
Moneybox · London
About Moneybox At Moneybox, our mission is to give everyone the means to get more out of life. We're guided by our belief that wealth isn't about the money, it'...
About Moneybox
At Moneybox, our mission is to give everyone the means to get more out of life. We're guided by our belief that wealth isn't about the money, it's about the means to more - more freedom, opportunities, possibilities, and peace of mind. Moneybox is an award-winning wealth management platform, helping over one and a half million people build wealth throughout their lives, whether they’re saving and investing, buying their first home, or planning for retirement.
Job Brief
Moneybox is looking for a Head of Information Security to lead and mature our information security function.
Reporting to the Engineering Director, this role will own Moneybox’s Information Security Programme and be accountable for reducing security risk across our people, systems, products and third-party ecosystem as the business continues to scale.
This is a hands-on leadership role. The successful candidate will need to think strategically, set direction and influence senior stakeholders whilst also being close enough to the detail to get things done.
We are looking for someone who can build a small, high-performing and nimble security function, using technology, automation and AI to increase the breadth, quality and pace of what the team can achieve.
The role will suit an experienced information security leader who is pragmatic, commercially aware and focused on reducing meaningful risk, not creating unnecessary bureaucracy or replicating a big-bank security model.
CFTC-Regulated Business Unit (DCM) Location: Chicago, IL. Fully remote to start, transitioning to 3 days/week in office. ABOUT SMARKETS Smarkets is a prediction market exchange for sports and political trading that has handled over $50 billion in volume since 2010. We are upending the sports betting industry by growing a platform that offers the best value for traders, with not only the fairest prices but also the best technology, alongside a superior customer experience. We believe the foundation to our success is attracting the best people to our organisation and creating a high-performance environment where they can thrive. We are searching for an atypical candidate with a wealth of regulated business experience to support the development of our CFTC business. THE ROLE This is a senior security leadership role sitting within our CFTC-regulated business unit, responsible for the information security, cybersecurity, and operational resilience of our Designated Contract Market (DCM). You will design and enforce the policies and controls that protect the confidentiality, integrity, and availability of our critical systems and data, in alignment with Core Principle 20 (System Safeguards) under 17 CFR § 38.1050 et seq. This is a founding build: our licensing applications are in-flight and you will stand up the security programme through to go-live, then operate and mature it as the business scales. You will lead efforts to identify and mitigate cyber and physical threats, coordinate incident response, and ensure the DCM can continue operating under stress, working closely with engineering, risk, and compliance, including our UK-based teams, to embed security across the software development life cycle and infrastructure. You will work directly with the CEO and senior management, with the support of the Smarkets UK team behind you. ABOUT YOU * Senior security leader with 7+ years of senior-level information security experience, ideally within financial services, exchange infrastructure, or critical regulated systems. * Demonstrated leadership in implementing cybersecurity, compliance, and resilience programmes in high-risk environments. * Deep familiarity with CFTC expectations around system safeguards, including Core Principle 20 and 17 CFR § 38.1050 et seq. * Direct experience with security and risk assessments, incident response planning and execution, cybersecurity compliance audits (internal or regulatory), and disaster recovery and business continuity programmes. * Experience managing or working with geographically distributed engineering and infrastructure teams. * Strong understanding of security frameworks and secure software development practices. * Excellent communication and reporting skills, including for executive and regulatory audiences. RESPONSIBILITIES * Define and implement the DCM's information security vision, strategy, and programme, consistent with CFTC Core Principle 20 and industry-aligned best practice. * Lead risk identification, vulnerability management, and cyber threat mitigation across all DCM technology assets. * Ensure the design and enforcement of security controls across infrastructure, software development, vendor relationships, and end-user operations. * Own the incident response framework, including procedures for detection, containment, reporting, recovery, and root cause analysis. * Direct the business continuity and disaster recovery programmes, ensuring systems and teams can operate during disruption. * Prepare and maintain system safeguards documentation, audit logs, penetration tests, and other evidence for CFTC oversight and examinations. * Serve as the executive lead for cybersecurity audits, control testing, and CFTC technology compliance. * Collaborate with engineering, DevOps, product, and risk to ensure secure-by-design development and deployment, including across UK-based teams. * Regularly brief the CEO and senior management on security posture, threats, incidents, and risk levels. DESIRABLE ATTRIBUTES * Personal interest in sports, exchanges, or trading * Experience securing exchange, clearing, or trading infrastructure. * Relevant certifications such as CISSP, CISM, or equivalent. * Familiarity with event contracts, prediction markets, or similar novel futures products and their treatment under the CFTC framework. * Experience engaging directly with regulators or examiners on technology and system safeguards. OUR VALUES * Push to win * Make others better * Give a shit * Be a pro * Bring the energy Our values are at the heart of everything that we do. We believe these are the fundamentals to ensure we are delivering what's expected of us in the best way possible for ourselves and for those around us. COMPENSATION AND BENEFITS Base salary range: $130,000 to $200,000 USD per year. The actual offer within this range will depend on experience, qualifications, and other job-related factors. We have designed our benefits offering around Health, Wealth, Lifestyle and Development. From day one you will receive: * 25 days' annual leave, plus public holidays. * 401(k) plan: Smarkets matches 100% of employee contributions up to the first 6% of salary. Participation is voluntary, with automatic enrolment at a default contribution rate of 6% unless you select an alternative rate or choose to opt out. * Private medical insurance: a monthly reimbursement towards the private health insurance plan of your choice. * Performance bonus of up to 25% of base salary. * Equity via share options scheme. * Annual professional development budget of $1,000 for conferences, training, courses, books, and other learning opportunities. * Work From Anywhere: up to 20 days per year (pro-rated) to work remotely from locations around the world. ADDITIONAL INFORMATION * This role is offered subject to satisfactory background screening and, where applicable, CFTC fitness and eligibility requirements. * We use Ashby, our applicant tracking system, to manage applications, and AI-assisted tools may be used to support parts of our recruitment process. Applications are reviewed by our team, and hiring decisions are made by people rather than by automated tools.
Ready to combine a security-first mindset with strong technical understanding to shape the future of digital banking? As Head of Information Security at Nordiska, you will lead the security strategy, guide architecture decisions and ensure secure delivery across our organization - where banking meets tech. About Nordiska Nordiska is a bank that provides innovative financial products for both companies and consumers. Nordiska Embedded is a platform for embedded financial services, where we offer savings, lending, and payment services, either under our own brand or through partners. Nordiska also provides corporate and real estate financing, as well as sustainable savings with a government-backed deposit guarantee. What we offer Our code of conduct is the foundation for everything we do. We act with honesty and responsibility to build long-term trust among customers, partners, and employees. We believe that diversity drives innovation and encourages each employee to contribute their unique expertise and perspective. We are driven and dedicated to making a difference. Our employees receive a competitive benefits package. About the Role As we continue scaling with embedded finance partners on a European level, we’re looking for a Head of Information Security to take end-to-end ownership of information security and cybersecurity. At Nordiska, security is more than compliance; it’s a core enabler of growth and trust. As our embedded platform capabilities expand, so do partner expectations and the need for clear security ownership, strong execution and pragmatic risk management. In this role, you will own Nordiska’s security posture and drive initiatives that strengthen resilience, governance, and operational security. You will ensure compliance with evolving requirements and frameworks, while embedding security into product development and day-to-day operations in close collaboration with Risk, Tech and Legal. This is a hands-on, operational leader role with accountability for both strategy and implementation. You will also serve as Nordiska’s primary security representative in external engagements - working with regulators, auditors, and partners - leading compliance efforts and ensuring Nordiska not only meets, but consistently raises the bar on security, governance and risk management. What You’ll Do As Head of Information Security some of your key responsibilities are: Lead Nordiska’s information security and cybersecurity work end-to-end, aligned with business priorities, partner expectations and regulatory requirements. Lead and maintain the ICT security framework, including governance, implementation, and cross-functional coordination, while leading third-party security risk management through due diligence, contractual requirements, and ongoing monitoring of vendors and service providers. Measure, report, and continuously strengthen Nordiska’s security posture through risk-based prioritization, clear metrics, and structured remediation, while owning incident management and regulatory reporting with well-defined procedures, timely escalation, and compliant communication with relevant authorities. Establish and maintain security governance and controls, embedding regulatory and industry requirements into policies, processes and steering documentation. Lead security assurance and stakeholder management, including ISO work, internal/external/regulatory audits and assessments and advising management and the Board on risks and mitigations. We’re Looking for Someone who has 7+ years of experience in information security/cybersecurity, with at least 5 years in leading roles in technology or infrastructure-intensive environments. Extensive experience in information security, cyber risk management and regulatory oversight, ideally within fintech, banking, or other highly regulated environments. A strong understanding of modern cybersecurity principles and technical security concepts. Hands-on experience driving audits, assessments and security programs, including regulatory reviews, risk assessments and remediation follow-up. Solid knowledge of key regulatory frameworks and standards such as DORA, ISO 27001, and GDPR, and how to translate requirements into practical controls. Excellent communication skills in both English and Swedish, with experience presenting to senior stakeholders and non-technical audiences. Experience from a tech-driven organization (preferred), where security enables delivery, scale and partner trust. Your Professional Profile Proactive and accountable - you take ownership beyond “tech security” and ensure security and compliance are embedded across the business. Structured and execution-oriented - you thrive in building, running and continuously improving compliance processes, not just overseeing them at a distance. Independent and self-sufficient - you can drive progress without formal line management, leading through influence in cross-functional initiatives. Collaborative and influential – you create alignment across departments and communicate risks, trade-offs, and priorities effectively across all levels of the organization. Application & Process If you’re looking to join a growth-driven environment that pairs innovation with profitability and reliability, welcome to Nordiska. We look forward to receiving your application. We review and interview continuously, with background checks as part of the final stage of our process. For questions about the role and or more information, you are warmly welcome to contact Ida Garamvölgyi, ida.garamvolgyi@nordiska.com or +46704 385 325.
WHO WE ARE At Trustly, we're building a smarter, faster, and more secure financial future by revolutionizing the world of payments. As a global leader in Open Banking Payments, we are establishing Pay by Bank as the new standard at checkout, providing unparalleled freedom, speed, and ease to millions of consumers and merchants worldwide. Our Ambition: To build the world’s most disruptive payment network and redefine what the payment experience should feel like. Trustly is a global team of innovators, collaborators, and doers. If you are driven by a strong sense of purpose and thrive in a dynamic, entrepreneurial, and high-growth environment, join us and be part of a team that’s transforming the way the world pays. About the team The Security & Information Technology organization is the backbone of Trustly’s commitment to global financial trust. We are responsible for architecting a resilient security posture and a seamless, AI-native workplace that enables our global workforce to innovate at speed. Our mission is to protect millions of transactions while ensuring that our internal technology ecosystem is as fast, secure, and disruptive as the payment solutions we build for our merchants and customers. About the role Reporting directly to the Global CTO, the Chief Information Security Officer (CISO) & Head of Information Technology will serve as Trustly’s most senior security and internal technology operations executive. This is a dual-scope role: you will own the full information security program - strategy, architecture, risk, and response, while also leading the IT organization that underpins Trustly’s global workforce, including driving our AI productivity journey. You will be a key voice to the C-suite and a trusted advisor to the Board on all matters related to security posture, cyber risk, and technology resilience. You will operate at the intersection of a high-growth, globally distributed fintech and a fast-evolving regulatory and threat landscape, making decisions that have direct implications for our customers, our partners, and our business.