Chief Information Security Officer - Klarna Bank USA

KlarnaNew York City, New YorkOn-siteFull-timeListed 43 minutes ago

Apply now

About this role

Klarna, briefly At Klarna, we're building an everyday finance network, helping over 120 million consumers across 26 countries save time and money, and worry less about their finances. Working here means taking on problems most companies never get to solve, and being hands-on enough that the interesting part of the work lands with you, not someone else — you'll build with AI, not watch it happen. This is the stretch zone. Come find out what you're capable of. About the role Klarna Bank USA operates as a regulated U.S. banking entity, which means its information security program answers not just to internal risk committees but to banking regulators and supervisory examination teams. As Chief Information Security Officer, Klarna Bank USA, you'll own that program end to end — the bank's cyber risk, its regulatory relationships, and how well it draws on Klarna's global Security organization without duplicating it. You'll be part of Klarna's global Security organization and report to the Group CISO. For matters relating to the U.S. bank entity, you'll also have a direct reporting and governance relationship with the Klarna Bank USA Chief Risk Officer. What you'll do You'll own the information security and cybersecurity program for Klarna Bank USA — governance, strategy, policies and standards; risk assessments and control oversight; and security requirements for products, services, and material technology changes. You'll lead identity and access security, cloud, infrastructure, and application security, data protection, and vulnerability and exposure management, along with security monitoring, detection, and response across the bank's environment. You'll own incident management and cyber resilience, third-party and intra-group technology risk, security testing and assurance, and security awareness and training, and report on all of it to the Board and senior management. You'll represent Klarna Bank USA to regulators and supervisory teams on information security and cybersecurity matters, and lead security-related regulatory examinations, reviews, and information requests. You'll turn regulatory observations and commitments into effective, sustainable control improvements, and keep the bank in continuous examination readiness rather than treating compliance as a periodic exercise. You'll connect Klarna Bank USA to the security capabilities Klarna operates group-wide, establishing clear accountability across entity and group boundaries and closing any gaps that are specific to the U.S. bank. You'll advise the Klarna Bank USA CRO, CEO, Board, and Group CISO on the bank's cyber risk profile, turning security concerns into concrete recommendations and escalating material issues as they arise. You'll move between Board-level discussions, regulatory meetings, architecture reviews, and significant security incidents, staying close to the substance of what you're accountable for. Who you are You've worked in cybersecurity, information security, or technology risk within U.S. banking or another regulated financial institution, and you've led or materially owned an information security program there — a background in a de novo bank, industrial bank, fintech, or bank charter process is especially relevant here. You've worked directly with U.S. banking regulators and regulatory examination teams, and you know what supervisory engagement looks like from the inside. You've presented cybersecurity risk to Boards, executive management, and regulators, and you can move between governance conversations and detailed technical discussions with the same audience. You understand modern cloud infrastructure, software engineering, and technology platforms well enough to assess the risk in them yourself. You've operated in an environment where important technology or control capabilities are owned by a parent company, affiliate, or shared service, and you know how to build clear accountability across that boundary. You can tell which risks are material and which are theoretical, and you act on that distinction instead of treating every finding the same way. You take ownership of problems proactively, build relationships across organizational boundaries without relying on hierarchy, and form your views from evidence rather than from what worked at your last organization. Things you should know before applying This position is based in Utah, or requires frequent business travel to Utah if you're based elsewhere in the U.S. Working together: we value co-located teams; most teams currently meet in the office 2–3 days per week, and this varies by team and can change over time. Non-obvious backgrounds are welcome. Diversity of skills, perspectives and backgrounds is how we create, innovate, and disrupt like no other. Final compensation will be based on the candidate's qualifications, skills, and experience.