Fiserv

Head of Information Security

Fiserv • $127K — $204K *
US-AnywhereRemote in Colorado, US
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of experience in information security or a related field
  • Proven expertise in risk management and compliance standards
  • Hands-on experience with vendor governance and third-party security management
  • Strong grasp of security controls and frameworks like NIST and PCI DSS
  • Demonstrated leadership in cyber incident response and operations

Responsibilities

  • Develop and implement MPG's enterprise information security strategy and roadmap
  • Establish governance across various technological and cloud environments
  • Define security roles and communicate risks to executive leadership
  • Provide oversight of security operations including SIEM and vulnerability management
  • Lead MPG's incident response programs and tabletop exercises

Benefits

  • Remote work flexibility
  • Working with a leading company in the technology and information security sector
  • Opportunity to enhance personal and professional development through innovative projects
  • Engagement in cutting-edge technologies like AI and cloud services
  • Potential for a mix of cash bonuses and equity awards as incentives
Full Job Description
Job Title
Head of Information Security

Head of Information Security

Company: MoneyPass Group (MPG)
Function: Technology / Information Security
Reports To: Chief Information Officer
Location: Remote
Level: Director / VP, depending on candidate experience

Position Summary

MoneyPass Group is seeking a hands-on Head of Information Security to establish and lead the company's information security, cyber risk, and security governance capabilities as MPG builds its independent technology environment.

This leader will be responsible for defining MPG's security strategy, establishing an effective security control environment, managing cyber risk, and ensuring that security responsibilities are effectively executed across MPG and its technology partners.

MPG operates a highly outsourced technology model in which managed service providers and other strategic partners deliver significant portions of infrastructure, application development, ATM technology, cloud, and security services. As a result, this role requires a leader who can effectively govern third-party security services while maintaining clear accountability for MPG's security posture.

The successful candidate will combine security leadership, technical depth, risk management, compliance expertise, and strong vendor governance with the willingness to personally drive execution in a lean organization.

Key Responsibilities

Security Strategy & Governance

Develop and maintain MPG's enterprise information security strategy, roadmap, policies, standards, and control framework aligned with the company's business objectives and risk tolerance.

Establish security governance across MPG's corporate technology, payment and ATM environments, cloud services, software platforms, data platforms, and third-party technology ecosystem.

Define security roles and responsibilities across MPG, its MSP/MSSP providers, software partners, and other critical vendors.

Establish and maintain the company's cyber risk register and regularly communicate material risks, remediation priorities, and security posture to the CIO and executive leadership.

Develop meaningful security metrics and executive reporting, including risk trends, vulnerabilities, incidents, control effectiveness, third-party risk, and remediation progress.

Security Operations & Cyber Defense

Provide oversight of MPG's security operations capabilities, including:
  • Security monitoring and SIEM
  • Managed detection and response (MDR)
  • Endpoint detection and response (EDR)
  • Vulnerability management
  • Threat intelligence
  • Identity monitoring
  • Cloud security monitoring
  • Email and collaboration security
  • Security incident detection and response

Manage and hold MPG's MSSP and other security providers accountable to defined SLAs, security requirements, escalation procedures, and performance metrics.

Ensure vulnerabilities are appropriately identified, prioritized, assigned, remediated, and tracked through closure.

Lead MPG's cyber incident response program, including incident response plans, escalation procedures, tabletop exercises, forensic coordination, regulatory/customer notification support, and post-incident reviews.

Serve as MPG's primary security leader during significant cybersecurity incidents.

Identity & Access Management

Establish and oversee MPG's identity and access management program, including:
  • Single sign-on and multifactor authentication
  • Privileged access management
  • Joiner/mover/leaver processes
  • Role-based access
  • Periodic access certification
  • Service and privileged account governance
  • Third-party access
  • Segregation of duties

Partner with IT and business leaders to implement appropriate least-privilege and Zero Trust principles across MPG's environment.

Security Architecture & Engineering

Establish security architecture principles and requirements for MPG's technology environment.

Review material technology implementations and architecture changes for security risks and required controls.

Partner with infrastructure, development, data, and MSP teams to incorporate security into cloud architecture, networks, endpoints, applications, APIs, integrations, and data platforms.

Establish appropriate security practices throughout the software development lifecycle, including code scanning, dependency management, secrets management, application security testing, and remediation processes.

Ensure new technologies-including AI and generative AI solutions-are evaluated for security, privacy, data protection, access, and third-party risks before production use.

Risk, Compliance & Audit

Own the technology security control environment supporting MPG's compliance and customer assurance requirements.

Partner with Legal, Finance, Internal Audit, Compliance, and external auditors to establish and maintain readiness for applicable frameworks and requirements, including:
  • SOC 1
  • SOC 2
  • PCI DSS, where applicable
  • NIST Cybersecurity Framework
  • CIS Controls
  • Applicable customer, contractual, regulatory, and privacy requirements

Translate compliance requirements into sustainable operational controls rather than point-in-time audit activities.

Maintain appropriate evidence demonstrating control operation and effectiveness.

Coordinate security-related audit activities and drive remediation of findings through closure.

Third-Party & Supply Chain Security

Establish MPG's third-party technology and cybersecurity risk management program.

Define minimum security requirements for MSPs, MSSPs, SaaS providers, software development partners, data providers, and other critical vendors.

Perform or oversee security assessments of critical vendors and review relevant SOC reports, penetration testing results, certifications, control exceptions, and remediation plans.

Maintain clear MPG-versus-provider responsibility matrices for critical security controls.

Ensure contracts contain appropriate cybersecurity, incident notification, data protection, audit, business continuity, and security-control requirements.

Actively challenge providers rather than assuming outsourced technology means outsourced accountability.

Data Protection

Partner with MPG's data and technology teams to establish security controls governing sensitive corporate, customer, transaction, payment, and endpoint data.

Establish standards for:
  • Data classification
  • Encryption
  • Key management
  • Data access
  • Data retention and destruction
  • Data loss prevention
  • Secure data transfer
  • Sensitive-data discovery and monitoring

Work with the business to reduce unnecessary retention and exposure of sensitive information.

Data Privacy & AI Governance

Partner with Legal, Compliance, and business leaders to operationalize MPG's data privacy obligations, translating them into sustainable technical and operational controls, including applicable requirements under:
  • Gramm-Leach-Bliley Act (GLBA), including the FTC Safeguards Rule and Privacy Rule requirements for protecting customer financial information
  • California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), and other applicable U.S. state privacy laws
  • EU and UK General Data Protection Regulation (GDPR), where MPG processes personal data of individuals in those jurisdictions

Maintain MPG's written information security program consistent with GLBA Safeguards Rule requirements, including periodic risk assessments, service provider oversight, and regular reporting to executive leadership and the Board.

Support data inventories, data mapping, and records of processing, and conduct privacy and data protection impact assessments for new systems, products, vendors, and material changes.

Embed privacy-by-design principles-including data minimization, purpose limitation, and retention limits-into architecture reviews and the software development lifecycle.

Enable timely and secure fulfillment of consumer and data subject rights requests, including access, deletion, correction, and opt-out, with appropriate identity verification.

Ensure incident response plans address privacy breach notification obligations and timelines, including GDPR supervisory authority notification, GLBA Safeguards Rule notification, and state breach-notification laws.

Ensure vendor contracts include appropriate data processing terms, such as GDPR data processing agreements and cross-border transfer mechanisms, CCPA service-provider provisions, and GLBA safeguarding requirements.

Partner with Legal, Compliance, Data, and business leaders to establish and lead MPG's AI governance program, including:
  • AI acceptable-use policies and employee guidance
  • An inventory of AI use cases, models, and AI-enabled vendor products
  • Risk-tiering and approval processes for internal and third-party AI solutions
  • Controls governing the use of customer, personal, and confidential data in AI prompts, training, and outputs


This role will perform services for The MoneyPass Group, a company that is jointly owned by Fiserv and Bridgeport Partners. Your employment initially will be with Fiserv , and Fiserv will lease your services to The MoneyPass Group through December 31, 2026. As of January 1, 2027, employment with Fiserv will end and employment will transfer to The MoneyPass Group.

Salary Range
$127,500.00 - $204,000.00

These pay ranges apply to employees in Colorado, Hawaii, Illinois, Nevada, Rhode Island, Vermont and Washington. Pay ranges for employees in other states may differ.

For incentive eligible associates, the successful candidate is eligible for an annual incentive opportunity which may be delivered as a mix of cash bonus and equity awards in the Company's sole discretion.

It is unlawful to discriminate against a prospective employee due to the individual's status as a veteran.

Thank you for considering employment with Fiserv. Please:

  • Apply using your legal name
  • Complete the step-by-step profile and attach your resume (either is acceptable, both are preferable).

About Fiserv

CashEdge(R) provides infrastructure that global financial institutions rely on to extend their online channels and enhance customer profitability. CashEdge delivers secure Online Money Movement and Advanced Account Aggregation platforms that power specialized retail banking and advisor applications. These proven solutions enable CashEdge's clients to create compelling online offerings that attract customers, generate revenues, and reduce costs. CashEdge serves top-tier financial institutions around the world. Clients and partners include Vanguard, RBC Financial Group, CIBC, Yahoo! Finance, Digital Insight, First Data, TD Canada Trust, NYCE, Laurentian Bank, Financial Fusion and Corillian. CashEdge has offices in New York and Silicon Valley.

Fiserv Careers

Join the Fiserv team today and be part of a dynamic company known for innovation, leadership, and a commitment to the professional growth of its employees. At Fiserv, we offer more than just job opportunities; we provide a platform where skills are honed, leadership is cultivated, and career aspirations are achieved. Work You’ll Do At Fiserv, we are constantly on the lookout for talented individuals eager to thrive in a culture that fosters growth and diversity. Our team is composed of professionals who lead the way in financial services technology. By joining us, you will collaborate with some of the brightest minds in the industry, working together to solve complex challenges and deliver innovative solutions that impact millions of people every day. Explore Our Job Opportunities Whether you're seeking an entry-level position or a more senior role, Fiserv offers a range of career paths in areas such as software development, project management, financial analysis, and client services. Our hiring process is designed to identify and attract individuals who are not only technically proficient but who also embody our values of integrity and responsibility. Internship Programs Kickstart your career with a Fiserv internship. Our internships provide invaluable workplace experience and networking opportunities that often lead to full-time employment. As an intern, you’ll gain hands-on experience while working on meaningful projects that directly contribute to the company’s goals. Benefits and Culture Fiserv is committed to the well-being and continuous development of our employees. We offer competitive benefits including health, dental, and vision insurance, as well as opportunities for professional development through leadership training and diversity programs. Our culture is one of inclusion, where every team member is valued and has the opportunity to contribute to our success. Career Growth and Development We believe in nurturing the potential of our employees through career development initiatives and continuous learning opportunities. At Fiserv, you will find a supportive environment where you can grow your career through on-the-job experiences, mentoring, and formal training. Stay Connected Join Our Team Search open positions that match your skills and interests. We look for passionate, curious, creative, and solution-driven team players. Start your journey with Fiserv today and help shape the future of financial services. Keep Up to Date Stay ahead with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here. Job Alert Emails Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await at Fiserv. Explore, innovate, and grow with Fiserv. Let your career journey begin here, where you can make a real difference in the world of finance.
Learn more about Fiserv
Size
44,000 employees
Market Cap
$63.4 billion
Industry
Net Income
$958 million
Founded
1984
5 Year Trend
+24.1%
Revenue
$14.8 billion
NASDAQ

Similar Jobs

More Jobs at Fiserv

More Information Technology Jobs

Find similar Head of Information Security jobs: