Irving
Job DescriptionSalary: Join CellPoint Digital: Shape the Future of Payments with Us! Were the innovators behind the worlds leading Payment Orchestration Platform, helping global brands like airlines and travel leaders turn payments into profit. At CellPoint Digital, we believe payments should be a strategic advantage - and security is at the heart of that mission. Were looking for a Security Lead to define and drive our global security strategy, safeguard our payment infrastructure, and lead a world-class security culture across engineering, operations, and compliance. Based in Dallas and working with teams worldwide, youll protect our platform, people, and clients through excellence in governance, data protection, and technical security. If youre a hands-on, visionary security leader with deep fintech or payments experience and the ambition to set new standards in trust and resilience, wed love to meet you. Join us as a Security Lead on our mission to turn payments into possibilities! Key Responsibilities & Skills You will have Fine-tuned 1. Security Strategy & Governance • Define and execute CellPoint Digitals global information security strategy, ensuring alignment with business objectives, risk appetite, and regulatory obligations., • Oversee the Information Security Management System (ISMS), ensuring continual improvement and certification under ISO 27001/27701., • Establish and maintain group-wide security policies, standards, and operational procedures across all legal entities (UK, Denmark, Bulgaria, India, Philippines, and US)., • Report regularly to the Executive Team and Board on security posture, risks, and mitigation actions., • Take part in Business Risk and Compliance Committee meetings ("BRCC") and coordinate with Compliance, Legal, and Infrastructure leadership. 2. Regulatory Compliance & Certification • Maintain and evolve compliance with PCI DSS v4.0, SOC 2 Type 2, ISO 27001, and GDPR., • Act as liaison with QSAs, auditors, acquirers, and enterprise clients during audits, RFPs, and security assessments., • Partner with Legal and Compliance to ensure secure handling of payment data and customer information across global jurisdictions., • Oversee third-party risk management and due diligence of vendors, processors, and cloud providers. 3. Operational & Technical Security • Lead and develop the Security Operations Centre (SOC), ensuring continuous monitoring, detection, and response to incidents., • Oversee vulnerability management, penetration testing, and incident response processes., • Implement best-practice controls for network, application, and cloud security, including encryption, IAM, and zero-trust principles., • Integrate DevSecOps practices across the OSO platform and CI/CD pipelines to ensure security-by-design., • Manage key management, tokenisation, and secure transaction flow architectures critical to PCI compliance. 4. Data Protection & Privacy • Ensure technical and organisational measures align with GDPR and other applicable data protection laws., • Support the DPO and Legal team with privacy impact assessments (PIAs), breach management, and data-subject requests., • Oversee DLP (Data Loss Prevention) and access control frameworks for customer, partner, and employee data. 5. Leadership & Culture • Build, mentor, and lead a high-performing global security team covering governance, compliance, and technical domains., • Promote a strong security-first culture across engineering, product, and operations teams through awareness and training., • Serve as the companys key spokesperson and trusted advisor on all information security matters for clients, investors, and partners. Key Skills & Experience: • 10+ years of experience in information security, with at least 5 years in a role within a fintech, payments, or financial services environment., • Proven success managing security programs compliant with PCI DSS v4.0, ISO 27001, SOC 2, and GDPR., • Strong knowledge of payment orchestration, card data environments, tokenisation, and transaction-flow architectures., • Hands-on experience securing cloud-native (AWS/Azure) microservice architectures., • Strong background in incident response, vulnerability management, and DevSecOps integration., • Excellent stakeholder management skills and experience engaging at C-suite and board level., • Professional certifications such as CISSP, CISM, CISA, PCI ISA/QSA, or ISO 27001 Lead Implementer/Auditor preferred. Performance Metrics: • PCI DSS, ISO 27001, and SOC 2 audit outcomes and recertifications., • Reduction in vulnerabilities and mean time to detect/respond (MTTD/MTTR) to incidents., • Zero non-conformities in client or regulator security reviews., • Positive trend in company-wide security awareness metrics., • Timely and accurate reporting to management and regulators. What's in it for you: • We offer you the opportunity to be an innovator, challenge the status quo, and redefine the payments category, • Competitive salary in a fast-growing start-up, • Rewards & Recognition system, • Opportunity for personal and professional growth in a dynamic industry, • Work from anywhere in the world; we're a fully distributed company, and we provide the tools, culture, and support to make your work setup work for you, • Joining a scaling company that is growing and an opportunity to have great impact, • Occasional travel to Europe (UK, Copenhagen, Bulgaria) and India. What makes CellPoint Digital a leader in the payment landscape isnt just our technology - its our people and how we work together. Weve built a global community where diverse talents and perspectives unite to create innovative solutions.When you join us, you become part of something bigger: a collaborative culture that crosses borders and disciplines, bringing out the best in every team member to deliver breakthrough results for our clients and partners. Together, we are transforming the payments industry - challenging, supporting, and inspiring one another in the process.