3d ago
New

Chief Information Security Officer (CISO)

GermanyGermany·Munichfull-timeexecutive
OtherInformation Security Officer
1 views0 saves0 applied

Quick Summary

Requirements Summary

Establish and enforce secure coding baselines directly within engineering workflows. Ensure automated vulnerability scanning, SBOM tracking,

Technical Tools
OtherInformation Security Officer

Hawk is the leading provider of AI-supported anti-money laundering and fraud detection technology. Banks and payment providers globally are using Hawk’s powerful combination of traditional rules and explainable AI to improve the effectiveness of their AML compliance and fraud prevention by identifying more crime while maximizing efficiency by reducing false positives. With our solution, we are playing a vital role in the global fight against Money Laundering, Fraud, or the financing of terrorism. We offer a culture of mutual trust, support and passion – while providing individuals with opportunities to grow professionally and make a difference in the world. 

Hawk builds AI-powered financial crime detection (AML, transaction monitoring, and fraud prevention) for global tier-1 banks, payment processors, and high-growth fintechs. Because our platform analyzes real-time payment streams and sensitive financial data, security is not an administrative support function—it is our primary product promise.

We are looking for a technically grounded, hands-on CISO to own our global security posture end-to-end. This is a true player-coach leadership role. You will lead a dedicated team of four domain specialists while staying close enough to the technology to review cloud architecture, triage high-severity vulnerabilities, command critical incident responses first-hand, and debate technical security controls peer-to-peer with customer bank CISOs.

Requirements

~1 min read
  1. Commercial Velocity: Enterprise bank security assessments clear with zero high-severity blockers, accelerating enterprise contract closures.

  2. Proactive Risk Registry: The company risk registry is fully operationalized with executive buy-in, systematically driving down enterprise risk while supporting business expansion.

  3. Regulatory & Audit Record: DORA compliance program is operational; ISO 27001 and SOC 2 renew cleanly across all operating regions.

  4. Engineering & AI Hardening: Software supply chain security controls, secure coding standards, and AI harness guard rails are fully integrated into engineering CI/CD workflows.

  5. Resilient Team Operations: The four-person security team executes with high autonomy, defined KPIs, and high cross-functional trust across the company.

  • Practitioner Foundations: Proven background as a hands-on security practitioner (e.g., former security engineer, AppSec specialist, cloud security architect, or technical penetration tester) who has advanced into security leadership.

  • Player-Coach Track Record: Demonstrated ability to manage and grow a small team of domain experts while personally reviewing technical configurations, auditing cloud policies, or investigating an alert.

  • Commercial & CISO-to-CISO Fluency: Experience debating architecture, supply chain controls, and threat postures directly with enterprise bank CISOs and security evaluation boards to clear deal roadblocks.

  • AI & Supply Chain Defense Fluency: Ability to quickly understand our AI architecture, implement hands-on controls to harden AI tooling (including AI harnesses and sandboxing), and protect CI/CD pipelines against software supply chain risks.

  • Risk Registry Execution: Demonstrated ability to maintain a living risk registry, articulate risk trade-offs to non-technical executives, and rally engineering and commercial buy-in to remediate risks.

  • FinTech & Regulated SaaS Background: Multi-year leadership experience in a B2B SaaS, FinTech, or banking platform handling sensitive financial or transactional data under regulatory oversight (e.g., DORA, ISO 27001, SOC 2, GDPR).

  • Technical Breadth: Strong practical understanding of AWS and GCP security primitives, container and Kubernetes security, modern IAM/SSO, API gateways, and EDR/XDR toolchains.

Nice to Have

~1 min read
  • Industry certifications reflecting technical or managerial competence (e.g., CISSP, CISM, CCSP, OSCP).

  • Direct experience securing real-time event-streaming architectures.

  • German language proficiency (conversational or fluent) is a strong advantage.

 

Location & Eligibility

Where is the job
Munich, Germany
On-site at the office
Who can apply
DE

Listing Details

Posted
October 6, 2026
First seen
October 6, 2026
Last seen
October 9, 2026

Posting Health

Days active
2
Repost count
0
Trust Level
57%
Scored at
October 9, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Chief Information Security Officer (CISO)