Chief Information Security Officer

Remote: 
Full Remote
Contract: 
Work from: 

Offer summary

Qualifications:

5-8+ years in cybersecurity, risk, or information security governance roles., Proven experience in the EU regulatory landscape, particularly with NIS2, MiCA, DORA, and GDPR., Strong collaboration and communication skills, especially across borders and time zones., Certifications such as CISSP, CISM, or equivalent are preferred..

Key responsibilities:

  • Review and monitor adherence to European cybersecurity regulations like NIS2 and GDPR.
  • Coordinate regulatory filings, audits, and inquiries, serving as a regional SME on crypto-related regulations.
  • Collaborate with Legal, Risk, and Compliance teams to align on regulatory guidance interpretations.
  • Monitor cybersecurity risk posture and oversee third-party vendor assessments from a regional risk perspective.

Robinhood logo
Robinhood Financial Services Large http://www.robinhood.com
1001 - 5000 Employees
See all jobs

Job description

Join a leading fintech company that’s democratizing finance for all.

Robinhood Markets was founded on a simple idea: that our financial markets should be accessible to all. With customers at the heart of our decisions, Robinhood and its subsidiaries and affiliates are lowering barriers and providing greater access to financial information. Together, we are building products and services that help create a financial system everyone can participate in.

With growth as the top priority...

The business is seeking curious, growth-minded thinkers to help shape our vision, structures and systems; playing a key-role as we launch into our ambitious future. If you’re invigorated by our mission, values, and drive to change the world — we’d love to have you apply.

About the team: 

The Chief Information Security Officer (Europe) will provide regional oversight of cybersecurity, technology risk, and privacy risk management for Robinhood Crypto’s European operations. This role will work in close coordination with Robinhood’s centralized U.S. Security and Privacy teams to ensure that European-specific regulatory requirements—such as those under the NIS2 Directive, the Digital Operational Resilience Act (DORA), and GDPR security and privacy provisions—are effectively met, documented, and integrated into global risk frameworks.

The CISO (Europe) will serve as the primary point of contact in the region for regulatory responses related to cybersecurity and technology risk. The ideal candidate will be a seasoned risk and security leader with a strong understanding of European regulatory frameworks, cross-border data flows, and a collaborative approach to managing evolving risks in a dynamic and regulated environment.

No licenses are required.

What you’ll do day-to-day:

  • Review and monitor adherence to European cybersecurity regulations (e.g., NIS2, DORA, GDPR security provisions).
  • Coordinate and contribute to regulatory filings, audits, or inquiries (e.g., preparing evidence for EU supervisory authorities). Serve as a regional SME on crypto-related regulatory expectations, particularly around MiCA, AML/CFT, and privacy/security of blockchain-based systems.
  • Collaborate with Legal, Risk, and Compliance to align on interpretations of regulatory guidance.
  • Act as an advisor to product, engineering, and business teams on secure design principles and operational risks tied to the European market. In addition, partner with global product and engineering teams to review new crypto product launches, token listings, or integrations for security and compliance risks.
  • Monitor cybersecurity risk posture specific to European operations.
  • Oversee third-party vendor assessments from a regional risk perspective, including support for data residency or encryption requirements.
  • Coordinate with Procurement and Legal for vendor onboarding or reassessments.
  • Serve as a regional conduit for U.S.-led security operations, incident response, threat intelligence, and security architecture.
  • Flag or escalate local threats, regulatory risks, or tooling gaps to the global security team.
  • Localize global security policies or standards for the European context.
  • Support security-by-design reviews, especially for European customer-facing features or partnerships.
  • Deliver security awareness or training content customized for EU audiences, where relevant.
  • Monitor and support security controls specific to digital assets, such as secure key management, wallet infrastructure, custody models (e.g., MPC, HSMs), and blockchain protocol-level risks.
  • Coordinate with U.S. cybersecurity and crypto-specific security functions on threat intel, blockchain forensics, or emerging vulnerabilities (e.g., smart contract risks, bridge exploits).
About you:
  • 5- 8+ years in cybersecurity, risk, or information security governance roles, with experience in the EU regulatory landscape.
  • Proven experience working in or closely with a cryptocurrency exchange, digital asset custodian, or blockchain-based platform.
  • Deep familiarity with European cybersecurity laws (NIS2, MiCA, DORA, GDPR Art. 32) and frameworks (ISO 27001, NIST CSF).
  • Experience working with or responding to supervisory authority inquiries, inspections, or regulatory requests
  • Demonstrated ability to interpret and operationalize regulatory requirements into practical policies or controls.
  • Experience engaging with European regulators or auditors, especially in the fintech or financial services sector.
  • Strong collaboration and communication skills, especially across borders and time zones.
  • Ability to work independently, balancing oversight duties with influence—not control—of operational execution.
Bonus points:
  • Experience working with or supporting a centralized/global security team from a satellite or regional function.
  • Experience with MiCA and DORA implementation or acting as a CISO in a VASP, or similar financial institution
  • Familiarity with third-party risk management tools and processes.
  • Certifications such as CISSP, CISM, CIPP/E, ISO 27001 Lead Auditor, or equivalent.
  • Knowledge of cloud-native security principles, AWS preferred
  • Knowledge of chain analytics tools (e.g., Chainalysis, TRM Labs) or experience partnering with such vendors.
  • Multilingual abilities (e.g., English + Lithuanian or German) can be helpful in regulator communications.

Click here to learn more about available Benefits, which vary by region and Robinhood entity.

We’re looking for more growth-minded and collaborative people to be a part of our journey in democratizing finance for all. If you’re ready to give 100% in helping us achieve our mission—we’d love to have you apply even if you feel unsure about whether you meet every single requirement in this posting. At Robinhood, we're looking for people invigorated by our mission, values, and drive to change the world, not just those who simply check off all the boxes.

Robinhood embraces a diversity of backgrounds and experiences and provides equal opportunity for all applicants and employees. We are dedicated to building a company that represents a variety of backgrounds, perspectives, and skills. We believe that the more inclusive we are, the better our work (and work environment) will be for everyone. Additionally, Robinhood provides reasonable accommodations for candidates on request and respects applicants' privacy rights. Please review the specific Robinhood Privacy Policy applicable to the country where you are applying.

Required profile

Experience

Industry :
Financial Services
Spoken language(s):
EnglishLithuanianGerman
Check out the description to know which languages are mandatory.

Other Skills

  • Collaboration
  • Communication
  • Problem Solving

Chief Information Officer (CIO) Related jobs