The second candidate dataset against the ICPs from report #5. After AML, this is the second most painful role: Brighty holds an EMI license and runs crypto custody, yet reopened the CISO req ×4 — the security function is still to be built. We assembled a vetted pool from fintech donors plus crypto exchanges (Coinbase, Kraken, Ledger — companies obsessed with custody and key security): exactly the expertise a crypto-fiat neobank needs. Not a raw list — data engineering built for the task: who, why now, and how we find them.
prepared 2026-06-28 · MEASURED · Outricher data
In report #5, CISO ranks among the hardest reqs (reopened ×4). For a crypto-fiat neobank with custody, security isn't "just another role" — it's a survival condition: a key compromise is game over. And Brighty has no security team yet — it needs both a leader (CISO / Head of Security) and an engineering core (AppSec, cloud security, infrastructure).
The best security expertise for a crypto-fiat product lives in two places: Brighty's fintech donors and crypto exchanges / custodians, where security is the core of the business. Below are 259 vetted specialists from these companies, by name and with contacts.
Current security specialists across 17 donor companies — Brighty's fintech peers plus crypto exchanges and custodians (Coinbase, Kraken, Binance, Ledger, Bitstamp…), where custody and key security are the core discipline. Geography where Brighty hires (EU/EEA + Switzerland + UK + UAE). An honest "floor" against the named set.
| Donor company (top 10) | Security core (current, in the hiring zone) |
|---|---|
| Revolut | 57 |
| N26 | 51 |
| Bitpanda | 20 |
| Binance | 18 |
| Bitstamp | 18 |
| Ledger | 18 |
| Crypto.com | 16 |
| Nexo | 15 |
| Coinbase | 14 |
| Blockchain.com | 11 |
| Total unique (17 donors) | 259 |
An honesty caveat: security talent among fintech donors is objectively thinner than AML (security people come from tech broadly). That's why the donor set is extended with crypto exchanges — this adds relevant depth, not padding. Geography is more distributed than in AML (leaders being the UK and Germany): security is remote-friendly and isn't tied to a license in a single country.
The best, but not necessarily the most expensive. The pool of 216 candidates breaks into two core tiers, each with its own hiring economics — plus 11 adjacent profiles (SOC / security analysts) kept separate. 45 + 160 + 11 = 216.
CISO, Head / Director of Security, Principal / Lead, Security Architect at licensed fintechs or crypto exchanges. Can stand up and lead Brighty's security function — build the processes from scratch. Of these, 28 already carry a CISO / Head of Security title. More expensive, but you're buying a ready-made leader, not potential.
| Candidate | Current role | Donor | Geo | Tenure in role | Score |
|---|---|---|---|---|---|
| Mirko Teroni, | CISO & DPO | Bitstamp | LU | 6 yrs | A+ 13.5 |
| Jan Urbanc | Head Of Security Operations | Bitstamp | Slovenia | 4.9 yrs | A+ 13.5 |
| Rick Mark | Staff Security Architect | Coinbase | Switzerland | 5.6 yrs | A+ 13.5 |
| Philip Edwards | CISO | Revolut | United Kingdom | 6.2 yrs | A+ 13.5 |
| Nathan Swain | Chief Information Security Officer | Binance | United Kingdom | 4.1 yrs | A+ 13.5 |
| Mark Lechner | CISO | Bitpanda | Germany | 4.8 yrs | A+ 13.5 |
| Milan Velev | Chief Information Security Officer | Nexo | Bulgaria | 5.2 yrs | A+ 13.5 |
| Marc W. | VP of Security | TransferGo | United Kingdom | 3.7 yrs | A+ 12.5 |
Top of the funnel — real people from the dataset, not a hypothesis.
Security Engineer, AppSec, cloud security, InfoSec specialists trained at a tier-1 fintech / crypto exchange, but "a step below Head." Far cheaper than senior, trained to the standards of companies where security is the core. For Brighty, this is the engineering core of the future security team; a strong middle, hired well, grows into Lead / Head within the role.
| Candidate | Current role | Donor | Geo | Tenure in role | Score |
|---|---|---|---|---|---|
| Mustafa Issabayev | Senior Security Engineer | Bitstamp | Germany | 4.1 yrs | A 11.5 |
| David Petek | Senior Application Security Engineer | Bitstamp | Slovenia | 4.7 yrs | A 11.5 |
| Deepak Singh Pawar | Senior Security Engineer | Blockchain.com | United Kingdom | 3.2 yrs | A 11.5 |
| Aditya Chaudhary | Senior Security Engineer | Blockchain.com | United Kingdom | 4.9 yrs | A 11.5 |
| Aurelijus Stuknys | Information Security, Revolut Bank Europe & Revolut Insurance Europe | Revolut | Lithuania | 5.2 yrs | A 11.5 |
| Aidan Bracher | Senior Security Engineer (Security Operations) | Revolut | United Kingdom | 3.8 yrs | A 11.5 |
| Muhammet TEKBIÇAK | Senior IT Security Engineer | Bitpanda | Austria | 4.8 yrs | A 11.5 |
| Boryana Kulinska | Senior Information Security Analyst | Nexo | Bulgaria | 4.5 yrs | A 11.5 |
CAVEAT: the middle covers engineering roles (AppSec / cloud / infra security), but not the CISO seat — the leader requires Tier A. Don't mix them in one funnel.
SOC engineers and security analysts — next to the function, but not its core. In the dataset they're tagged separately so they don't blend into the target funnels A and B. Included for a complete picture of the pool.
Readiness to move is detected structurally from career data.
111 of 216 have been in their current role ≥3 years. At a large exchange/bank a security engineer is a cog in a big machine; at Brighty the same person builds the function from scratch, with direct impact and a path to Head. The strongest pull trigger for an ambitious security professional.
114 already work at a crypto exchange / custodian: wallets, HSM, key management, on-chain threats. For Brighty that's a precise fit — they don't need to retrain for crypto specifics.
47 come from Revolut, where Brighty's team has already sourced from. Outreach with the reference "your former colleague is already here" removes the trust barrier toward a young company.
Security isn't tied to a local license — candidates span the whole EU (leaders: the UK, Germany). Brighty can hire the best without demanding relocation to Vilnius; 7 are already in Lithuania for those who value presence at HQ.
By function within the pool — a structured funnel from leader to engineer.
| Function | People | Share |
|---|---|---|
| Security Engineer / InfoSec specialist | 122 | 56% |
| Senior Security Engineer / AppSec | 38 | 18% |
| Security leadership (CISO / Head / Director) | 28 | 13% |
| Principal / Lead / Security Architect | 17 | 8% |
| Adjacent (SOC / security analyst / ops) | 11 | 5% |
The full dataset: JSONL / CSV / Excel + ready-made segments. Each profile — career depth, education, skills, location, contacts (where available), score and tier.
| Quality metric | Value |
|---|---|
| Profiles in the dataset | 216 |
| Fields per profile (min · avg · max · union) | 91 · 133 · 146 · 148 |
| Ready for outreach | 100% |
| Email (combined) | 47.2% (102) |
| Hot A+/A | 93 |
Email and phone come only from verified sources; where there's none, the value is NULL — we don't fabricate contacts.
This is a sample for any of the 6 roles from report #5. AML/MLRO and CISO are already done; next up — finance, UX, support, analytics. Name the role and tier — we'll assemble the dataset in the same format.
Tell us your target company or ICP and we'll deliver the dataset + a short analysis in the same format.