CISO
Sunflower
- Where
- Tel Aviv, Israel, on-site
- Language, from the listing
- No Hebrew mentionedA missing mention doesn't mean Hebrew isn't needed. Ask if it matters to you.
- Dates
- Found 7 Oct 2026
- Last checked on the employer's site
- 2 h ago (7 Oct 2026)
- Source
- Employer career page (Comeet)
What they ask for
- 7+ years in information security, including 3+ years leading a security program or team at a cloud-native tech company
- Deep hands-on knowledge of AWS security, plus working knowledge of GCP
- Built an incident response process and led real incidents through to post-incident fixes
- Identity and access management at scale: SSO, MFA and least privilege, including access for contractors or offshore teams
- Led security audits or certifications (SOC 2, PCI DSS or ISO 27001), and worked with Legal on regulatory and privacy requirements
- Built application security programs alongside engineering leaders
- Able to explain risk to executives, and hands-on enough to read Terraform, review alerts and challenge engineers on technical detail
- Experience using LLMs or AI agents to automate security work
Nice to have
- Security in gaming, sweepstakes, fintech or payments
- Fighting bots, fraud or account takeover at scale
- Securing offshore or BPO teams, including the Philippines Data Privacy Act
- Hands-on experience with Cloudflare, JumpCloud or Island Enterprise Browser
- Certifications such as CISSP, CISM, CCSP or AWS Security Specialty
The full listing
Description
We run Crown Coins, a high-traffic social gaming platform on AWS and GCP. Players pay us, redeem prizes and trust us with their data. You’ll own our security program end to end: strategy, risk, compliance and incident response.
You’ll lead a SecOps engineer who sits inside our DevOps team. You’ll partner with the VP R&D on application security, and with Legal and IT on identity, access and compliance. This includes access and control for our external team in the Philippines.
Responsibilities
• Security strategy and risk: Own the security roadmap and risk register. Report security risk to executive leadership in business terms.
• Security operations: Lead the SecOps engineer inside DevOps. Set priorities for cloud security (AWS + GCP), edge protection (Cloudflare), detection and response. Own the incident response plan and lead major incidents.
• Application security: Work with the VP R&D to build security into how we ship: threat modeling, code and dependency scanning, pentests and vulnerability management.
• Identity and access: Work with IT and Legal to set access policy for employees, contractors and our external Philippines team. This covers SSO, MFA, least privilege, onboarding and offboarding, access reviews, and device and browser controls (JumpCloud, Google Workspace, Island).
• Compliance and privacy: Work with Legal on regulatory, payment (PCI DSS) and privacy requirements. Own security audits and vendor risk for vendors and outsourcing partners.
• Fraud and abuse: Work with engineering and fraud analysis teams to cut bot abuse, account takeover and fraud before it costs us money.
• AI-first security: Drive the use of AI agents for alert triage, access reviews and compliance evidence. Set the guardrails for how the company uses AI tools safely.
• Security culture: Write policies people actually follow. Run security awareness training for employees and external staff.
Requirements
• 7+ years in information security, including 3+ years leading a security program or team at a cloud-native tech company
• Deep hands-on knowledge of AWS security, plus working knowledge of GCP
• Built an incident response process and led real incidents through to post-incident fixes
• Identity and access management at scale: SSO, MFA and least privilege, including access for contractors or offshore teams
• Led security audits or certifications (SOC 2, PCI DSS or ISO 27001), and worked with Legal on regulatory and privacy requirements
• Built application security programs alongside engineering leaders
• Able to explain risk to executives, and hands-on enough to read Terraform, review alerts and challenge engineers on technical detail
• Experience using LLMs or AI agents to automate security work
Nice to have
• Security in gaming, sweepstakes, fintech or payments
• Fighting bots, fraud or account takeover at scale
• Securing offshore or BPO teams, including the Philippines Data Privacy Act
• Hands-on experience with Cloudflare, JumpCloud or Island Enterprise Browser
• Certifications such as CISSP, CISM, CCSP or AWS Security Specialty