About this role
InfoSec Manager (GRC)
Malta or EU remote | Reports to CTO, leads one pentester to start. Build the framework, then run the controls: ISO 27001, GDPR, PCI DSS, SIEM, EDR, incident response.
Location: Based in Malta - Employee or Remote from Europe Reporting to CTO Direct Reports: Penetration Tester
Your Impact
Governance, Risk & Compliance
- Build and maintain the security framework, aligned to ISO 27001.
- Manage security risk across the group and report clearly to leadership.
- Keep us compliant with the regulations that matter - GDPR, PCI DSS, and similar.
- Write practical security policies people will actually follow.
- Lead audits, certifications, and security questionnaires from partners and regulators.
- Run vendor risk checks and deliver security awareness training.
- Create training materials for our staff.
IT Security
- Own identity and access - SSO, MFA, and access controls.
- Harden endpoints and manage device security (EDR, MDM).
- Set and check network security controls with IT (firewalls, VPN, segmentation).
- Run vulnerability and patch management, and drive fixes to closure.
- Manage email security, phishing defense, and SaaS security.
- Operate security tooling and monitoring (SIEM, DLP).
- Lead incident response and investigations.
- Coordinate penetration tests and manage remediation.
Leadership & Process
- Lead and mentor the security team, starting with one penetration tester.
- Grow the team as the function scales - hiring and shaping roles as needs evolve.
- Partner closely with IT - security sets the requirements, IT helps implement, and you drive them together without stepping on each other.
What Makes You a Fit
- 5+ years in information security, across both GRC and hands-on IT security.
- Background in iGaming, fintech, or another regulated industry.
- Solid grounding in IT security: identity, endpoints, networking, and security tooling.
- Experience with risk assessments, audits, and incident response.
- Able to explain security risk clearly to both technical and business audiences.
- Comfortable working independently in a fast-paced environment.
- Leadership experience - managing or mentoring at least one team member, with the appetite to grow a team.
- Able to explain security risk clearly to both technical and business audiences.
- Experience with a recognized framework (ISO 27001, SOC 2, NIST, or similar).
- Good knowledge of GDPR and at least one of PCI DSS, MGA, or DORA.
- Nice to have (not a must): production systems and AWS
What's in it for you?
Be with a team that builds the momentum that moves the industry. A fast-paced environment driven by innovation, curiosity, and a shared love for technology. A people-first culture that rewards ambition, integrity, and genuine collaboration.
Comprehensive benefits package for Malta-based employees, including:
- Private health insurance, wellness allowance, and communication allowance.
- Healthy lunch on Wednesdays and a varied calendar of social events throughout the year.
- Employee discounts in restaurants and businesses.
- Extended second-parent leave policy.
- Private parking space.
This opportunity is powered by Bet On Talent - Applying through us is your ultimate VIP pass We work deeply within our partner's ecosystem, which means we skip the generic applicant piles and fast-track your profile straight to the team - Hit apply now and let's make your next big career move happen!
Department
Information Security
Locations
Malta, Remote
Remote status
Hybrid
Employment type
Full-time
Contact
Catarina Bastos
Talent Acquisition Manager
Apply
Information Security
Malta, Remote
Hybrid
InfoSec Manager (GRC)
Malta or EU remote | Reports to CTO, leads one pentester to start. Build the framework, then run the controls: ISO 27001, GDPR, PCI DSS, SIEM, EDR, incident response.