Cybersecurity Lead
🧡 Coverflex
Work changed. Pay didn’t.
Coverflex exists to make compensation work for everyone.
Pay is still rigid, fragmented, and hard to feel.
We turn compensation into choice — one platform, one card, one app — for benefits, meal allowance, insurance and more.
Our platform is simple for HR and meaningful for employees.
We provide choice, smarter compensation tools and empowerment.
⚙️ TL;DR (The Essentials)
Role: Cybersecurity Lead
Seniority Level: Lead
Type: Individual Contributor
Languages: English (main) / Portuguese or Spanish or Italian a plus
Main Tools: AWS and/or GCP security tooling, SIEM, detection/response, EDR/MDM, identity/SSO/MFA, and privileged-access tooling, Vulnerability scanning, application security testing, and penetration-testing workflows, Jira/Notion or equivalent risk, remediation, evidence, and roadmap tracking, Scripting/automation for control operation and evidence collection
Location: Remote (Europe only)
Compensation:
Base Salary: 65.000€ to 95.000€ gross yearly
Bonus / Commissions: No
Equity: Yes – Stock Options under our Equity Incentive Plan
Benefits: All Coverflex benefits apply
Contract Type: Permanent
💥 Your Impact
Your role will play a major role in our success because…
The Cybersecurity Lead will help Coverflex grow as a trusted, resilient multi-market fintech. By identifying material risks earlier, strengthening security operations and third-party assurance, and making security evidence reusable, this role will protect customers and company data, support reliable payment and benefits services, preserve ISO 27001 and contractual commitments, and reduce friction in launches, enterprise sales, renewals, and audits.
You’ll know you’re successful if, after 90 days...
100% of material security risks have an owner, treatment decision, due date, and monthly review; a monthly dashboard and quarterly Management Team risk review are in place; and all required ISMS, cybersecurity, and related privacy documentation has a named owner, review cadence, and current approved version.
At least one executive risk exercise and one technical control validation are completed, with ≥90% of resulting actions closed by their due dates; ≥95% of critical/high vulnerabilities are remediated within policy SLA and all exceptions are formally approved and time-bound.
100% of defined high-risk changes receive a risk-based review before launch; 100% of critical suppliers are tiered and the highest-risk suppliers are assessed, with contractual and technical gaps tracked.
How we’ll measure success:
Establish ownership and visibility: consolidate material security risks, findings, exceptions, critical suppliers, security actions, tooling, spend, and key-person dependencies; own and maintain the core ISMS and cybersecurity documentation, including the Information Security Policy and Cybersecurity Risk Management Plan; and publish a risk-ranked 12-month roadmap and management dashboard. Privacy- and GDPR-specific documentation remains jointly coordinated with the DPO and Legal/Compliance, with explicit ownership agreed for each document.
Operationalise security governance and resilience: clarify escalation roles, risk thresholds, control ownership, evidence requirements, vulnerability SLAs, and the risk-exception workflow; run an executive risk exercise and technical control validation covering a critical payment partner.
Embed proportionate assurance into growth: establish review gates for high-risk launches, architecture changes, and critical vendors; introduce repeatable threat-modelling patterns; tier critical third parties and track material gaps to closure.
⚡ Reality Check - What Makes This Role Hard
Let’s be real - here’s what makes this role challenging:
This is a broad, hands-on role in a scaling, regulated, multi-market environment. The person must move comfortably between technical investigation, cloud and product security, risk and assurance, partner management, and executive communication. They will need to influence teams without taking ownership away from Engineering, Product, Legal/Compliance, the DPO, or business leaders; prioritise ruthlessly with limited dedicated capacity; and build useful guardrails without becoming a gatekeeper. Third-party dependencies, an evolving threat surface, remote-first operations, and fragmented security ownership add complexity.
👤 You
Must-haves (evidence, not years)
Senior, hands-on security experience in a regulated fintech, payments, SaaS, or similarly high-trust environment
Personally conducted security investigations, tuned detections, assessed cloud and identity controls, reviewed architectures, and validated vulnerability remediation
Strong cloud, application/product security, IAM, detection/response, vulnerability management, and third-party risk judgement
Experience owning ISO 27001 or comparable assurance while keeping the programme outcome-focused
Ability to build a proportionate security programme in a scaling company, not only operate within a mature enterprise function
Credibility with engineers and the ability to translate technical detail into clear business recommendations
Fluent professional English
Nice-to-have
Experience with payment processors, card ecosystems, regulated partners, or multi-market fintech operations
Experience using managed security services and specialist providers effectively
Security automation and evidence-collection experience
Experience with executive risk exercises and supplier resilience scenarios
Relevant certifications such as CISSP, CISM, CCSP, OSCP, or ISO 27001 Lead Implementer/Auditor; practical evidence matters more than certificates
🧬 Your DNA
Pragmatic, calm under pressure, curious, and evidence-driven. You combine sound judgement with a bias for action, challenge constructively, and communicate risk without fearmongering. You are comfortable doing the work yourself while creating leverage through standards, automation, and collaboration. You understand commercial trade-offs, make clear recommendations, and escalate material risks appropriately rather than seeking universal control.
You should add dedicated security depth and consistent ownership while preserving clear accountability in the teams that own systems and decisions. You will make Engineering, Product, IT, Legal/Compliance, the DPO, and leadership more effective through prioritisation, expert challenge, reusable patterns, direct technical support, and reliable follow-through. You should reduce key-person dependency on Technology Leadership and become the trusted bridge between technical evidence and business risk decisions.
👥 Manager & Team
Meet Your Manager
Hiring Manager: Tiago Fernandes, CTO
Location: Portugal
LinkedIn Profile
Profile Snapshot:
Who you are as a person: Curious and motivated by solving meaningful problems with durable systems rather than theatre. My approach can be pragmatic, but I also enjoy exploring a problem deeply before converging on the answer.
Who you are as a manager: I give experienced people autonomy and trust them to bring judgement, ownership, and a point of view. I do not always provide perfectly clear context at the outset, so I value people who ask questions, help structure ambiguity, and confirm shared outcomes and priorities.
Your type of energy: Calm, analytical, low-ego, and action-oriented—particularly in high-pressure and ambiguous situations.
Your communication style: Candid and context-rich. I sometimes provide more context than necessary or do not land the clearest version immediately, so I appreciate people who synthesise, ask clarifying questions, and help turn discussion into explicit decisions and next steps.
Your feedback style: Thoughtful and conversational, focused on learning and improving the work rather than assigning blame. I value a two-way dialogue and expect people to ask for clarification when the feedback is not sufficiently clear or actionable.
What is it like to work with you?
You will have meaningful autonomy, access to leadership, and support when a risk requires escalation. I expect you to bring a point of view, go deep enough to understand the facts, and be comfortable creating structure from ambiguity. We will not always begin with perfectly packaged context, so asking questions, summarising what you heard, and making decisions explicit are important. Healthy challenge is welcome, as is helping me simplify or sharpen the framing. The goal is to build a trusted security function that enables the business while being honest about material risk.
Your Team
Team structure: This is initially a senior individual-contributor role reporting to the CTO and owning the cybersecurity function. It is a hands-on position rather than a people-management layer. You will maintain the security roadmap, backlog, operating metrics, tooling, targeted specialist support, and core ISMS and cybersecurity policies and plans. You will partner with the DPO and Legal/Compliance on GDPR- and privacy-related documentation, with explicit ownership agreed per document. Engineering and other system-owning teams remain responsible for implementation, remediation, service ownership, and recovery.
Other stakeholders: Technology Leadership; Engineering and Infrastructure/Platform; Product; IT; Legal/Compliance; the DPO/Privacy; Finance and Procurement; People; Customer-facing teams; the Management Team; external auditors, penetration testers, managed security providers, cloud/SaaS vendors, and critical regulated/payment partners. The Management Team remains the final decision-maker for material residual-risk acceptance and major business trade-offs.
💜 Access & Belonging (Equal Opportunity)
We hire for impact and potential, not pedigree.
We welcome applications from people with non-linear careers, career breaks, caregiving gaps, and those changing fields.
No discrimination on the basis of age, disability, gender identity/expression, marital or family status, pregnancy, neurodivergence, race/ethnicity, religion/belief, sexual orientation, or any other protected ground.
Assessment fairness:
We anchor on evidence of outcomes (what you shipped, moved, or influenced).
We actively de-bias by using structured rubrics, multiple assessors, and blind screening most of the time (we won’t know your name, gender, or personal info until the interview stage).
📬 Application Clarity
No cover letter required.
Apply with your LinkedIn or upload your CV.
You may be asked a few short, relevant questions.
Total candidate time investment: ~3–5 hours end-to-end.
🧩 Hiring Stages (What to Expect, Why & How Long)
1. CV / LinkedIn Screen — Signal check vs must-haves
• Done by People + Hiring Manager.
• You’ll hear from us within 7 business days.
2. Role-Fit Questionnaire (async)
Purpose: capture signals your CV can’t (languages, tools, scenario judgement) and calibrate seniority.
Format: multiple choice + short answers.
Accessibility: prefer a call? Tell us - we’ll swap for a short chat.
3. Hiring Manager Interview - Deep dive into your work • 45–60 min
Structured around outcomes, decisions, and collaboration.
4. Behavioural Interview - Show how you think • 45-60 min
Use our case or bring a real artefact (deck, PR, analysis, playbook).
We assess clarity, decision quality, stakeholder thinking, and ethics.
5. Case / Work Sample - Show how you think • ≤90 min
Use our case or bring a real artefact (deck, PR, analysis, playbook).
We assess clarity, decision quality, stakeholder thinking, and ethics.
6. Case Review & Team Chat - Walkthrough + Q&A • 20–30 min
You’ll get actionable feedback either way.
7. Final Conversation (CEO / C-Level) — Values, strategy, and your growth • 30–45 min
Optional: References (2–3 people who’ve seen your recent work) - async.
🤖 AI & Hiring Tools Transparency
We use a few tools to reduce bias and improve documentation, not to make hiring decisions.
Teamtailor anonymisation: profiles are reviewed without relying on names/personal identifiers.
Meeting recording tools (e.g., Talka.ai): may be used to capture interviews so we can focus on the conversation.
ChatGPT: may be used to turn interview notes/transcripts into clear, structured summaries.
Important: every application is reviewed by a human, and no decision or rejection is made by AI. If recording is used, we’ll be transparent and (where required) ask for consent.
⏱️ Speed & Communication
Decision: within 4 weeks of your application.
Updates: weekly if the process runs longer.
Scheduling: interviews between 10:00–16:00 CET (flexible across Europe).
Feedback: from the Case stage onwards, you’ll always receive written or verbal feedback - what went well, and what to strengthen next time.
- Team
- Tech
- Remote status
- Fully Remote
Perks
-
👊 Unique Culture
A team committed to creating a strong and unique culture that celebrates diversity (and weirdness). Learn even further about us on our purpose page!
-
👩🏻💻 Fully Remote
A fully remote setup, with on-site get-togethers at least once a year.
-
💸 Compensation
Competitive and flexible compensation, including our own Coverflex card and stock options to really own our success.
-
🖥️ Workstation & Onboarding Budget
A MacBook and a €500 onboarding budget to help you set up an effective workstation during your first months.
-
📚 FlexBudget
A €1,000 yearly budget to invest in your professional development & remote work enablement.
-
👩⚕️ Health Insurance
Health Insurance plans, with the option to add family members and update conditions (*depending on country).
-
🌴 Time Off
25 day paid vacation days + 3 caring days per year to work on side projects that support causes with a positive impact on our society.
-
🐱🐶🐹 Family Friendly
2 additional paid weeks on top of the legal maximum Parental Leave. Your birthday + kids’ birthday off.