Skip to content

Head of Cyber Fusion (all humans)

    • Vienna, Austria
  • Cyber Defense Center / Cyber Security

Job description

Make a difference in the financial life of millions of people: At Erste Digital you are co-creating the digital future, in which better financial health is possible. #believeinyourself


We are part of Erste Group – the largest banking group in Central and Eastern Europe with more than 2,500 branches and over 45,000 employees. Our more than 2,000 IT experts and enthusiasts are the bank's Digital Muscle.

Help shape the next generation of Cyber & Information Security at Erste Digital

We are evolving our security organization around clear missions, accountable services and stronger collaboration across domains. As Head of Department, you will shape the capability together with your teams and peers rather than inherit a fixed organizational blueprint. You will be accountable for outcomes, people leadership, service maturity and cross-Group value.

Your Mission

Shape the capabilities that detect and disrupt cyber threats and fraud early and respond with speed, context and automation, combining detection engineering, threat intelligence, incident response, fraud detection and response orchestration into one coherent operational capability. The scope spans employees, customers, identities, payments and digital services, with the aim of limiting operational impact and preventing avoidable financial loss. With PSD3/PSR increasing the focus on payment-fraud prevention, information sharing and preventive measures, anti-fraud detection and technical response should be treated as a strategic capability alongside classical cyber defense, in close cooperation with fraud and payment functions while business case decisions remain with the accountable business owners.

What you will shape and be accountable for

  • Set direction for threat and fraud detection, detection platforms, coverage engineering, cyber threat intelligence, incident response and technical fraud-prevention capabilities.

  • Continuously improve signal quality, detection coverage and response speed across endpoints, identity, network, cloud, applications, customer journeys and payment-related signals.

  • Drive automation of repeatable investigation, containment and fraud-response activities while preserving expert judgement where context, customer impact or financial consequences matter.

  • Build strong operational interfaces with preventive controls, exposure management, security validation, identity, major-incident coordination and the Group's fraud, payments and customer-protection stakeholders.

Group first - Built to scale beyond one entity

  • Think Group First: design every capability so it can be consumed across the Group where feasible, or at minimum produce reusable blueprints, patterns, standards and lessons that create value beyond Erste Digital.

  • Seek alignment with Group Security and relevant entities before creating local-only solutions where a shared approach is realistic.

  • Balance local delivery responsibility with the ambition to simplify, standardize and scale security capabilities across the Group.

What success looks like

  • Meaningful cyber threats and fraud patterns are detected earlier with actionable signal quality and fewer avoidable blind spots across employee and customer journeys.

  • Cyber incidents and technically detectable fraud cases are investigated, contained or disrupted consistently and quickly, helping to reduce operational impact and prevent avoidable financial loss.

  • Lessons from incidents, fraud cases, testing and threat intelligence systematically improve detection, preventive controls and automated response capability.

  • Detection, response and fraud-prevention capabilities and operating patterns can be consumed or replicated by Group entities where appropriate.

Who benefits from your work

Employees, customers, business owners, payment and fraud functions, IT operations, security teams and Group entities benefit from earlier detection, faster disruption and containment, and a more predictable response to both cyber incidents and fraud attempts - ultimately helping protect trust and reduce financial loss.

Job requirements

What you bring

  • Leadership experience in security operations, fraud prevention, incident response, detection engineering or another operational technology environment where rapid detection and response matter.

  • Solid understanding of modern SOC capabilities, telemetry, detection engineering, threat intelligence and response processes; experience with fraud analytics, payment-security or customer-protection capabilities is highly valuable but not a prerequisite.

  • Ability to stay effective under pressure and exercise sound judgement with incomplete information, balancing security, customer impact and financial consequences.

  • A strong improvement mindset: use incidents, fraud cases and operational data to make detection and response measurably better over time.

  • Ability to navigate ambiguity, build alignment across organizational boundaries and turn strategic intent into concrete delivery.

Leadership approach we value

We are looking for leaders who combine high standards with trust, candour and genuine interest in helping others succeed.

  • Servant leader: create clarity, remove obstacles and give people the space and trust to do their best work.

  • High standards, genuine support: set clear expectations, follow through on commitments and help people reach them.

  • Honest and elevating: give direct, respectful feedback, make achievements visible and create opportunities for others to grow and be recognized.

  • Expert without micromanaging: bring enough subject-matter depth to ask the right questions, coach and exercise sound judgement, while trusting specialists to own the technical detail.

  • Delivery oriented and willing to address difficult topics: turn concepts into measurable outcomes, exercise sound judgement when needed, address difficult topics early and question established approaches when they no longer serve the mission.

Click here to learn more about our Leadership Dimensions.

Why this role

  • You will have the opportunity to shape a major security and anti-fraud capability, influence how we protect employees, customers and the Group, and build an environment where strong specialists can take ownership, grow and deliver visible outcomes - including measurable reduction of operational and financial impact from successful attacks and fraud.

  • Employee benefits – Benefit from special conditions for financial services and insurances, supermarkets, clothing stores and many more.

  • Employee Referral Program – Become a talent scout for career opportunities in IT. We are rewarding every successful referral for Erste Digital

  • A competitive and performance-related salary dependent on your professional and personal qualifications is granted - the minimum wage for this position in accordance with the respective collective agreement is EUR 85.000,-- gross per year. But this is just a formality, we are more than happy to discuss your actual expectations.

In your motivational letter, please include the following two perspectives:
Briefly describe one concrete example of how you would make a local security capability valuable for the wider Group - as a shared service, blueprint, pattern or standard.
Reflect on one aspect of this role description you would deliberately challenge or refine, including why.

We look forward to receiving your application by 16. October. First-round interviews are planned for early November.

You do not need to match every point perfectly to be a strong candidate. If the mission resonates with you and you believe you can grow into parts of the scope, we encourage you to apply.


The way we are

Erste Group considers the diversity of its employees as key to innovation and success. As employer we are proud to offer everyone equal chances, irrespective of age, skin colour, religious belief, gender, sexual orientation or origin.

or

Apply with Linkedin unavailable