Information Security & Risk Professional · CISO
Senden Sie diesem Kandidaten direkt ein Jobangebot
Information risk and cybersecurity professional with broad experience across crypto, fintech, retail, and banking. Track record of building and running risk, security, and AI governance programs that align with business goals, including with DORA, BaFin, and ISO 27001 expectations.
Has worked all three lines of defense: security engineering and architecture, internal audit, and risk. At ease with peer functions, engineers, executives, and regulators. Hands-on as well as strategic: designs the controls, tests them, and builds the tooling when none exists. Uses AI in that work, and checks what it produces. Looking for a leading role to drive the strengthening of security posture, secure AI adoption, and the harmonization of technical security controls with regulatory and legislative requirements.
SPECIALTY & CREDENTIALS
Specialty: Leading information security and information risk projects. Applying practical and compliant solutions. Delivering on-time in-full. Consulting. Mentoring. Identifying problems and root causes.
Defining frameworks. Prioritizing. Simplifying. Increasing awareness. Cultivating cross-functional buy-in to accelerate critical initiatives. Reporting. Running own AI tooling for security research and control work: self-hosted RAG over MITRE ATT&CK, MITRE ATLAS, SOC 2 TSC, and the EU AI Act.
Governing it to the same standard as any AI the business adopts.
Education: Information Technology School, Belgrade, BASc in E-Business
Certifications: CISSP, Open FAIR Foundation, CCSK, ISACA Advanced in AI Security Management (exam passed, certification application submitted)
Languages: English (fluent), Serbian (native)
Finoa · Berlin, Germany · Startup - regulated crypto-assets service provider
Head of ICT Risk Office & Chief Information Security Officer Jan 2025 - July 2026
Reporting to the Chief Legal and Compliance Officer (MD). Led a two-person information security and risk team. Built the IT risk and cybersecurity control environment from a low base.
Principal InfoSec Risk Manager Sep 2021 - Dec 2024
Deputy CISO. Owned the company's "policy desk" and drove the alignment of the internal framework with regulatory and legislative requirements.
Reporting to the Chief Information Security Officer. Launched the initiatives that shaped the information risk agenda; promoted to Principal after seven months.
Senior Manager - Corporate Internal Audit IT
Jan 2019 - Jan 2021Reporting to the Chief Audit Officer. Third-line assurance over IT and information security. Updated the risk universe, improved the audit methodology, and led international teams across audit and advisory engagements.
Embedded information security into technical design across waterfall and agile projects.
IT Security Engineer
Jan 2016 - Dec 2016Security engineering on the bank's PCI DSS certification program, achieved during the engagement. Assessed control gaps and implemented the missing security layers. Classified sensitive data and specified encryption in transit for in-scope flows. Led security testing and solution integration with system integrators and major vendors.
Senior Network and Telecommunications Engineer Dec 2008 - Dec 2015
Led a team of network engineers. Designed a highly available and secure network of more than 1500 endpoints. Introduced authentication, authorization, and accounting for administrative access, and role-based access control for network devices and firewall clusters.
Education: Information Technology School, Belgrade, BASc in E-Business
Certifications: CISSP, Open FAIR Foundation, CCSK, ISACA Advanced in AI Security Management (exam passed, certification application submitted)