White Hat Gaming

Head of Information Security

White Hat Gaming is a state-of-the-art iGaming platform providing a secure, scalable and flexible modular Casino and Sportsbook Player Account Management solution.

 

We offer operators choice, from our proprietary Player Account Management (PAM) to a full white-label solution. WHG provides market-leading content including Kambi Sportsbook, CRM tools, all payment options, and more than 3000 games from 120 leading games providers.


With over 500 talented colleagues from around the world, we offer a dynamic, collaborative environment where your ideas can flourish alongside industry leaders. Join us and be at the forefront of iGaming innovation!


Summary:

WHG is seeking an experienced and visionary Head of Information Security to lead and evolve our global information security function. Reporting to the executive team and overseeing the Senior Information Security Engineer and wider security function, you will own and drive the company’s security strategy, governance, risk management programme and long-term roadmap. Combining deep technical expertise with executive-level influence, you will lead a team of security professionals and partner closely with engineering, compliance, legal and executive leadership to protect our people, platforms, customers and data across all jurisdictions, with a particular focus on the regulated online gambling and financial services environment.


This role reports to the Head of IT and is fully remote.


Your day to day:

  • Defining and executing the company-wide information security strategy, vision, and multi-year roadmap aligned with business objectives and regulatory obligations.
  • Leading, mentoring, and growing the security team, including the Senior Information Security Engineer and other security staff, fostering a culture of accountability, learning, and continuous improvement.
  • Owning the enterprise risk management programme, including identification, assessment, treatment, and reporting of security and technology risks to the executive team and board.
  • Overseeing compliance with all relevant standards and regulations, including PCI DSS, ISO 27001, SOC 2, GDPR, and jurisdiction-specific gambling regulations across Malta, the UK, US states and other regulated markets.
  • Acting as the senior point of contact for external auditors, regulators, partners, and customers on all matters relating to information security, privacy, and assurance.
  • Establishing and maintaining security policies, standards, and procedures, ensuring they are embedded across engineering, operations, and business functions.
  • Leading the incident response programme, ensuring readiness through tabletop exercises, playbooks, and clear escalation paths, and taking command during major security incidents.
  • Driving the vulnerability management, threat intelligence, and penetration testing programmes, ensuring timely identification and remediation of risks across cloud (AWS) and on-premise environments.
  • Championing security-by-design across the SDLC, working with engineering and SRE leadership to embed secure development practices, automation, and tooling.
  • Defining and managing the security budget, vendor relationships, and tooling investments to ensure cost-effective and scalable security capabilities.
  • Building and running a security awareness and training programme that engages all employees and contractors across the organisation.
  • Reporting regularly to the executive team and board on the security posture, key risks, programme progress, and emerging threats.
  • Staying ahead of the evolving threat landscape, regulatory developments, and industry best practice, particularly within the online gambling and financial services sectors.

 

What we are looking for:

  • Significant experience in senior information security leadership roles, ideally including Head of Security, CISO, or equivalent positions in regulated industries.
  • Proven track record of building and leading high-performing security teams across multiple geographies.
  • Deep expertise in security governance, risk, and compliance frameworks such as PCI DSS, ISO 27001, SOC 2, NIST CSF, and GDPR.
  • Strong technical foundation across cloud security (AWS), application security, network security, identity and access management, and security operations.
  • Experience leading incident response and crisis management at an organisational level, including engagement with regulators and law enforcement where required.
  • Industry knowledge of online gambling, fintech, or other highly regulated sectors is strongly preferred.
  • Relevant certifications such as CISSP, CISM, CISA, CRISC, or equivalent are highly desirable.
  • Outstanding communication, influencing, and stakeholder management skills, with the ability to translate complex security topics for executive and board audiences.
  • Strategic mindset combined with hands-on pragmatism and the ability to operate effectively in a fast-paced, scale-up environment.


How we approach things:

  • Dynamic Medium-Sized Environment: We have a can-do ethos, where innovation is encouraged, and action is valued.
  • Core Values at Heart: We live by Teamwork, Innovation, Trust, and Integrity in everything we do.
  • Results-Oriented Focus: We prioritise getting things done while supporting each other to reach both collective and individual goals.
  • Open Collaboration: Our open-door policy fosters collaboration across all levels and departments, where ideas flow freely.
  • Global Team: We are truly a global team with people from various countries and cultures contributing to our success.


 What we offer:

  • A remote and flexible working schedule. 
  • Generous time off varied based on the country of residence.
  • Discretionary annual performance bonus
  • Training and other learning & development opportunities to support you through your career progression.
  • Hardware & Software allowance or work equipment is provided to make sure you have all the right tools to get the job done.
  • Various well-being programmes and initiatives.


We are an equal opportunities employer and welcome applications from all suitably qualified persons regardless of their race, gender, disability, religion/belief, sexual orientation, or age.


By submitting your application, you agree that we process your data in accordance with our Privacy Policy for the management of your candidature to any of the positions we offer.

Tech - Infrastructure

Remote

Partilhar em:

Termos de serviço.PrivacidadeCookiesDesenvolvido pela Rippling