Flexifai is an AI-driven payment platform (PSP) serving both high-risk and traditional industries. We process millions of transactions through 80+ payment methods, including cryptocurrency, across Africa, Europe, and LATAM. Our platform is built on a scalable microservices architecture with a strong focus on security, automation, and high availability.
Our team of 80+ professionals works in a hybrid format from offices in Kyiv, Lisbon, Limassol, and London, as well as remotely across the globe.
What you’ll be responsible for: * Developing, implementing, and maintaining information security policies. * Building and developing an ISMS in accordance with ISO/IEC 27001. * Preparing the company for PCI DSS certifications and audits. * Working with external auditors (QSAs) and overseeing compliance with requirements. * Managing access controls (IAM) and conducting regular Access Reviews. * Coordinating penetration testing and vulnerability management. * Establishing and maintaining Incident Response processes. * Managing security risks and supporting internal audits. * Participating in security due diligence for partners and clients. * Partially administering corporate SaaS services and security tools.
Required Skills: * 5+ years of experience in Information Security. * At least 2 years of experience in fintech, banking, PSP, or payment processing. * Hands-on experience with PCI DSS audits. * Experience building or maintaining an ISMS in accordance with ISO/IEC 27001. * Good understanding of IAM, Access Management, and modern security practices. * English — Upper-Intermediate (B2+) or higher. * Professional certifications such as CISSP, CISM, or ISO 27001 Lead Implementer/Auditor will be a strong advantage.
Nice to have: * PCIP or ISA. * CISA, CRISC, or CCSP. * Experience with SOC 2 Type II audits. * Practical experience with DORA, GDPR, or NIS2. * Understanding of PSD2, SCA, and the European payment ecosystem.
What we offer: * An opportunity to work in a growing international fintech company. * The chance to have a real impact on building security processes practically from scratch. * Exposure to international security standards and compliance frameworks. * Remote work. * Competitive compensation. * A strong team of technical specialists with minimal bureaucracy. * A real opportunity to influence the development of both the product and the company’s security.