- Experience
- 5+ yrs
- Salary
- —
- Openings
- 1
- Posted
- 1 week ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About Hawk
Hawk is a premier provider specializing in AI-driven anti-money laundering and fraud detection technologies. Our solutions integrate traditional rule systems with interpretable AI to enhance AML compliance and fraud prevention for banks and payment providers worldwide. Our mission is to detect more criminal activity while minimizing false positives, contributing significantly to the global efforts against money laundering, fraud, and terrorism financing. At Hawk, we nurture a supportive and passionate culture that fosters professional growth and meaningful impact.
Role Overview
We are looking for a knowledgeable and technically proficient Senior Information Security Officer to join our Information Security team. This role is pivotal in maintaining customer trust, aiding sales and pre-sales efforts, and ensuring compliance with security frameworks like ISO 27001. You will serve as a crucial liaison among customers, auditors, internal teams, and security tools, managing security inquiries and requests for proposals (RFPs), enhancing our Information Security Management System (ISMS), and improving endpoint and access security to protect Hawk's platform, data, and operations. Proficiency in German is essential due to frequent interactions with German-speaking clients.
Key Responsibilities
- Manage security-related questionnaires, RFPs, and due-diligence requests in cooperation with Sales and Pre-Sales teams.
- Engage in customer discussions to effectively communicate Hawk’s security posture and address technical, compliance, and infrastructure inquiries.
- Present Hawk’s security capabilities confidently to regulated financial institutions.
- Support the upkeep and enhancement of Hawk’s ISMS, ensuring strict adherence to ISO 27001 controls and related processes.
- Assist in internal audits, evidence collection, and risk assessments essential to certification readiness.
- Monitor and improve the security stance of corporate tools, infrastructure, and third-party integrations.
- Support assessments and due diligence procedures for vendor security tools.
- Collaborate closely with Engineering, IT, and Information Security teams to strengthen platform and enterprise-wide security foundations.
- Work cross-functionally with Information Security, IT, Engineering, Sales, Customer Success, and Procurement departments.
- Translate complex technical and security concepts into clear terms suitable for both technical and non-technical stakeholders.
- Contribute to internal security awareness initiatives, documentation, and operational workflows.
Candidate Profile
- Minimum of five years’ practical experience in Information Security, IT Security, or related Governance, Risk, and Compliance roles in a B2B technology or SaaS context.
- Demonstrated expertise in operating and enhancing an ISMS aligned with ISO 27001, including policy formulation, risk evaluations, conducting internal audits, and managing certification processes.
- Familiarity with additional regulatory and compliance standards such as SOC 2, DORA, and NIS 2.
- Strong grasp of IT security fundamentals encompassing authentication protocols, endpoint protection, encryption, and basic networking.
- Technical competence across various operating systems including macOS, Windows, and Linux.
- Experience liaising with external auditors, certification agencies, and regulatory bodies.
- Relevant certifications are highly valued, including ISO 27001 Lead Implementer/Auditor, CISSP, CISM, CRISC, or CompTIA Security+.
- Fluent communication skills in both German and English to facilitate interaction with customers, auditors, and regulators.
- Excellent ability to clarify complex security and compliance matters for diverse audiences including engineers, clients, auditors, and senior management.
- Strong documentation skills, emphasizing precision, consistency, and audit preparedness.
- Knowledge or experience with identity and access management tools (e.g., JumpCloud, Okta), mobile device management systems, and enterprise security platforms is a plus.
- Exposure to vendor security evaluations, third-party risk management, and SaaS security tools enhance candidacy.
- Experience supporting security questionnaires, RFPs, and due diligence communications with regulated financial organizations is advantageous.
- Understanding of data protection laws such as GDPR in relation to security practices.
- A proactive, methodical, and cooperative approach, capable of managing multiple priorities efficiently in a dynamic setting.