About the Company
Our client is a leading global infrastructure provider of digital asset solutions, delivering custody, wallets, staking, trading, financing, and settlement services from regulated cold storage. Founded over a decade ago, the firm serves thousands of institutional clients and millions of retail investors worldwide, and is one of the largest independent digital asset custodians and staking providers globally.
The Role
Our client is looking for a CISO to establish the security strategy and direction for their European entity. This is a senior leadership opportunity to shape the security posture of a global leader in digital asset custody, working closely with engineering teams to ship secure, scalable products while maintaining full regulatory compliance across BaFin, DORA, and MiCA requirements.
Key Responsibilities
- Serve as the designated CISO for the European entity, fulfilling all regulatory obligations under BaFin, DORA, and MiCA
- Develop, implement, and maintain an ISMS in line with ISO 27001 and applicable EU regulatory standards
- Lead identification, assessment, and treatment of ICT and information security risks in alignment with DORA's ICT risk management framework
- Act as primary contact with BaFin and other EU regulators on security matters, audits, and inquiries
- Own incident response and ICT-related incident reporting, including regulatory notifications under DORA
- Define and enforce security policies covering network security, access management, cryptographic asset protection, and operational resilience
- Coordinate security assessments, penetration tests, vulnerability management, and third-party ICT risk reviews
- Align European security posture with global standards while meeting local regulatory requirements
- Foster a security-first culture and provide security awareness training across the Frankfurt office
- Report to senior management and the Management Board on security posture, risks, and remediation progress
Candidate Profile
- 6–10 years of information security experience, including at least 3 years in a senior or lead CISO role within a regulated financial services or fintech environment
- Deep knowledge of BaFin, DORA, and MiCA, with hands-on experience implementing related controls
- Experience managing or operating under an ISO 27001-certified ISMS; CISM, CISSP, or equivalent certification strongly preferred
- Strong grounding in ICT risk management, third-party risk, and operational resilience under DORA
- Direct experience engaging with financial regulators (BaFin or an equivalent EU authority)
- Familiarity with digital asset infrastructure, custody technology, and blockchain security considerations is a strong advantage
- Fluent in English and German, with the ability to produce regulatory-quality and board-level documentation
- Proven ability to build and lead cross-functional security initiatives in a fast-paced, international organization
- Based in or willing to relocate to Frankfurt