FISPAN

Lead, Information Security Strategy and Risk

FISPAN$100K — $120K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years in security architecture, cloud security, application security, or technical risk roles.
  • Experience in SaaS or cloud-native environments.
  • Strong understanding of security controls across IAM, cloud infrastructure, and vulnerability management.
  • Proven experience in vulnerability management and penetration testing programs.
  • Ability to assess risk and identify remediation strategies.
  • Effective in producing security recommendations and executive summaries.
  • Strong collaboration and teamwork skills across diverse functions.

Responsibilities

  • Lead security and risk reviews for key technology and operational changes.
  • Define security principles and control expectations across various environments.
  • Offer security-by-design guidance for new systems and integrations.
  • Manage the vulnerability management strategy across applications and infrastructure.
  • Oversee high-severity vulnerabilities and emerging security threats.
  • Align security strategy with business goals and regulatory obligations.
  • Collaborate with various teams to embed security considerations in key decisions.

Benefits

  • Extended health and dental benefits
  • Paid time off
  • Savings and retirement plan matching
  • Parenthood top-up
  • Support for career development and personal growth through mentorship programs.
Full Job Description
Role Summary

FISPAN is hiring a Lead, Information Security Strategy and Risk to help ensure security decisions, control designs, and technical changes are reviewed early and implemented with the right level of rigor. This role focuses on practical security architecture, design assurance, and risk reduction across product, engineering, infrastructure, and operational change.

You will partner closely with Engineering, Infrastructure, Product, GRC & Legal to review material technical decisions, assess security controls, and help teams move quickly without introducing avoidable risk. You will also lead key parts of FISPAN's vulnerability management and penetration testing program, translating technical findings into clear remediation priorities and durable security improvements.

Key Responsibilities:

Security Design & Risk Review
  • Lead security and risk reviews for material technology, infrastructure, integration, product, and operational changes.
  • Define security principles, control expectations, and risk guardrails across cloud, SaaS, data flows, identity, privileged access, and production environments.
  • Provide security-by-design guidance for new systems, internet-facing services, AI capabilities, shared platforms, and sensitive data integrations.
  • Support risk assessments, threat modeling, control reviews, and documented security decisions for significant initiatives.

Vulnerability Management & Security Testing
  • Own the vulnerability management strategy and governance process across applications, infrastructure, cloud services, and shared platforms.
  • Define risk-based severity, prioritization, remediation expectations, escalation, and exception handling.
  • Identify recurring vulnerability patterns and drive lasting control improvements and measurable risk reduction.
  • Provide oversight of high-severity vulnerabilities, external exposure, and emerging threats.

Security Strategy, Risk & Oversight
  • Develop and maintain security strategy and priorities aligned with business objectives, regulatory obligations, and bank partner expectations.
  • Identify material and emerging risks, recurring control weaknesses, and areas requiring broader security investment.
  • Translate technical risks into clear business impact, priorities, and recommendations for leadership.
  • Contribute to security governance, risk reporting, roadmap planning, and oversight of material exceptions and risk acceptances.
  • Partner with Product, Engineering, Compliance, Legal, and Operations to embed security and risk considerations into key decisions.

Requirements/Qualifications
  • 7+ years in security architecture, cloud security, application security, security assurance, or technical risk roles with strong technical collaboration.
  • Demonstrated experience reviewing architecture and implementation decisions in SaaS or cloud-native environments.
  • Strong understanding of security controls across IAM, cloud infrastructure, network security, logging/monitoring, vulnerability management, and production access.
  • Experience leading or materially contributing to vulnerability management and penetration testing programs.
  • Ability to assess material risk, identify control gaps, and drive practical remediation.
  • Strong written communication skills, including the ability to produce clear security recommendations, design feedback, and executive-facing summaries.
  • Strong collaboration and teamwork skills with the ability to work effectively across Engineering, Infrastructure, Product, Legal/GRC, and Security.


Nice to Have
  • Experience in FinTech, banking, embedded finance, or regulated SaaS environments.
  • Familiarity with AWS, Kubernetes/EKS, cloud networking, and production change patterns.
  • Experience reviewing shared infrastructure patterns, workflow automation platforms, and operational tooling.
  • Familiarity with privacy and regulatory expectations relevant to SaaS platforms serving financial institutions.


Compensation Package

FISPAN believes in an atmosphere and culture when innovation can flourish, collaboration and teamwork are valued and transparency is at the core of it all. We want our employees to see how the ideas they help generate today have an impact on how we do business tomorrow.With that, the hiring salary range for this position is $100,000-$120,000 annually; the base pay offered is based on comparable market data from companies of similar employee size, revenue and location. As part of our total rewards offering, permanent employees in this position may be eligible for our competitive semi-annual bonus program, subject to program eligibility requirements.

At FISPAN, we reward employees for achieving their objectives, going beyond the requirements of their job, demonstrating leadership, fostering innovation and advancing the organization as a whole. We value talented people of all backgrounds and characteristics that share our vision of being the number one platform for the business banking ecosystem.

Other components of our rewards offerings include support of career development, wellbeing, and personal growth.
  • Extended health and dental benefits
  • Paid time off
  • Savings and retirement plan matching
  • Parenthood top-up
  • Mentorship programs, and leadership series (to name a few)


Note: The incentive programs, benefits, and perks have certain eligibility requirements and may vary, only be partially or not at all available based on criteria such as location, employment status, etc. We'll be happy to clarify eligibility for interviewing candidates.

About FISPAN

FISPAN is a fintech company that provides a platform for banks to offer their customers access to third-party financial services. The company's platform enables banks to offer their customers a range of financial services, such as payments, lending, and insurance, without the need for the customer to leave the bank's website or mobile app. FISPAN's platform is designed to be easy to integrate with a bank's existing systems, and the company provides a range of tools and services to help banks manage their relationships with third-party service providers.
Learn more about FISPAN
Size
50 employees
Industry
Net Income
-$500,000
Founded
2016
5 Year Trend
+50%
Revenue
$1 million
NASDAQ

Similar Jobs

More Information Technology Jobs

Find similar Lead, Information Security Strategy and Risk jobs: