обновлено 18 дней назад
Head of Security & Risk (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Head of Security & Risk (Fintech): Building M0’s enterprise information security, risk, and compliance function for stablecoin and financial infrastructure with an accent on SOC 2, ISO 27001, audit readiness, and institutional partner due diligence. Focus on designing risk management and security operations frameworks, coordinating audits and vendors, and establishing incident response, business continuity, and security awareness programs.
Location: NYC or remote within the USA; ability to work multiple days per week from the main hub office in NYC is preferred.
Company
provides shared infrastructure for businesses launching branded stablecoins and financial institutions powering them.
What you will do
- Build and own the enterprise risk management program covering security, operational, regulatory, and counterparty risk.
- Lead the information security compliance certification roadmap across SOC 2, ISO 27001, policies, vendor risk, access reviews, and audits.
- Design the incident response, ISMS, business continuity, disaster recovery, and security policy frameworks.
- Manage external security vendors, auditors, penetration testing firms, compliance providers, and tabletop exercises.
- Own institutional partner security due diligence, security questionnaires, reusable evidence packages, and security representations in commercial agreements.
- Build the security awareness training program and embed a proactive security culture across the organization.
Requirements
- 7–10 years of experience in information security, risk, GRC, or compliance operations.
- End-to-end experience building compliance certification programs and completing SOC 2 audits and ISO 27001 implementations or maintenance.
- Hands-on experience with GRC automation platforms such as Vanta or Drata, cloud security environments, and BCP/DR program design.
- Working knowledge of AWS, GCP, and Azure, including security controls in DevOps and IaaS environments.
- Experience managing auditors, penetration testing firms, compliance vendors, evidence collection, and report production.
- Ability to work multiple days per week in the NYC hub office is preferred.
Nice to have
- Security certifications such as CISSP, CISM, CRISC, Cloud+, or CySA+.
- Experience with digital assets, stablecoins, blockchain infrastructure, smart contract security risk, or on-chain monitoring tools.
- Knowledge of the GENIUS Act, MiCA, DORA, or other digital asset and financial services regulations.
- Experience operating across multi-entity structures.
Culture & Benefits
- Remote work or access to hubs in NYC and Berlin within a global team.
- Competitive base salary with equity or token grant.
- Comprehensive healthcare insurance, wellbeing allowance, and gym membership.
- Customizable IT equipment and workspace setup.
- Annual professional development budget, conference opportunities, and worldwide company events.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
GRC Security Analyst (AI Governance)
114 000 - 139 000$
Robinhood
5 дней назад
Security Risk Management Intern (AI)
42 - 42$
9 дней назад
Senior GRC Program Manager (Fintech)
3 дня назад
IT Risk and Compliance Analyst
80 000 - 90 000$
5 дней назад
Information Security Co-op (AI/Cybersecurity)
21 - 25$
Asana
10 дней назад
Security Risk Manager (Cybersecurity)
194 000 - 220 000$