AutoGen
LangChain
LlamaIndex
Fine-tuning
Embeddings
Prompt Engineering
Function Calling
AI Agents
Semantic Kernel
AWS Bedrock
CrewAI
LLM
RAG
Hallucination
Reranking
Amazon SageMaker
LLMOps
AWS Bedrock AgentCore
Feature Store
LLM Guardrails
Agentic Workflows
Tool Use
DevOps
Terraform
AWS CDK
CloudFormation
CI/CD
AWS
Docker
Kubernetes
Amazon EKS
Vector
Amazon ECS
Analytics
ETL/ELT
Apply
Account Manager 2 years ago
$24k – $69k per year (Estimated) • Remote/Hybrid • 1+ year exp • Sofia
Apply
$28k – $65k per year (Estimated) • In office • Full-Time • Master's Degree • Lisbon • Warsaw • Barcelona • Budapest • Prague
Apply
$20k – $57k per year (Estimated) • In office • Full-Time • Sofia
AI/ML
LLM
Semantic Search
Analytics
Looker
Management
Google Sheets
Marketing
GA4
Ahrefs
Screaming Frog
Apply
Remote/Hybrid • Full-Time • 3+ years exp • Sofia
AI/ML
ChatGPT
Midjourney
Game Dev
Spine
Design
Adobe Photoshop
Adobe After Effects
Apply
Remote/Hybrid • Full-Time • 3+ years exp • Sofia
Python
Java
C#
C++
Management
Agile
Apply
Remote • Full-Time • Sofia
Apply
See all jobs
This is one of many
617,667 more open roles from verified company boards, updated every day.