← All verified jobs

Chief Information Security Officer

trustly San Francisco, CA

See all open roles at trustly

Ghost-risk verdict

Some ghost-posting signals

  • open for 111 days (90+ without a fill is a strong ghost signal)
  • 35 open roles at this company in 30 days (mass-hiring blitz)
  • no salary disclosed (correlates with ghost postings)

How we score ghost risk →

See your fit for this role and apply with a truthfully tailored résumé.

See my fit, free

About the role

What you’ll do

Information Security Strategy & Program Leadership

Define and execute Trustly’s global information security strategy, roadmap, and multi-year program, aligned to business objectives and risk appetite.

Own the enterprise security architecture across cloud infrastructure, payment systems, APIs, and internal applications.

Build and mature security capabilities spanning identity and access management, threat detection and response, data protection, application security, and vulnerability management.

Lead and develop a high-performing security team; attract, retain, and grow top security talent across the organization.

Champion a security-first culture, partnering with Engineering, Product, Legal, and Finance to embed security into every stage of the development and business lifecycle.

Information Technology Organization

Lead the global IT function, overseeing end-user computing, workplace technology, service desk, network infrastructure, and enterprise systems.

Drive operational excellence and reliability across IT services for Trustly’s distributed, global workforce.

Lead our global workforce in productivity improvements centered around AI.

Own IT vendor relationships and enterprise tool strategy, ensuring cost-effectiveness, scalability, and compliance.

Oversee IT disaster recovery and business continuity programs, ensuring resilience across critical business systems.

Risk Management & Regulatory Compliance

Own Trustly’s cybersecurity risk framework, conducting regular assessments and translating technical risk into business terms for executive and Board audiences.

Ensure compliance with applicable regulatory requirements across all operating jurisdictions, including PCI DSS, SOC 2, GDPR, DORA, ISO 27001, CCPA, and open banking regulations.

Partner with Legal and Compliance to navigate evolving data privacy and financial services regulations in the U.S., EU, and other markets.

Lead third-party and vendor risk management, ensuring Trustly’s partner and supply chain ecosystem meets security standards.

Security Operations & Incident Response

Oversee the Security Operations Center (SOC), threat intelligence, and incident response capabilities, ensuring rapid detection, containment, and recovery.

Serve as executive incident commander for major security events; manage stakeholder communications, regulatory notifications, and post-incident reviews.

Continuously improve detection engineering, red team / blue team programs, and tabletop exercise cadences.

Executive Leadership & Board Engagement

Present security and IT risk posture, program updates, and strategic priorities to the Board of Directors and executive leadership on a regular basis.

Partner with the CTO, CFO, General Counsel, and other C-suite executives to align security investments with business strategy.

Represent Trustly externally with regulators, auditors, strategic partners, and industry bodies.

Who you are

15+ years of progressive experience in cybersecurity, with demonstrated breadth across security architecture, risk management, compliance, and security operations.

Proven track record of building and scaling enterprise security programs in complex, high-growth environments.

Hands-on experience navigating regulatory frameworks (e.g. PCI DSS, ISO 27001)

Deep knowledge of cloud security (AWS, GCP, and/or Azure), DevSecOps practices, and modern security tooling.

Executive presence and communication skills, with the ability to engage a Board of Directors and translate complex technical risk into strategic business terms.

Experience leading high-performing, geographically distributed teams in a global organization.

Strong vendor and contract management experience.

Prior CISO title or equivalent accountabilities at a technology company, financial institution, or regulated fintech.

Experience managing IT organizations at scale, including enterprise infrastructure, end-user technology, and IT operations.

Experience at a payments company, open banking platform, or financial services organization operating under multiple regulatory regimes.

Familiarity with open banking infrastructure, API security, and payment rail security considerations.

Advanced security certifications such as CISSP, CISM, or CISA.

Experience with security program build-out and audit readiness.

Multilingual capability or experience working across U.S., EU, and APAC operating environments is a plus.

Stop applying to ghosts.

OyaPilot surfaces only verified, real jobs, scores your fit, and tailors your application truthfully.