обновлено 1 день назад
Head of Security & Risk (Stablecoins)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Head of Security & Risk (Stablecoins): Building M0’s information security, enterprise risk, and compliance function for infrastructure supporting branded stablecoins and regulated financial institutions with an accent on SOC 2, ISO 27001, risk management, and security operations. Focus on designing audit-ready programs, coordinating partner due diligence, establishing incident response and business continuity frameworks, and embedding security controls across cloud and DevOps environments.
Location: NYC or remote within the USA; ability to work multiple days per week from the main hub office in NYC is a plus.
provides shared infrastructure for businesses launching branded stablecoins and financial institutions operating issuance and on-chain liquidity solutions.
What you will do
- Build and own the enterprise risk management program covering security, operational, regulatory, and counterparty risk.
- Lead the SOC 2, ISO 27001, and other information security compliance certification workstreams.
- Establish incident response, ISMS, security policy, business continuity, and disaster recovery frameworks.
- Manage external auditors, penetration testing firms, security vendors, and compliance partners.
- Own institutional partner security due diligence, questionnaires, and reusable security documentation.
- Design security awareness training and promote a proactive security culture across business and technical teams.
Requirements
- 7–10 years of experience in information security, risk, GRC, or compliance operations.
- End-to-end ownership of a SOC 2 audit cycle and experience implementing or maintaining ISO 27001.
- Hands-on experience with GRC platforms such as Vanta or Drata, cloud security, and BCP/DR program design.
- Working knowledge of AWS, GCP, and Azure, including security controls in DevOps and IaaS environments.
- Experience managing auditors, penetration testing firms, compliance vendors, evidence collection, and report production.
- Preferred certifications include Cloud+, CySA+, CISSP, CISM, or CRISC.
Nice to have
- Experience with digital assets, stablecoins, blockchain infrastructure, smart contract security risk, or on-chain monitoring tools.
- Familiarity with GENIUS Act, MiCA, DORA, or other digital asset and financial services regulations.
- Experience working across a multi-entity structure.
- Familiarity with BlockAid, Chainalysis, or similar tools.
Culture & Benefits
- Flexible work from the USA remotely or from hubs in NYC and Berlin.
- Comprehensive healthcare insurance, wellbeing allowance, and gym membership.
- Customizable workspace and IT equipment.
- Annual professional development budget, conferences, and worldwide company events.
- Base salary with equity or token grant, commensurate with experience.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
7 дней назад
GRC/IT Compliance Analyst
108 000 - 130 000$
Plaid
1 день назад
Security Analyst, Third-Party Ecosystem Risk Management
119 000 - 176 000$
4 дня назад
Security Governance Risk & Compliance Analyst I (Cybersecurity)
49 729 - 73 130$
1 день назад
Head of Security and IT (AI)
3 дня назад
Principal Security GRC Analyst (FedRAMP)
150 000 - 200 000$
19 часов назад