Head of Information Security
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
About the Role
As the Head of Information Security, you’ll play a key role in ensuring Bondora’s systems, data, and customers stay protected as we build toward a banking license—owning security hands-on, including when incidents happen. Collaboration is crucial, as you’ll work closely with product engineering, Site Reliability Engineering (SRE), information technology (IT), and compliance teams to maintain robust security controls and optimize processes for peak performance. This position requires a combination of hands-on engineering, regulatory expertise, and process management, making it an exciting and impactful opportunity to enhance our organization’s security posture.
Key Responsibilities
- Conduct regular security reviews of architecture and significant product changes—collaborating in design discussions, not acting as a gatekeeper at the end.
- Perform regular practical hardening work alongside engineering, including secrets management, access control, network segmentation, logging and alerting coverage, and CI/CD pipeline security.
- Design and coordinate external penetration tests, red team exercises, and the threat-led penetration testing (TLPT) mandated by the Digital Operational Resilience Act (DORA), translating findings into a realistic remediation backlog.
- Monitor and evaluate the ICT risk management framework required by DORA, working with all lines of defense on the practical application of related policies.
- Maintain accurate documentation of the quality assurance process, audits, results, and action points.
- Prepare and prioritize business requirements for necessary changes based on findings to improve efficiency and accuracy.
Location
This role is preferably based in Estonia, or remote from the EU.
Success Factors
Success in this role is determined by analytical expertise, process oversight, and data accuracy management. The ideal candidate will have:
- Proven experience in working with ICT regulations such as European Central Bank (ECB) requirements, DORA, and Estonian Financial Supervision Authority (EFSA) expectations.
- Strong skills in writing and reading code, and in security hardening practices in a cloud environment.
- Ability to work fluently with industry-standard security tooling—code analysers, network analysers, vulnerability scanners.
- Experience with penetration testing practices and standards.
- Ability to use large language model (LLM) powered security tools in daily work, and to reason with practical examples about their benefits, risks, and governance value in a regulated organization.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Bondora
Bondora
View Company ProfileBondora is a leading European peer-to-peer lending platform that provides an opportunity for individuals to lend money to other individuals or small businesses, offering a unique alternative to traditional banking and investment options. Founded in 2008, the company has established itself as a trusted and reputable player in the fintech industry, operating in multiple countries across Europe. With a strong focus on innovation, transparency, and user experience, Bondora has developed a robust platform that enables lenders to diversify their portfolios and achieve attractive returns, while borrowers can access affordable and convenient credit. The company's goal is to create a more efficient, secure, and accessible financial system, bridging the gap between lenders and borrowers and promoting financial inclusion. Through its cutting-edge technology and data-driven approach, Bondora has built a community of thousands of users, fostering a culture of trust, reliability, and collaboration. As a pioneering force in the peer-to-peer lending space, Bondora continues to evolve and expand its services, addressing the changing needs of the market and pushing the boundaries of financial innovation.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.






