Post a job

Cybersecurity Lead

Coverflex · United States · €65k – €95k · posted today ago

Apply for this role

engineeringremote jobs in united states
Listing supplied by Himalayas. 101 Careers did not originate this post and applications are handled by the employer.

About this role

🧡 Coverflex

Work changed. Pay didn’t.

Coverflex exists to make compensation work for everyone.
Pay is still rigid, fragmented, and hard to feel.
We turn compensation into choice — one platform, one card, one app — for benefits, meal allowance, insurance and more.

Our platform is simple for HR and meaningful for employees.
We provide choice, smarter compensation tools and empowerment.

⚙️ TL;DR (The Essentials)

Role: Cybersecurity Lead
Seniority Level: Lead
Type: Individual Contributor
Languages: English (main) / Portuguese or Spanish or Italian a plus
Main Tools: AWS and/or GCP security tooling, SIEM, detection/response, EDR/MDM, identity/SSO/MFA, and privileged-access tooling, Vulnerability scanning, application security testing, and penetration-testing workflows, Jira/Notion or equivalent risk, remediation, evidence, and roadmap tracking, Scripting/automation for control operation and evidence collection
Location: Remote (Europe only)
Compensation:

💥 Your Impact

Your role will play a major role in our success because…

The Cybersecurity Lead will help Coverflex grow as a trusted, resilient multi-market fintech. By identifying material risks earlier, strengthening security operations and third-party assurance, and making security evidence reusable, this role will protect customers and company data, support reliable payment and benefits services, preserve ISO 27001 and contractual commitments, and reduce friction in launches, enterprise sales, renewals, and audits.

You’ll know you’re successful if, after 90 days...

  1. 100% of material security risks have an owner, treatment decision, due date, and monthly review; a monthly dashboard and quarterly Management Team risk review are in place; and all required ISMS, cybersecurity, and related privacy documentation has a named owner, review cadence, and current approved version.

  2. At least one executive risk exercise and one technical control validation are completed, with ≥90% of resulting actions closed by their due dates; ≥95% of critical/high vulnerabilities are remediated within policy SLA and all exceptions are formally approved and time-bound.

  3. 100% of defined high-risk changes receive a risk-based review before launch; 100% of critical suppliers are tiered and the highest-risk suppliers are assessed, with contractual and technical gaps tracked.

How we’ll measure success:

⚡ Reality Check - What Makes This Role Hard

Let’s be real - here’s what makes this role challenging:

This is a broad, hands-on role in a scaling, regulated, multi-market environment. The person must move comfortably between technical investigation, cloud and product security, risk and assurance, partner management, and executive communication. They will need to influence teams without taking ownership away from Engineering, Product, Legal/Compliance, the DPO, or business leaders; prioritise ruthlessly with limited dedicated capacity; and build useful guardrails without becoming a gatekeeper. Third-party dependencies, an evolving threat surface, remote-first operations, and fragmented security ownership add complexity.

👤 You

Must-haves (evidence, not years)

Nice-to-have

🧬 Your DNA

Pragmatic, calm under pressure, curious, and evidence-driven. You combine sound judgement with a bias for action, challenge constructively, and communicate risk without fearmongering. You are comfortable doing the work yourself while creating leverage through standards, automation, and collaboration. You understand commercial trade-offs, make clear recommendations, and escalate material risks appropriately rather than seeking universal control.

You should add dedicated security depth and consistent ownership while preserving clear accountability in the teams that own systems and decisions. You will make Engineering, Product, IT, Legal/Compliance, the DPO, and leadership more effective through prioritisation, expert challenge, reusable patterns, direct technical support, and reliable follow-through. You should reduce key-person dependency on Technology Leadership and become the trusted bridge between technical evidence and business risk decisions.

👥 Manager & Team

Meet Your Manager

Hiring Manager: Tiago Fernandes, CTO
Location: Portugal
LinkedIn Profile

Profile Snapshot:

What is it like to work with you?

You will have meaningful autonomy, access to leadership, and support when a risk requires escalation. I expect you to bring a point of view, go deep enough to understand the facts, and be comfortable creating structure from ambiguity. We will not always begin with perfectly packaged context, so asking questions, summarising what you heard, and making decisions explicit are important. Healthy challenge is welcome, as is helping me simplify or sharpen the framing. The goal is to build a trusted security function that enables the business while being honest about material risk.

Your Team

💜 Access & Belonging (Equal Opportunity)

We hire for impact and potential, not pedigree.
We welcome applications from people with non-linear careers, career breaks, caregiving gaps, and those changing fields.

No discrimination on the basis of age, disability, gender identity/expression, marital or family status, pregnancy, neurodivergence, race/ethnicity, religion/belief, sexual orientation, or any other protected ground.

Assessment fairness:
We anchor on evidence of outcomes (what you shipped, moved, or influenced).
We actively de-bias by using structured rubrics, multiple assessors, and blind screening most of the time (we won’t know your name, gender, or personal info until the interview stage).

📬 Application Clarity

No cover letter required.

Apply with your LinkedIn or upload your CV.
You may be asked a few short, relevant questions.

Total candidate time investment: ~3–5 hours end-to-end.

🧩 Hiring Stages (What to Expect, Why & How Long)

1. CV / LinkedIn Screen — Signal check vs must-haves

• Done by People + Hiring Manager.

• You’ll hear from us within 7 business days.

2. Role-Fit Questionnaire (async)
Purpose: capture signals your CV can’t (languages, tools, scenario judgement) and calibrate seniority.

Format: multiple choice + short answers.

Accessibility: prefer a call? Tell us - we’ll swap for a short chat.

3. Hiring Manager Interview - Deep dive into your work • 45–60 min
Structured around outcomes, decisions, and collaboration.

4. Behavioural Interview - Show how you think • 45-60 min
Use our case or bring a real artefact (deck, PR, analysis, playbook).
We assess clarity, decision quality, stakeholder thinking, and ethics.

5. Case / Work Sample - Show how you think • ≤90 min
Use our case or bring a real artefact (deck, PR, analysis, playbook).
We assess clarity, decision quality, stakeholder thinking, and ethics.

6. Case Review & Team Chat - Walkthrough + Q&A • 20–30 min
You’ll get actionable feedback either way.

7. Final Conversation (CEO / C-Level) — Values, strategy, and your growth • 30–45 min

Optional: References (2–3 people who’ve seen your recent work) - async.

🤖 AI & Hiring Tools Transparency

We use a few tools to reduce bias and improve documentation, not to make hiring decisions.

Important: every application is reviewed by a human, and no decision or rejection is made by AI. If recording is used, we’ll be transparent and (where required) ask for consent.

⏱️ Speed & Communication

Originally posted on Himalayas

Similar remote engineering jobs

Browse all remote engineering jobs →

Cybersecurity Lead at Coverflex — Remote | 101 Careers