About Bondora

At Bondora, our mission is simple: to make finance easy, transparent, and accessible for everyone. Founded in 2008, we’ve helped more than 700,000 customers across Europe borrow and invest effortlessly through our trusted digital products. As a rapidly growing financial technology company, we’re reaching new heights with a bold vision. We’re set to acquire a banking license, unlocking a world of possibilities for our customers. This transition will allow us to expand our lending across more EU countries and broaden our product suite to deliver even more value.

Role Overview

As the Head of Information Security, you'll play a key role in ensuring Bondora's systems, data and customers stay protected as we build toward a banking licence — owning security hands-on, including when incidents happen. Collaboration is crucial, as you'll work closely with product engineering, Site Reliability Engineering (SRE), information technology (IT) and compliance teams to maintain robust security controls and optimize processes for peak performance. This position requires a combination of hands-on engineering, regulatory expertise, and process management, making it an exciting and impactful opportunity to enhance our organization's security posture.

Responsibilities

  • Conduct regular security reviews of architecture and significant product changes — as a collaborator in design discussions, not a gate at the end.
  • Perform regular practical hardening work alongside engineering: secrets management, access control, network segmentation, logging and alerting coverage, and continuous integration / continuous delivery (CI/CD) pipeline security.
  • Design and coordinate external penetration tests, red team exercises and the threat-led penetration testing (TLPT) mandated by the Digital Operational Resilience Act (DORA), translating findings into a realistic remediation backlog.
  • Monitor and evaluate the information and communication technology (ICT) risk management framework required by DORA, working with all lines of defence on the practical application of related policies.
  • Maintain accurate documentation of the quality assurance process, audits, results, and action points.
  • Prepare and prioritize business requirements for necessary changes based on findings to improve efficiency and accuracy.

What we offer

  • Contribute to Bondora’s ambitious goal of reaching 1BN in revenue. Your skills and efforts will directly impact our growth trajectory and shape the future of our company.
  • Our employees deserve the best. We recognize our people with a competitive salary and a generous benefits package (5 weeks of vacation, private healthcare compensation, hobby grant, mental healthcare support, share options and much more!)
  • We provide an environment that encourages your personal and professional growth. As we constantly evolve and innovate, you’ll have endless opportunities (and budget) to expand your skills and skyrocket your career.

Requirements

  • Proven experience in working with ICT regulations such as European Central Bank (ECB) requirements, DORA, and Estonian Financial Supervision Authority (EFSA) expectations.
  • Strong skills in writing and reading code, and in security hardening practices in a cloud environment.
  • Ability to work fluently with industry-standard security tooling — code analysers, network analysers, vulnerability scanners.
  • Experience with penetration testing practices and standards.
  • Ability to use large language model (LLM) powered security tools in daily work, and to reason with practical examples about their benefits, risks, and governance value in a regulated organisation.