Chief Information Security Officer

Sofia, Sofia City Province, Bulgaria

Apply now Apply later

Dreаmix was founded 18 years ago by passionate IT students, who wanted to create the dreamiest workplace where everyone is heard, works under transparent management, and lives up to their full potential. Now, many years later, we deliver software solutions for renowned companies from Germany, the UK, Switzerland, and Silicon Valley. Dreamix provides quality software services and products for top enterprises around the world through Java and Web technologies.

We believe that the employer-employee relationship must be in the form of partnership not transaction. We are committed to investing as much as possible in our employees and we expect the same from you. Culture is what makes us different as we strongly believe in striving for mastery, teamwork, knowledge sharing, proactivity, a healthy lifestyle, and personal development.


As the Chief Information Security Officer (CISO) & Head of IT, you will be responsible for shaping, implementing, and overseeing the company’s cybersecurity strategy and practices, while also providing leadership and direction to the IT department. This position combines a robust knowledge of information security frameworks, risk management, and compliance requirements with strong management capabilities. You will ensure that the organization’s technical infrastructure and security posture meet both current and future business needs.



Responsibilities: 

1. Information Security Leadership

  • Develop and execute a comprehensive information security strategy and roadmap aligned with business objectives
  • Identify, evaluate, and recommend emerging hardware/software cybersecurity solutions to ensure that company security practices remain effective and up-to-date
  • Create and maintain security policies, procedures, and best practices; ensure they are clearly communicated and enforced across the company
  • Lead company-wide security awareness campaigns, develop training materials, and deliver regular security training sessions to promote a security-first culture
  • Analyze phishing attacks and other security incidents; coordinate response strategies, and implement improvements to prevent future risks
  • Manage and advance the company’s security certification efforts (including ISO 27001 and ISO 9001). Oversee audits, maintain documentation, and liaise with auditors and regulators as needed
  • Respond to security questionnaires from new and existing clients. Build and maintain relationships with cybersecurity service providers and industry partners
  • Work closely with the parent company’s security team to align security policies, share best practices, and collaborate on incident response

2. IT Department Oversight

The IT Department ensures the company’s technology infrastructure runs smoothly and securely. They install and maintain systems, troubleshoot technical issues, manage hardware and software resources, and coordinate with external service providers to optimize and protect the company’s tech environment.

  • Provide leadership and direction to the IT department, ensuring alignment with the company’s operational and business objectives
  • Prepare annual budgets for infrastructure, services, and improvements; allocate resources effectively to meet departmental goals
  • Have the technical expertise to understand the existing infrastructure and make informed decisions on enhancements, migrations (e.g., accounts, security software, cloud storage), and upgrades
  • Act as the key liaison between IT and other departments (Finance, Operations, Talents & Culture), ensuring smooth collaboration on projects and initiatives
  • Set clear priorities for the IT team; ensure that all incoming requests and ongoing projects are properly tracked, assessed, and executed
  • Build and maintain relationships with 3rd-party service providers; negotiate contracts and service-level agreements
  • Establish IT processes and procedures that uphold security standards while facilitating efficient operations


Main requirements:

  • Bachelor’s degree in Computer Science, Information Security, Information Technology, or a related field (Master’s degree preferred)
  • Relevant certifications such as CISM, CISSP, CISA, ISO 27001 Lead Implementer/Auditor, or similar are a plus
  • Proven experience (3+ years) in information security leadership roles, ideally within a software development or technology services organization
  • Demonstrated experience in managing a department or cross-functional team
  • Experience in leading security initiatives, obtaining security certifications, and maintaining compliance with relevant standards (ISO 27001, ISO 9001, etc.) is a plus 
  • Strong understanding of network and endpoint security, intrusion detection, vulnerability management, and incident response
  • Familiarity with cloud platforms, virtualization technologies, and modern infrastructure (e.g., AWS, Azure, Docker, Kubernetes)
  • Working knowledge of IT systems, hardware management, and infrastructure planning
  • Ability to analyze complex technical issues, propose practical solutions, and assess potential risks
  • Excellent people management skills; proven ability to build, mentor, and motivate high-performing people/teams
  • Strong communication and stakeholder management skills; able to explain complex security concepts to non-technical audiences
  • Adept at budget planning, resource allocation, and vendor negotiations
  • Fluent in English, both written and verbal
  • High attention to detail, strong analytical skills, and effective problem-solving abilities


What we offer:

  • A warm and supportive work environment where you can reach your full potential
  • Flexible working hours that allow you to balance your work and personal life
  • Opportunities for professional development, including certifications and training
  • Additional benefits for academic teaching and speaking engagements
  • Knowledge-sharing sessions where you can learn from our Dreamix team
  • Team and company-wide events that bring us together
  • Amazing week long summer office and winter office initiatives
  • Additional health insurance and dental allowance to ensure your well-being
  • Multisport card to encourage a healthy and active lifestyle
  • Office massages to help you relax and unwind

If you are interested, please send us your CV.

Thank you for applying!

Only shortlisted candidates will be contacted. The confidentiality of all applications is assured!

By applying for this job, you voluntarily agree and submit your personal information. Any personal data that you provide will be processed in strict confidentiality by Dreamix ltd. only for the purposes of selection and recruitment and will not be transferred to other data controllers unless required by law. It will be stored, processed, retrieved, and deleted in accordance with the GDPR.

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0

Tags: Audits AWS Azure CISA CISM CISO CISSP Cloud Compliance Computer Science Docker Endpoint security Finance GDPR Incident response Intrusion detection ISO 27001 Java Kubernetes Risk management Security strategy Strategy Teaching Vulnerability management

Perks/benefits: Career development Flex hours Health care Team events

Region: Europe
Country: Bulgaria

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.