406,751open jobs
14,106companies
78,682added this week
Browse all
Location
In office
Employment
Full-Time
Overview
Company
Impact
Profile match
Transak is a fiat-to-crypto payments company founded in 2019 and headquartered in London. Its developer integration lets wallets, games and marketplaces accept local payment methods in more than a hundred countries. The company handles identity verification, licensing and settlement on behalf of the applications that embed it.

About the company:

Our mission is that "Any financial application can onboard any user, anywhere in the world, in 1 click." Transak provides onboarding to financial applications through authentication, KYC, risk checks, and fiat on/off ramps. This is a next generation of infrastructure for the next generation of financial applications that are built on blockchain and stablecoin rails. Our API and widget-based solutions are used by top partners like MetaMask, Coinbase, Ledger, and Trust Wallet to enable seamless onboarding of over 10 million users across over 450 active applications.

We have raised over $37M from top-tier investors including Consensys, Tether, and Animoca Brands.

About the Role:

Transak operates regulated entities across the EU, MENA and the US. Security controls are owned and operated by the first line such as DevOps, IT and engineering teams. Independent oversight of whether those controls actually work, whether they satisfy the obligations Transak is licensed under, and what residual risk the business is carrying, sits in the second line with the CISO.

This role joins that second line, reporting to the CISO and working closely with the Risk and Compliance functions. You will not build or operate security controls. You will test whether they work, and say so when they do not. There is no established testing programme to inherit: you will design it, run it, and make it credible to an auditor.

What You'll Be Doing

As Transak's first dedicated second-line information security hire, you will provide independent assurance over the security controls the business relies on. Your responsibilities include:

  • Design and run a risk-based control testing programme over first-line security controls, with a defined cycle, scope and sampling approach.
  • Test the control, pull the evidence, sample the population, re-perform where feasible, and form an independent conclusion.
  • Focus testing where it matters most for a fiat on and off ramp: privileged access and segregation of duties, access recertification, change and release approval, backup and restore, incident response execution, and ICT third-party oversight.
  • Maintain the mapping between regulatory obligation and implemented control across MiCA, DORA, SOC 2 and ISO 27001.
  • Cover the regional regimes applying to the MENA and US entities, rather than assuming EU compliance is a superset, and surface obligations with no owning control as gaps.
  • Run the information security and ICT risk register alongside the Risk function, using the group risk taxonomy rather than a security-only one.
  • Challenge first-line risk ratings and acceptances, including testing whether the compensating controls cited actually operate.
  • Produce assurance reporting for committee and board that distinguishes what has been independently tested from what has been asserted by the first line.
  • Act as the internal counterpart to external audit and regulatory examination, and run readiness assessments so that findings are known internally before they are found externally.
  • Operate as one second line with Risk and Compliance - shared register, shared obligation mapping, and the first line asked once for evidence.
  • Translate between technical control and regulatory obligation, so colleagues in Risk and Compliance do not need to interpret a cloud or identity control themselves.

What We're Looking For

Core Experience:

  • 5+ years in a second-line, technology risk, IT audit or security assurance role, with meaningful time in a regulated financial institution.
  • Has independently tested technical security controls - designed the test, sampled the population, formed an own conclusion.
  • Deep working knowledge of at least one financial services regime, and the ability to translate a specific article into a testable control and the evidence that proves it.
  • Practical understanding of identity and access, cloud, change and resilience controls, sufficient to test them credibly and to recognise an incomplete first-line answer.
  • Risk register ownership: rating methodology, escalation thresholds, and reporting into a governance forum.
  • Experience producing assurance reporting for a committee or board audience.
  • Comfortable acting as the internal counterpart to external audit or a regulatory examination.
  • Willing to hold a finding under pressure from a senior stakeholder, with the judgement to do so without damaging the working relationship.
  • Excellent communication skills, able to move between an engineering audience and a board audience.
  • Comfortable building a programme from nothing rather than inheriting a mature one.

Bonus:

  • Cryptoasset, VASP, payments or neobank experience, particularly under MiCA or an equivalent regime.
  • Multi-jurisdiction experience covering MENA or the US.
  • Familiarity with ICT risk under DORA and its regulatory technical standards.
  • Prior first-line security experience, giving credibility with engineers, provided independence is understood.
  • Experience of a firm going through a licence application or authorisation gateway.
  • Certifications such as CISSP, CISA, CRISC, CISM, CIA or ISO 27001 Lead Auditor.
  • Experience standing up a second-line function where none existed.

Why join us

  • Equity options so you can share in the success of the company
  • A fast-moving, fun, and international company made up of skillful team players
  • Transparent, Open, and Collaborative work environment
  • A competitive compensation package and comprehensive benefits offering
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
406,751 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$43k – $93k per year (Estimated) • Remote • 5+ years exp
Go
JavaScript
Databases
ClickHouse
Firestore
Redis
AI/ML
Tokenization
Frontend
Vue.js
DevOps
Chaos Engineering
CI/CD
FinOps
GCP
Google GKE
gRPC
Incident Management
Kubernetes
OpenTelemetry
SLI/SLO/SLA
Cybersecurity
ISO 27001
PCI DSS
SOC 2
Apply
Backend Engineer 1 day ago
$85k – $240k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Tel Aviv
Python
Rust
SQL
Databases
Apache Kafka
Kafka
RabbitMQ
AI/ML
Airflow
Dagster
dbt
Flink
Spark
DevOps
Amazon Kinesis
AWS
CI/CD
GCP
Kubernetes
Web3
MetaMask
Stellar
Uniswap
Analytics
ETL/ELT
Apply
Remote/Hybrid • Full-Time • 4+ years exp • Singapore
AI/ML
Claude
Web3
MetaMask
Stellar
Uniswap
Apply
$106k – $240k per year (Estimated) • Remote/Hybrid • Full-Time • Tel Aviv
Python
Rust
Web3
MetaMask
Smart Contracts
Stellar
Uniswap
Apply
Remote/Hybrid
PowerShell
Python
DevOps
Azure
Azure AKS
Azure DevOps
Bicep
CI/CD
Docker
Kubernetes
Cybersecurity
ISO 27001
Microsoft Sentinel
Apply
$53k – $121k per year (Estimated) • Equity • Remote • Full-Time • 5+ years exp
JavaScript
Node JS
Python
Frontend
npm
DevOps
CI/CD
GitHub
GitHub Actions
GitLab
GitLab CI
Jenkins
Cybersecurity
Burp Suite
EPSS
GDPR
ISO 27001
KEV
OWASP Top 10
OWASP ZAP
SBOM
SLSA
Snyk
SOC 2
Web3
MetaMask
Trust Wallet
Apply
In office • Full-Time • Bachelor's Degree • Bengaluru
Web3
MetaMask
Token Standards
Trust Wallet
Management
Intercom
Marketing
Zendesk
Apply
MLRO, UK 11 days ago
Equity • Remote • Full-Time • Bachelor's Degree
Web3
MetaMask
Trust Wallet
Apply
$64k – $151k per year (Estimated) • Remote • Full-Time • 6+ years exp • London
Node JS
TypeScript
JavaScript
Databases
Apache Kafka
Redis
Kafka
DevOps
Amazon EKS
AWS
AWS Lambda
CI/CD
CloudFormation
gRPC
Jenkins
New Relic
Pipeline as Code
Terraform
Kubernetes
Amazon CloudWatch
Amazon ECS
Amazon S3
IAM
Cybersecurity
PCI DSS
Web3
MetaMask
Trust Wallet
Apply
$126k – $227k per year (Estimated) • In office • Full-Time • 5+ years exp • Miami
Web3
MetaMask
Trust Wallet
Apply
See all jobs
This is one of many
406,751 more open roles from verified company boards, updated every day.