About this role
Head of Information Security
Location: Remote, Colorado
Job ID: R-10403660
Category: Technology
Remote
Posting Start Date: 27-September-2026
Posting End Date: 30-September-2026
Calling all innovators – find your future at Fiserv.
We’re Fiserv, a global leader in Fintech and payments, and we move money and information in a way that moves the world. We connect financial institutions, corporations, merchants, and consumers to one another millions of times a day – quickly, reliably, and securely. Any time you swipe your credit card, pay through a mobile app, or withdraw money from the bank, we’re involved. If you want to make an impact on a global scale, come make a difference at Fiserv.
Job Title Head of Information Security
Head of Information Security
Company: MoneyPass Group (MPG) Function: Technology / Information Security Reports To: Chief Information Officer Location: Remote Level: Director / VP, depending on candidate experience
Position Summary
MoneyPass Group is seeking a hands-on Head of Information Security to establish and lead the company's information security, cyber risk, and security governance capabilities as MPG builds its independent technology environment.
This leader will be responsible for defining MPG's security strategy, establishing an effective security control environment, managing cyber risk, and ensuring that security responsibilities are effectively executed across MPG and its technology partners.
MPG operates a highly outsourced technology model in which managed service providers and other strategic partners deliver significant portions of infrastructure, application development, ATM technology, cloud, and security services. As a result, this role requires a leader who can effectively govern third-party security services while maintaining clear accountability for MPG's security posture.
The successful candidate will combine security leadership, technical depth, risk management, compliance expertise, and strong vendor governance with the willingness to personally drive execution in a lean organization.
Key Responsibilities
-
Security Strategy & Governance
-
Develop and maintain MPG's enterprise information security strategy, roadmap, policies, standards, and control framework aligned with the company's business objectives and risk tolerance.
-
Establish security governance across MPG's corporate technology, payment and ATM environments, cloud services, software platforms, data platforms, and third-party technology ecosystem.
-
Define security roles and responsibilities across MPG, its MSP/MSSP providers, software partners, and other critical vendors.
-
Establish and maintain the company's cyber risk register and regularly communicate material risks, remediation priorities, and security posture to the CIO and executive leadership.
-
Develop meaningful security metrics and executive reporting, including risk trends, vulnerabilities, incidents, control effectiveness, third-party risk, and remediation progress.
-
Security Operations & Cyber Defense
Provide oversight of MPG's security operations capabilities, including:
-
Security monitoring and SIEM
-
Managed detection and response (MDR)
-
Endpoint detection and response (EDR)
-
Vulnerability management
-
Threat intelligence
-
Identity monitoring
-
Cloud security monitoring
-
Email and collaboration security
-
Security incident detection and response
-
Manage and hold MPG's MSSP and other security providers accountable to defined SLAs, security requirements, escalation procedures, and performance metrics.
-
Ensure vulnerabilities are appropriately identified, prioritized, assigned, remediated, and tracked through closure.
-
Lead MPG's cyber incident response program, including incident response plans, escalation procedures, tabletop exercises, forensic coordination, regulatory/customer notification support, and post-incident reviews.
-
Serve as MPG's primary security leader during significant cybersecurity incidents.
-
Identity & Access Management
Establish and oversee MPG's identity and access management program, including:
-
Single sign-on and multifactor authentication
-
Privileged access management
-
Joiner/mover/leaver processes
-
Role-based access
-
Periodic access certification
-
Service and privileged account governance
-
Third-party access
-
Segregation of duties
-
Partner with IT and business leaders to implement appropriate least-privilege and Zero Trust principles across MPG's environment.
-
Security Architecture & Engineering
-
Establish security architecture principles and requirements for MPG's technology environment.
-
Review material technology implementations and architecture changes for security risks and required controls.
-
Partner with infrastructure, development, data, and MSP teams to incorporate security into cloud architecture, networks, endpoints, applications, APIs, integrations, and data platforms.
-
Establish appropriate security practices throughout the software development lifecycle, including code scanning, dependency management, secrets management, application security testing, and remediation processes.
-
Ensure new technologies—including AI and generative AI solutions—are evaluated for security, privacy, data protection, access, and third-party risks before production use.
-
Risk, Compliance & Audit
-
Own the technology security control environment supporting MPG's compliance and customer assurance requirements.
Partner with Legal, Finance, Internal Audit, Compliance, and external auditors to establish and maintain readiness for applicable frameworks and requirements, including:
-
SOC 1
-
SOC 2
-
PCI DSS, where applicable
-
NIST Cybersecurity Framework
-
CIS Controls
-
Applicable customer, contractual, regulatory, and privacy requirements
-
Translate compliance requirements into sustainable operational controls rather than point-in-time audit activities.
-
Maintain appropriate evidence demonstrating control operation and effectiveness.
-
Coordinate security-related audit activities and drive remediation of findings through closure.
-
Third-Party & Supply Chain Security
-
Establish MPG's third-party technology and cybersecurity risk management program.
-
Define minimum security requirements for MSPs, MSSPs, SaaS providers, software development partners, data providers, and other critical vendors.
-
Perform or oversee security assessments of critical vendors and review relevant SOC reports, penetration testing results, certifications, control exceptions, and remediation plans.
-
Maintain clear MPG-versus-provider responsibility matrices for critical security controls.
-
Ensure contracts contain appropriate cybersecurity, incident notification, data protection, audit, business continuity, and security-control requirements.
-
Actively challenge providers rather than assuming outsourced technology means outsourced accountability.
-
Data Protection
-
Partner with MPG's data and technology teams to establish security controls governing sensitive corporate, customer, transaction, payment, and endpoint data.
Establish standards for:
-
Data classification
-
Encryption
-
Key management
-
Data access
-
Data retention and destruction
-
Data loss prevention
-
Secure data transfer
-
Sensitive-data discovery and monitoring
-
Work with the business to reduce unnecessary retention and exposure of sensitive information.
-
Data Privacy & AI Governance
Partner with Legal, Compliance, and business leaders to operationalize MPG's data privacy obligations, translating them into sustainable technical and operational controls, including applicable requirements under:
-
Gramm-Leach-Bliley Act (GLBA), including the FTC Safeguards Rule and Privacy Rule requirements for protecting customer financial information
-
California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), and other applicable U.S. state privacy laws
-
EU and UK General Data Protection Regulation (GDPR), where MPG processes personal data of individuals in those jurisdictions
-
Maintain MPG's written information security program consistent with GLBA Safeguards Rule requirements, including periodic risk assessments, service provider oversight, and regular reporting to executive leadership and the Board.
-
Support data inventories, data mapping, and records of processing, and conduct privacy and data protection impact assessments for new systems, products, vendors, and material changes.
-
Embed privacy-by-design principles—including data minimization, purpose limitation, and retention limits—into architecture reviews and the software development lifecycle.
-
Enable timely and secure fulfillment of consumer and data subject rights requests, including access, deletion, correction, and opt-out, with appropriate identity verification.
-
Ensure incident response plans address privacy breach notification obligations and timelines, including GDPR supervisory authority notification, GLBA Safeguards Rule obligations, and other applicable privacy requirements.
-
Training & Awareness
-
Develop and deliver ongoing security awareness programs for employees and contractors to promote secure behaviors and understanding of security governance, risk, and compliance requirements.
-
Collaboration & Partnerships
-
Build strong partnerships with IT, product, engineering, risk, privacy, legal, compliance, and business leadership to embed security into business decisions and product development.
-
Governance & Reporting
-
Report on the security program to executive leadership and the Board, including risk posture, remediation progress, and metric trends.
-
Budget & Resource Management
-
Define and manage the information security budget, staffing plans, and technology investments to support the security program.
-
Talent Management
-
Hire, develop, and retain security professionals with the right mix of strategic leadership and hands-on expertise to deliver results in a lean organization.
-
Regulatory and Industry Engagement
-
Maintain awareness of evolving security regulations and industry standards applicable to MPG, participating in external forums and coordinating audits as needed.
-
Incident Response & Crisis Management
-
Lead and coordinate response to significant security incidents, including communications with stakeholders, regulators, customers, and partners, and drive post-incident remediation and improvements.
-
Security Testing & Validation
-
Ensure regular penetration testing, vulnerability assessments, and security testing across the technology stack, and oversee remediation tracking and verification.
-
Cloud Security & DevOps Integration
-
Integrate security into cloud architectures, DevOps practices, and CI/CD pipelines, ensuring secure development, deployment, and monitoring processes.
-
Data Analytics & Metrics
-
Develop dashboards and reports to measure security posture, risk trends, and the effectiveness of controls, with clear escalation paths for emerging threats.
-
Vendor & MSP Management
-
Oversee third-party security providers and MSPs/MSSPs, ensuring alignment with security requirements, SLAs, and contract terms.
-
Business Continuity & Disaster Recovery
-
Participate in the development and testing of business continuity and disaster recovery plans to minimize downtime and data loss.
-
Privacy-by-Design
-
Embed privacy considerations into product and system design from conception through deployment.
-
Compliance Management
-
Maintain a risk-based approach to compliance, ensuring timely updates to policies, procedures, and controls in response to regulatory changes.
-
Documentation
-
Ensure comprehensive documentation of security policies, controls, procedures, and evidence for audits and assessments.
-
Continuous Improvement
-
Drive continuous improvement of the security program through metrics, benchmarking, and evolving threats.
Qualifications
-
Proven experience building and leading a mature information security program in a complex, highly outsourced technology environment.
-
Deep technical knowledge across security operations, identity and access management, cloud security, data protection, privacy, and governance.
-
Strong risk management, regulatory, and vendor governance experience, with the ability to translate risk into actionable controls.
-
Demonstrated ability to drive execution in a lean organization, manage third-party security services, and maintain accountability.
-
Excellent communication and stakeholder management skills, with the ability to influence at the executive level.
-
Relevant certifications (e.g., CISSP, CISM, CISA) are a plus.
-
Bachelor’s degree in a relevant field; advanced degree preferred.
-
Location and Travel
-
Remote. Some travel may be required based on business needs.
-
Note: This position is with MoneyPass Group, reporting to the Chief Information Officer. The role involves governing third-party security services and leading the information security program for MPG’s independent technology environment.