InfoSec Manager (GRC)
Malta or EU remote | Reports to CTO, leads one pentester to start. Build the framework, then run the controls: ISO 27001, GDPR, PCI DSS, SIEM, EDR, incident response.
We usually respond within a week
Location: Based in Malta - Employee or Remote from Europe
Reporting to CTO
Direct Reports: Penetration Tester
Your Impact
Governance, Risk & Compliance
Build and maintain the security framework, aligned to ISO 27001.
Manage security risk across the group and report clearly to leadership.
Keep us compliant with the regulations that matter - GDPR, PCI DSS, and similar.
Write practical security policies people will actually follow.
Lead audits, certifications, and security questionnaires from partners and regulators.
Run vendor risk checks and deliver security awareness training.
Create training materials for our staff.
IT Security
Own identity and access - SSO, MFA, and access controls.
Harden endpoints and manage device security (EDR, MDM).
Set and check network security controls with IT (firewalls, VPN, segmentation).
Run vulnerability and patch management, and drive fixes to closure.
Manage email security, phishing defense, and SaaS security.
Operate security tooling and monitoring (SIEM, DLP).
Lead incident response and investigations.
Coordinate penetration tests and manage remediation.
Leadership & Process
Lead and mentor the security team, starting with one penetration tester.
Grow the team as the function scales - hiring and shaping roles as needs evolve.
Partner closely with IT - security sets the requirements, IT helps implement, and you drive them together without stepping on each other.
What Makes You a Fit
5+ years in information security, across both GRC and hands-on IT security.
Background in iGaming, fintech, or another regulated industry.
Solid grounding in IT security: identity, endpoints, networking, and security tooling.
Experience with risk assessments, audits, and incident response.
Able to explain security risk clearly to both technical and business audiences.
Comfortable working independently in a fast-paced environment.
Leadership experience - managing or mentoring at least one team member, with the appetite to grow a team.
Able to explain security risk clearly to both technical and business audiences.
Experience with a recognized framework (ISO 27001, SOC 2, NIST, or similar).
Good knowledge of GDPR and at least one of PCI DSS, MGA, or DORA.
Nice to have (not a must): production systems and AWS
What's in it for you?
✨ Be with a team that builds the momentum that moves the industry.
A fast-paced environment driven by innovation, curiosity, and a shared love for technology. A people-first culture that rewards ambition, integrity, and genuine collaboration.
Comprehensive benefits package for Malta-based employees, including:
Private health insurance, wellness allowance, and communication allowance.
Healthy lunch on Wednesdays and a varied calendar of social events throughout the year..
Employee discounts in restaurants and businesses.
Extended second-parent leave policy.
Private parking space.
This opportunity is powered by Bet On Talent - Applying through us is your ultimate VIP pass 💎
We work deeply within our partner's ecosystem, which means we skip the generic applicant piles and fast-track your profile straight to the team - Hit apply now and let's make your next big career move happen!
- Department
- Information Security
- Locations
- Malta, Remote
- Remote status
- Hybrid
- Employment type
- Full-time