Domain Security Lead
Indexed description
You'll join the Security Enablement team within our first line of defense, working in close collaboration with our second-line assurance functions. You are the primary point of contact for all security matters in your domains: a strategic advisor and enabler.
Our vision: enable Klarna to provide market-leading, secure, high-quality, and compliant solutions that everyone loves developing and customers love using.
What You'll Do
- Partner with Domain Leads and senior stakeholders to align business plans, roadmaps, and security practices. Take full ownership of your domains' security posture and communicate it clearly to senior management.
- Lead, perform, and support risk identification and assessments, both for new products and initiatives before go-live and through periodic risk reviews.
- Help engineering and product teams identify security requirements, data classifications, and dependencies early in the design process.
- Drive security improvement programs within your area of expertise, and manage security engineering metrics, follow-up, and remediation work.
- Establish and maintain domain security routines that fit the teams' actual needs.
- Coordinate audit management: liaise with internal and external auditors, facilitate their inquiries, and follow up on the resolution of findings.
- Act as the local expert on security and compliance matters, including support for third-party vendors and outsourcing management.
- Review security incidents and vulnerabilities, and support retrospectives and root cause analyses.
- Grow the security culture: lead the Security Champions community in your domains and encourage participation in security training and competence development.
- Advocate for your domains' needs in Klarna's overall security planning and improvement initiatives.
- Several years of experience in information security, ideally in a BISO, security lead, security architect, GRC, or security consulting role, preferably within fintech, banking, or another regulated industry.
- Strong grasp of risk management, threat modeling, secure design and engineering practices, and incident response.
- Working knowledge of relevant regulatory and compliance frameworks such as ISO 27001, DORA, NIS2, PCI DSS, and SOX, and experience supporting audits against them.
- Comfortable operating across the full stack of stakeholders, from engineers and product managers to domain leadership and auditors, and translating between business language and technical security detail.
- A pragmatic enabler: you help teams find secure ways to ship, rather than just saying no.
- Experience building security culture and communities (e.g., security champions programs) is a strong plus.
- A technical background (software engineering, cloud infrastructure, or security engineering) is highly valued, as the role sits within our engineering competence.
- A pivotal role with broad ownership and direct influence on how one of the world's leading fintechs secures its products.
- A diverse, senior team of security specialists to learn from and collaborate with.
- The chance to work on security challenges spanning payments, banking, AI, fraud prevention, and large-scale engineering platforms.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search