Chief Information Security Officer
Trustly · Financial Services · 501-1,000 employees
San Francisco Bay Area · Hybrid · full_time
CLI Career Level
Enterprise CISO
Moderate confidence
Opportunity Score
78/100
Above average
High confidence
Executive Fit
Sign in
Add your background to score this role against you
Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.
First seen Aug 17, 2026 · Last verified 2 hours ago · Sourced from LinkedIn — CISO (US)
CLI Take
Scope matches the title
CLI reads this as an Enterprise CISO mandate, consistent with how the employer has titled it. Scope language covers global responsibility; multinational responsibility; board or committee interaction; executive committee exposure, and it reports to Global CTO and carries PCI DSS and SOC 2 accountability. The posting reads closer to an individual contributor mandate: hands-on delivery expected. Total compensation and team size are not disclosed and remain the main open questions before pursuing it.
Why this role scores the way it does
78/100 — above average opportunity quality. CLI reads this as an Enterprise CISO mandate. Strongest signal: Scope language covers global responsibility; multinational responsibility; board or committee interaction; executive committee exposure. Main drag on the score: The posting reads closer to an individual contributor mandate: hands-on delivery expected. 3 of 10 dimensions are not disclosed, which lowers confidence rather than the score.
Career level read
Enterprise CISO — The employer lists this as “Chief Information Security Officer”. CLI reads it as Enterprise CISO because the role shows global responsibility; multinational responsibility; board or committee interaction; executive committee exposure, reports to a C-level executive, board-level exposure expected.
Moderate confidence
What makes it attractive
- Scope language covers global responsibility; multinational responsibility; board or committee interaction; executive committee exposure.
- CLI's analysis of the posting describes a strategic build or transformation mandate.
- Board-level exposure is expected in the role.
- The role reports to a C-level executive.
- Signals worth probing: This is a dual-scope role: you will own the full information security program... while also leading the IT organization..
What to probe before applying
- The posting reads closer to an individual contributor mandate: hands-on delivery expected.
Scoring components · Above average
Compensation is not disclosed and there is no comparable set to place it against.
The role reports to a C-level executive.
Scope language covers global responsibility; multinational responsibility; board or committee interaction; executive committee exposure.
CLI's analysis of the posting describes a strategic build or transformation mandate.
Board-level exposure is expected in the role.
The posting reads closer to an individual contributor mandate: hands-on delivery expected.
Employer profile: 501-1,000 employee organization, pe backed ownership, private equity.
Team size: not disclosed.
Budget ownership: not disclosed.
Signals worth probing: This is a dual-scope role: you will own the full information security program... while also leading the IT organization..
Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.
Sign in to see how this role scores against your background, and add your career goal to evaluate career value.
Compensation
No compensation disclosed and insufficient comparable data to estimate.
The mandate
Serve as the most senior security and internal technology executive, owning both the global information security program and the IT organization. The CISO will define the security strategy, oversee enterprise architecture for payment systems, and lead the company's transition to an AI-native workplace productivity model.
Reports to the Global CTO; oversees a global team across Information Security and Information Technology. Remit includes security strategy, IT operations, AI productivity, and regulatory compliance for a global payments network.
Scope
- Reports to Global CTO
- Board-level exposure expected
Domains and regulation
- Enterprise Security
- Product Security
- Application Security
- Cloud Security
- Infrastructure Security
- Cyber Defense
- Identity
- GRC
- Incident Response
- Payments Security
- Resilience
- DevSecOps
- PCI DSS
- SOC 2
- CCPA
Requirements
Must have
- 15+ years of progressive experience in cybersecurity with breadth across architecture, risk, and operations
- Proven track record of building and scaling enterprise security programs in complex, high-growth environments
- Prior CISO title or equivalent accountabilities at a technology company, financial institution, or regulated fintech
- Hands-on experience navigating regulatory frameworks such as PCI DSS and ISO 27001
- Experience managing IT organizations at scale, including enterprise infrastructure and end-user technology
- Deep knowledge of cloud security (AWS, GCP, and/or Azure) and DevSecOps practices
Preferred / bonus
- Nothing listed as optional.
Only must-have items are scored as hard constraints in Executive Fit.
Likely challenges
- Managing security and IT operations across a high-growth, globally distributed fintech environment
- Navigating complex and evolving global regulatory regimes including PCI DSS, SOC 2, GDPR, DORA, and ISO 27001
- Redefining the internal technology ecosystem as an 'AI-native' workplace while ensuring security resilience
- Protecting millions of transactions across open banking infrastructure and API-heavy payment rails
Signals worth probing
- This is a dual-scope role: you will own the full information security program... while also leading the IT organization.
Not stated in the posting: Specific salary range (the posting references a range but does not list the numerical values); Team size (mentions 'leading high-performing teams' but no headcount); Budget authority details.
About Trustly
Trustly is a global payment platform that facilitates account-to-account transactions without requiring cards or mobile app downloads. The company serves e-commerce, financial services, gaming, and travel merchants by providing real-time payment processing and settlement capabilities. It processes billions of euros in transaction volume annually and operates across Europe, North America, and Australia.
- Industry
- Financial Services
- Headcount
- 501-1,000 employees
- Headquarters
- Stockholm, Sweden
- Founded
- 2008
- Ownership
- Private equity backed
- Funding
- Private equity backed
- Investors
- BlackRock, Nordic Capital, Neuberger Berman, Vitruvian Partners
Full company profile for Trustly →
View original job description
Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.