Head of Security & Risk (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Head of Security & Risk (Fintech/Web3): Establishing the enterprise risk management and information security function from the ground up for a stablecoin infrastructure platform with an accent on compliance certifications and institutional risk frameworks. Focus on building SOC 2/ISO 27001 roadmaps, designing security operations frameworks, and managing institutional partner due diligence.
Location: Remote, USA or hybrid in New York City
Company
provides shared infrastructure for businesses to launch branded stablecoins and financial institutions to power them.
What you will do
- Build and own the Enterprise Risk Management program covering security, operational, and regulatory risks.
- Drive the Information Security Compliance Certification roadmap, including SOC 2 and ISO 27001.
- Design and maintain the security operations framework, incident response plans, and ISMS documentation.
- Manage institutional partner security due diligence and respond to complex security questionnaires.
- Develop and lead the company's security awareness training and internal security culture.
Requirements
- 7–10 years of experience in information security, risk, GRC, or compliance operations.
- Proven track record of implementing SOC 2, ISO 27001, or similar regulatory frameworks from scratch.
- Hands-on experience with GRC automation platforms (e.g., Vanta, Drata) and AWS cloud environments.
- Experience managing external audits, penetration testing firms, and compliance vendors.
- Must be based in the USA.
Nice to have
- Professional certifications such as CISSP, CISM, or CRISC.
- Familiarity with digital assets, stablecoins, and blockchain infrastructure.
- Knowledge of emerging regulations like MiCA, DORA, or the GENIUS Act.
- Experience with multi-entity corporate structures.
Culture & Benefits
- Flexibility to work remotely or from hubs in NYC or Berlin.
- Comprehensive healthcare insurance, wellbeing allowance, and gym membership.
- Customizable IT equipment and professional development budget.
- Opportunities to attend worldwide conferences and on-site company events.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →