SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
SumUp's Information Security team protects a payments platform used by millions of small businesses globally. As an Information Security Architect, you will shape how security is built into new products from inception—from mobile payments to secure AI integration—while serving as a senior responder during security incidents. This role bridges prevention and response: you'll architect systems to prevent incidents and lead the response when they occur.
Key Responsibilities:
- Define security architecture requirements for high-risk initiatives including PCI PIN, payment processing, and mobile payment surfaces
- Build automation for security architecture assurance and incident response, including policy-as-code, detection-as-code, and SOAR workflows
- Lead incident triage, investigation, containment, and remediation for complex, high-severity security incidents
- Develop and improve incident response playbooks and detection automation with the security team
- Coordinate with Engineering, Platform, IT, Product, Risk, and Compliance to validate security before product launch
- Maintain a prioritized security roadmap balancing architecture work with lessons learned from incidents
The role is office-first based in SumUp's modern Sofia office. SumUp is a fintech platform serving over 4 million businesses across 38 markets, with a team of 3,000+ employees from 90+ nationalities. The company offers stock options, €2,000 annual L&D budget with 10 paid educational days, 25+ days paid leave, health and life insurance, on-site wellness programs, free shuttle service, and a 1-month sabbatical after 3 years.
Requirements:
- More than 8 years of security experience, including at least 3 years focused on security architecture and substantial hands-on incident response
- Strong knowledge of SIEM/SOAR/CNAPP systems
- Experience with modern cloud vendors (AWS, Azure, GCP) and SaaS solutions (Vercel, n8n, Cloudflare, Langdock, Cursor, IncidentIO, Notion, Vanta)
- Strong knowledge of payment security standards, including PCI DSS and PCI PIN
- Experience building or improving detection-as-code, security automation pipelines, or workflow automation tools
- Ability to translate architecture decisions and incident risk into clear language for senior stakeholders
- Track record of leading response during high-severity incidents while balancing multiple cross-functional priorities