Chief Information Security Officer (CISO) at Hawk

About Us 

Hawk is the leading provider of AI-supported anti-money laundering and fraud detection technology. Banks and payment providers globally are using Hawk’s powerful combination of traditional rules and explainable AI to improve the effectiveness of their AML compliance and fraud prevention by identifying more crime while maximizing efficiency by reducing false positives. With our solution, we are playing a vital role in the global fight against Money Laundering, Fraud, or the financing of terrorism. We offer a culture of mutual trust, support and passion – while providing individuals with opportunities to grow professionally and make a difference in the world. 

Hawk builds AI-powered financial crime detection (AML, transaction monitoring, and fraud prevention) for global tier-1 banks, payment processors, and high-growth fintechs. Because our platform analyzes real-time payment streams and sensitive financial data, security is not an administrative support function—it is our primary product promise.

We are looking for a technically grounded, hands-on CISO to own our global security posture end-to-end. This is a true player-coach leadership role. You will lead a dedicated team of four domain specialists while staying close enough to the technology to review cloud architecture, triage high-severity vulnerabilities, command critical incident responses first-hand, and debate technical security controls peer-to-peer with customer bank CISOs.

Why This Role Matters

Organizational Structure: The Four Domains

You will lead, mentor, and set technical direction for four specialized functional areas:

  1. Application Security: Secure SDLC, automated CI/CD security gates (SAST/DAST/SCA), software supply chain defense, secure coding standards, AI harnesses and pipeline hardening.

  2. Corporate Security: Zero Trust architecture, IAM/SSO, distributed endpoint defense (EDR/XDR), threat hunting, infrastructure access.

  3. Compliance & Governance: DORA implementation, ISO 27001, SOC 2 Type II, Third-Party Risk Management (TPRM), multi-jurisdiction regulatory audits, risk registry ownership.

  4. Data Protection: Solely dedicated to data protection: GDPR compliance, privacy governance, data subject rights, and statutory privacy regulatory requirements.

Core Accountabilities

1. Hands-On Technical Leadership, Engineering Integration & AI Hardening

2. Commercial Trust & Customer Engagement

3. Risk Registry, Compliance & Governance Leadership

4. Frontline Incident Response & Operational Resilience

12-Month Success Metrics:

  1. Commercial Velocity: Enterprise bank security assessments clear with zero high-severity blockers, accelerating enterprise contract closures.

  2. Proactive Risk Registry: The company risk registry is fully operationalized with executive buy-in, systematically driving down enterprise risk while supporting business expansion.

  3. Regulatory & Audit Record: DORA compliance program is operational; ISO 27001 and SOC 2 renew cleanly across all operating regions.

  4. Engineering & AI Hardening: Software supply chain security controls, secure coding standards, and AI harness guard rails are fully integrated into engineering CI/CD workflows.

  5. Resilient Team Operations: The four-person security team executes with high autonomy, defined KPIs, and high cross-functional trust across the company.

Candidate Profile:

Bonus:

 

Find Jobs in Germany on Arbeitnow

Apply for this Chief Information Security Officer (CISO) role

More jobs at Hawk

All open jobs at Hawk

More Chief Information Security Officer (CISO) jobs in Munich

More jobs in Munich