SlipstreamJobsFresh Startup & VC-Backed Jobs

Head of Security

Spiko - London, United Kingdom - Hybrid

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Spiko is a treasury management infrastructure company founded in 2023, providing institutional-grade cash management solutions to businesses, nonprofits, financial advisers, and fintechs across Europe. The company processes hundreds of millions of euros in flows monthly and is backed by Index Ventures, the CEO of Revolut, the founder of Kyriba, and the CTO of Wise. As Head of Security, you own security end-to-end across the organization: application security, infrastructure and cloud security, identity and access management, vulnerability management, pentesting, AI-driven security testing, detection and incident response, and security culture. You define the security roadmap and set priorities with full ownership, reporting within the tech team. Key responsibilities include: - Achieving and maintaining ISO 27001 certification - Leading DORA (Digital Operational Resilience Act) implementation - Establishing policies, controls, and evidence collection for regulatory compliance - Working with legal and compliance teams on regulatory requirements - Supporting business development through security due diligence responses - Presenting security posture to partners and making security a competitive advantage The tech stack includes AWS, GCP, Cloudflare, Terraform, Kubernetes, Docker, PostgreSQL, Datadog, Ory identity solutions, GitHub Actions, and TypeScript-based applications. Spiko offers competitive compensation with stock options, offices in central Paris and London, flexible remote work (up to 2 days/week plus one full remote week monthly), 100% health insurance coverage, monthly perks budget, 50% public transport subsidy, referral bonuses, and regular team social events and offsites. REQUIREMENTS: Must-haves: - 5+ years of experience in security engineering roles - Solid understanding of application security, network security, and cloud security best practices - Experience with security audit processes, vulnerability management, and compliance frameworks (ISO 27001, SOC 2, or similar) - Familiarity with CI/CD security tooling (SAST, DAST, dependency scanning, container scanning) - Experience with automated pentesting tools or AI-driven security testing - Comfortable working autonomously and defining your own roadmap - Fluent in English - Curious, pragmatic, and eager to learn Nice-to-have: - Experience in fintech, capital markets, or other highly regulated environments - Knowledge of blockchain infrastructure or Web3 security

Similar roles