Calling all innovators – find your future at Fiserv.
We’re Fiserv, a global leader in Fintech and payments, and we move money and information in a way that moves the world. We connect financial institutions, corporations, merchants, and consumers to one another millions of times a day – quickly, reliably, and securely. Any time you swipe your credit card, pay through a mobile app, or withdraw money from the bank, we’re involved. If you want to make an impact on a global scale, come make a difference at Fiserv.
Job Title
Head of Information Security
Head of Information Security
Company:
MoneyPass Group (MPG)
Function:
Technology / Information Security
Reports To:
Chief Information Officer
Location:
Remote
Level:
Director / VP, depending on candidate experience
Position Summary
MoneyPass Group is seeking a hands-on
Head of Information Security
to establish and lead the company's information security, cyber risk, and security governance capabilities as MPG builds its independent technology environment.
This leader will be responsible for defining MPG's security strategy, establishing an effective security control environment, managing cyber risk, and ensuring that security responsibilities are effectively executed across MPG and its technology partners.
MPG operates a highly outsourced technology model in which managed service providers and other strategic partners deliver significant portions of infrastructure, application development, ATM technology, cloud, and security services. As a result, this role requires a leader who can effectively govern third-party security services while maintaining clear accountability for MPG's security posture.
The successful candidate will combine
security leadership, technical depth, risk management, compliance expertise, and strong vendor governance
with the willingness to personally drive execution in a lean organization.
Key Responsibilities
Security Strategy & Governance
Develop and maintain MPG's enterprise information security strategy, roadmap, policies, standards, and control framework aligned with the company's business objectives and risk tolerance.
Establish security governance across MPG's corporate technology, payment and ATM environments, cloud services, software platforms, data platforms, and third-party technology ecosystem.
Define security roles and responsibilities across MPG, its MSP/MSSP providers, software partners, and other critical vendors.
Establish and maintain the company's cyber risk register and regularly communicate material risks, remediation priorities, and security posture to the CIO and executive leadership.
Develop meaningful security metrics and executive reporting, including risk trends, vulnerabilities, incidents, control effectiveness, third-party risk, and remediation progress.
Security Operations & Cyber Defense
Provide oversight of MPG's security operations capabilities, including:
Security monitoring and SIEM
Managed detection and response (MDR)
Endpoint detection and response (EDR)
Vulnerability management
Threat intelligence
Identity monitoring
Cloud security monitoring
Email and collaboration security
Security incident detection and response
Manage and hold MPG's MSSP and other security providers accountable to defined SLAs, security requirements, escalation procedures, and performance metrics.
Ensure vulnerabilities are appropriately identified, prioritized, assigned, remediated, and tracked through closure.
Lead MPG's cyber incident response program, including incident response plans, escalation procedures, tabletop exercises, forensic coordination, regulatory/customer notification support, and post-incident reviews.
Serve as MPG's primary security leader during significant cybersecurity incidents.
Identity & Access Management
Establish and oversee MPG's identity and access management program, including:
Single sign-on and multifactor authentication
Privileged access management
Joiner/mover/leaver processes
Role-based access
Periodic access certification
Service and privileged account governance
Third-party access
Segregation of duties
Partner with IT and business leaders to implement appropriate least-privilege and Zero Trust principles across MPG's environment.
Security Architecture & Engineering
Establish security architecture principles and requirements for MPG's technology environment.
Review material technology implementations and architecture changes for security risks and required controls.
Partner with infrastructure, development, data, and MSP teams to incorporate security into cloud architecture, networks, endpoints, applications, APIs, integrations, and data platforms.
Establish appropriate security practices throughout the software development lifecycle, including code scanning, dependency management, secrets management, application security testing, and remediation processes.
Ensure new technologies—including AI and generative AI solutions—are evaluated for security, privacy, data protection, access, and third-party risks before production use.
Risk, Compliance & Audit
Own the technology security control environment supporting MPG's compliance and customer assurance requirements.
Partner with Legal, Finance, Internal Audit, Compliance, and external auditors to establish and maintain readiness for applicable frameworks and requirements, including:
SOC 1
SOC 2
PCI DSS, where applicable
NIST Cybersecurity Framework
CIS Controls
Applicable customer, contractual, regulatory, and privacy requirements
Translate compliance requirements into sustainable operational controls rather than point-in-time audit activities.
Maintain appropriate evidence demonstrating control operation and effectiveness.
Coordinate security-related audit activities and drive remediation of findings through closure.
Third-Party & Supply Chain Security
Establish MPG's third-party technology and cybersecurity risk management program.
Define minimum security requirements for MSPs, MSSPs, SaaS providers, software development partners, data providers, and other critical vendors.
Perform or oversee security assessments of critical vendors and review relevant SOC reports, penetration testing results, certifications, control exceptions, and remediation plans.
Maintain clear
MPG-versus-provider responsibility matrices
for critical security controls.
Ensure contracts contain appropriate cybersecurity, incident notification, data protection, audit, business continuity, and security-control requirements.
Actively challenge providers rather than assuming outsourced technology means outsourced accountability.
Data Protection
Partner with MPG's data and technology teams to establish security controls governing sensitive corporate, customer, transaction, payment, and endpoint data.
Establish standards for:
Data classification
Encryption
Key management
Data access
Data retention and destruction
Data loss prevention
Secure data transfer
Sensitive-data discovery and monitoring
Work with the business to reduce unnecessary retention and exposure of sensitive information.
Data Privacy & AI Governance
Partner with Legal, Compliance, and business leaders to operationalize MPG's data privacy obligations, translating them into sustainable technical and operational controls, including applicable requirements under:
Gramm-Leach-Bliley Act (GLBA), including the FTC Safeguards Rule and Privacy Rule requirements for protecting customer financial information
California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), and other applicable U.S. state privacy laws
EU and UK General Data Protection Regulation (GDPR), where MPG processes personal data of individuals in those jurisdictions
Maintain MPG's written information security program consistent with GLBA Safeguards Rule requirements, including periodic risk assessments, service provider oversight, and regular reporting to executive leadership and the Board.
Support data inventories, data mapping, and records of processing, and conduct privacy and data protection impact assessments for new systems, products, vendors, and material changes.
Embed privacy-by-design principles—including data minimization, purpose limitation, and retention limits—into architecture reviews and the software development lifecycle.
Enable timely and secure fulfillment of consumer and data subject rights requests, including access, deletion, correction, and opt-out, with appropriate identity verification.
Ensure incident response plans address privacy breach notification obligations and timelines, including GDPR supervisory authority notification, GLBA Safeguards Rule notification, and state breach-notification laws.
Ensure vendor contracts include appropriate data processing terms, such as GDPR data processing agreements and cross-border transfer mechanisms, CCPA service-provider provisions, and GLBA safeguarding requirements.
Partner with Legal, Compliance, Data, and business leaders to establish and lead MPG's AI governance program, including:
AI acceptable-use policies and employee guidance
An inventory of AI use cases, models, and AI-enabled vendor products
Risk-tiering and approval processes for internal and third-party AI solutions
Controls governing the use of customer, personal, and confidential data in AI prompts, training, and outputs
This role will perform services for The MoneyPass Group, a company that is jointly owned by Fiserv and Bridgeport Partners. Your employment initially will be with Fiserv , and Fiserv will lease your services to The MoneyPass Group through December 31, 2026. As of January 1, 2027, employment with Fiserv will end and employment will transfer to The MoneyPass Group.
Salary Range
$127,500.00 - $204,000.00
These pay ranges apply to employees in Colorado, Hawaii, Illinois, Nevada, Rhode Island, Vermont and Washington. Pay ranges for employees in other states may differ.
For incentive eligible associates, the successful candidate is eligible for an annual incentive opportunity which may be delivered as a mix of cash bonus and equity awards in the Company’s sole discretion.
It is unlawful to discriminate against a prospective employee due to the individual's status as a veteran.
Thank you for considering employment with Fiserv. Please:
Apply using your legal name
Complete the step-by-step profile and attach your resume (either is acceptable, both are preferable).
Our commitment to Equal Opportunity:
Fiserv is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, gender, gender identity, sexual orientation, age, disability, protected veteran status, or any other category protected by law.
If you have a disability and require a reasonable accommodation in completing a job application or otherwise participating in the overall hiring process, please contact
AskHR.US@fiserv.com
. Please note our AskHR representatives do not have visibility to your application status. Current associates who require a workplace accommodation should refer to Fiserv’s Disability Accommodation Policy for additional information.
Note to agencies:
Fiserv does not accept resume submissions from agencies outside of existing
agreements. Please
do not send resumes to Fiserv associates. Fiserv is not responsible for any fees associated with unsolicited resume submissions.
Warning about fake job posts:
Please be aware of fraudulent job postings that are not affiliated with Fiserv. Fraudulent job postings may be used by cyber criminals to target your personally identifiable information and/or to steal money or financial information. Any communications from a Fiserv representative will come from a legitimate Fiserv email address.
---
Questions:
-
At Fiserv, we value integrity and transparency. As you complete your job application, please be aware that providing truthful, accurate, and complete information is essential. Any discrepancies, omissions, or falsehoods may result in the rejection of your application, withdrawal of any employment offer, or dismissal if you are already employed. Thank you for your commitment to maintaining the trust and integrity of our hiring process.
-
Are you currently or have you ever worked for Fiserv, First Data or any of their affiliates, subsidiaries or predecessors as an employee or contractor?
- No
- Yes
-
Are you of legal age to work in the United States?
- No
- Yes
-
Are you legally authorized to work in the United States?
- Yes
- No
-
Will you need Fiserv to sponsor you for a visa or otherwise provide support related to work authorization in order to work legally in the United States, either now or in the future? This includes, but is not limited to, candidates currently in F-1 Status with OPT or CPT work authorization and candidates who currently hold or will require employment-based work authorization sponsored by a U.S. employer (i.e. H-1B, TN, etc).
- Yes, I will require sponsorship now or in the future.
- No, I will not require sponsorship now or in the future.
-
Are you willing to work on-site? Please note that remote positions would not be required to work on-site.
- Yes, I am willing to work on-site.
- No, I am not willing to work on-site.
-
Are you currently within commuting distance to this work location? If you are not within commuting distance, are you willing to relocate? Please note that remote positions would not require relocation.
- Not applicable, I am within commuting distance.
- Yes, I am willing to relocate.
- No, I am not willing to relocate.
-
Client/Customer Employment Disclosure: Have you ever been employed by an organization (company/agency) that is a Fiserv or First Data client/customer? Note: Answering ‘Yes’ will not automatically disqualify you from working for Fiserv.
- Yes
- No
-
Do you have any relatives currently employed at Fiserv?
- No
- Yes
-
Are you a current or former United States Military Service Member or military spouse? (Please select all that apply)