Specialist, Information Security

Bitpanda · Vienna, Vienna, Austria · Engineering

Posted 2026-10-09

Apply for this role →

Your mission

As an Information Security Specialist, you will own and mature significant parts of our governance, risk, and compliance program in a regulated fintech environment. You’ll be the go-to person for one or more GRC domains (e.g., ISMS and ISO 27001, audit & assurance, third-party risk, risk management, regulatory mapping), driving outcomes end-to-end: control design, operationalization with stakeholders, testing, metrics, and continuous improvement. You’ll operate with high autonomy, influence across teams, and help shape how we scale security governance as the company grows.

What you’ll do

GRC domain ownership & program maturity: Own one or more GRC domains (e.g., ISO 27001/ISMS, control testing, TPRM, risk governance, BCM), including yearly plans, cadence, and measurable outcomes; Build scalable processes and playbooks that reduce audit friction and improve control consistency across teams/entities.

Assurance, audits & regulatory readiness: Coordinate internal and external audits end-to-end (readiness planning, walkthroughs, evidence strategy, auditor Q&A, remediation verification); translate new regulatory and customer requirements into control impacts, implementation guidance, and tracked delivery plans; draft and quality-review formal materials: audit responses, management action plans, risk acceptances, and control descriptions.

Risk management & decision support: Facilitate and challenge risk assessments for systems, products, and material changes; ensure consistent scoring and clear treatment decisions; drive risk treatment plans with accountable owners; escalate when timelines or residual risk are not acceptable; improve risk reporting for leadership: themes, systemic issues, KRIs/KPIs, and clear prioritization based on business criticality.

Third-party risk management (if in your scope): Lead due diligence for critical vendors: define minimum security requirements, review evidence, and track remediation; Partner with Legal/Procurement to embed security requirements into contracts and ensure ongoing oversight (renewals, periodic reviews, SLA/security obligations)

Control testing & continuous improvement: Design and run a risk-based control testing plan (design and operating effectiveness), ensuring repeatability and traceability; identify recurring control failures and drive cross-functional improvements (e.g., clearer ownership, automation, better tooling, updated standards); introduce automation and dashboards where useful (e.g., evidence collection, control health reporting, risk and audit tracking).

Who you are

Typically 4-7 years of experience in GRC, audit/assurance, security risk management, compliance, or information security.

Strong working knowledge of ISO 27001 (or comparable frameworks) and ability to map requirements to controls, evidence, and real operational processes.

Experience leading audits/assessments or significant parts of them (planning through closure).

Security fundamentals across IAM, SDLC governance, incident management, vulnerability management, logging/monitoring, and third-party risk concepts.

Excellent written communication: can produce policy/control documentation and audit-ready narratives with minimal supervision.

Apply for this role →

← Back to all jobs