Назад
Company hidden
обновлено 1 день назад

Head of Security & Risk (Stablecoins)

Формат работы
remote (только USA)/hybrid
Тип работы
fulltime
Грейд
head
Английский
b2
Страна
US/Germany
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Head of Security & Risk (Stablecoins): Building M0’s information security, enterprise risk, and compliance function for infrastructure supporting branded stablecoins and regulated financial institutions with an accent on SOC 2, ISO 27001, risk management, and security operations. Focus on designing audit-ready programs, coordinating partner due diligence, establishing incident response and business continuity frameworks, and embedding security controls across cloud and DevOps environments.

Location: NYC or remote within the USA; ability to work multiple days per week from the main hub office in NYC is a plus.

hirify.global provides shared infrastructure for businesses launching branded stablecoins and financial institutions operating issuance and on-chain liquidity solutions.

What you will do

  • Build and own the enterprise risk management program covering security, operational, regulatory, and counterparty risk.
  • Lead the SOC 2, ISO 27001, and other information security compliance certification workstreams.
  • Establish incident response, ISMS, security policy, business continuity, and disaster recovery frameworks.
  • Manage external auditors, penetration testing firms, security vendors, and compliance partners.
  • Own institutional partner security due diligence, questionnaires, and reusable security documentation.
  • Design security awareness training and promote a proactive security culture across business and technical teams.

Requirements

  • 7–10 years of experience in information security, risk, GRC, or compliance operations.
  • End-to-end ownership of a SOC 2 audit cycle and experience implementing or maintaining ISO 27001.
  • Hands-on experience with GRC platforms such as Vanta or Drata, cloud security, and BCP/DR program design.
  • Working knowledge of AWS, GCP, and Azure, including security controls in DevOps and IaaS environments.
  • Experience managing auditors, penetration testing firms, compliance vendors, evidence collection, and report production.
  • Preferred certifications include Cloud+, CySA+, CISSP, CISM, or CRISC.

Nice to have

  • Experience with digital assets, stablecoins, blockchain infrastructure, smart contract security risk, or on-chain monitoring tools.
  • Familiarity with GENIUS Act, MiCA, DORA, or other digital asset and financial services regulations.
  • Experience working across a multi-entity structure.
  • Familiarity with BlockAid, Chainalysis, or similar tools.

Culture & Benefits

  • Flexible work from the USA remotely or from hubs in NYC and Berlin.
  • Comprehensive healthcare insurance, wellbeing allowance, and gym membership.
  • Customizable workspace and IT equipment.
  • Annual professional development budget, conferences, and worldwide company events.
  • Base salary with equity or token grant, commensurate with experience.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →