CareerPlanGet AI match score →

Group Head of Security

Limassol, Cyprus💼 Full-time🗓 2026-07-07 → 2026-07-28

Core

Lead and develop the cybersecurity function as an independent structure reporting to the CEO, building security into the delivery pipeline while preparing the organization for regulatory compliance in financial services.

Role type

Group Head of Security (Cybersecurity)

Builds

Security frameworks, governance structures, secure SDLC practices, and automated security controls for a global trading provider.

Domain

Financial Services / Cybersecurity / Regulated Finance

Deliverable

production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work

Required skills

Offensive security expertise, hands-on engineering background, security framework implementation, risk management, security metrics reporting, network segmentation, secure SDLC integration, penetration testing, vulnerability assessment, DevSecOps practices, security automation, regulatory audit experience, Python programming, Bash/Zsh/PowerShell scripting.

Preferred skills

Trading platform experience, payment systems knowledge, AI/ML/LLM security considerations, familiarity with MT5 and trading APIs.

Technologies

Kali Linux, Metasploit, Burp Suite, Nmap, Wireshark, SQLMap, CI/CD pipelines, SAST, DAST, SCA, container scanning tools.

Responsibilities

Build security frameworks based on ISO 27001, NIST CSF, CIS Controls, and SOC 2; Implement information security governance, policies, and risk management processes; Establish and maintain security metrics, KPIs, and reporting for executive leadership; Design and implement network segmentation and secure perimeter architecture; Collaborate with development teams to establish secure SDLC practices; Conduct penetration testing and API security assessments; Provide hands-on remediation guidance to developers.

Seniority

Group Head, strategic leadership with hands-on technical execution.

Rewrite
## About the Company CFI Financial Group is an award-winning trading provider, possessing more than 25 years of experience with multiple offices around the world including London, Larnaca, Beirut, Amman, Dubai, Kuwait, Port Louis, and others. Are you looking to pursue a career in finance? Do you want to work with a dynamic and growing team in the exciting world of online trading and investing? If you answered yes, then we have some amazing opportunities for you! ## About the Role We're seeking a Head of Security to lead and develop our cybersecurity function as an independent structure reporting directly to the CEO. This role requires a unique blend of offensive security expertise, hands-on engineering background, and the ability to implement pragmatic security controls that guard rather than block business velocity. You'll work closely with the CTO and technology teams to build security into our delivery pipeline while preparing the organization for regulatory compliance in financial services. ## Key Responsibilities - Build security frameworks based on ISO 27001, NIST CSF, CIS Controls, and SOC 2 - Ensure compliance with DORA, EBA Guidelines, ISO 27001 - Implement information security governance structure, policies, and risk management processes - Establish and maintain security metrics, KPIs, and reporting for executive leadership - Secure Perimeter & Infrastructure Protection - Design and implement network segmentation and secure perimeter architecture - Collaborate with development teams to establish secure SDLC practices - Integrate security into CI/CD pipelines with automated quality gates (SAST, DAST, SCA, container scanning, aplication security tools) - Conduct penetration testing and API security assesments using Kali Linux, Metasploit, Burp Suite, and other offensive security tools - Provide hands-on remediation guidance that developers can implement ## Requirements ### Required Certifications (minimum 2) - Offensive Security (OSCP, OSCE, GPEN, or CEH) - Security Management (CISSP or CISM) - Cloud Security (CCSP, AWS Security Specialty, or Azure Security Engineer) - Audit (CISA) ### Experience - 8+ years in information security roles - 3+ years in security leadership positions ### Mandatory - Experience in regulated financial services (banking, brokerage, payments, fintech) - Hands-on penetration testing and vulnerability assessment experience - Development or DevOps background with practical coding experience - Successfully implemented DevSecOps practices and security automation - Experience with regulatory audits and compliance assessments ### Required Technical Skills - Offensive security tools: Kali Linux, Metasploit, Burp Suite, Nmap, Wireshark, SQLMap - Programming: Proficient in Python (prefferable) or atl least one other language - Scripting: Mandatory proficiency in Bash, Zsh, and PowerShell ### Mindset & Soft Skills - Pragmatic security mindset: Balance security with business enablement - Collaborative leadership: Build trust with engineering teams - Strong communication: Translate security risks into business impact ## Nice to Have - Experience with trading platforms, payment systems, or financial infrastructure - Knowledge of AI/ML/LLM security considerations - Familiarity with MT5, trading APIs, payment processing systems ## Why join CFI? - We're a fast-growing, multinational company - Competitive salaries and benefits - Work and learn with industry professions - Supportive and collaborative environment - Unlimited opportunities for growth and development
Sourced via cypruswork · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.
Apply on CyprusWork ↗