Skip to content
← All Web3 jobs

Head of Security & Risk

Confidential Web3 company

NYCHybrid$250k to $300k
About the Company We are the shared infrastructure where businesses launch their own branded stablecoins and financial institutions power them. Built on a common standard, every stablecoin on our platform is interoperable and liquid from day one — giving businesses programmable control over how money moves in their ecosystems, and giving financial institutions the most advanced issuance stack in the industry. About the Role We are seeking a sharp, execution-focused Head of Security & Risk to build and own the information security and risk function from the ground up. This is a foundational IC role at a critical inflection point — we are onboarding regulated institutional partners, expanding on-chain liquidity solutions, and operating infrastructure that regulated entities depend on. The information security and risk posture we establish in the next 12 months will define how we are perceived by partners, regulators, and institutional investors for years to come. Reporting to the Deputy COO, you will be our first dedicated information security and risk professional — responsible for building the enterprise risk management program, owning the information security compliance certification roadmap, establishing the security operations framework, and responding to partner security due diligence requests. You will work daily across engineering, product, legal, BD, and operations to ensure our security posture is proactive, documented, and defensible. Key Responsibilities - Build and Own Enterprise Risk Management: Build the enterprise risk program from scratch. Cover security, operational, regulatory, and counterparty risk — including the risk register, annual assessments, scenario analyses, and escalation framework across all entities. - Own the Information Security Compliance Certification Program: Own the compliance posture across SOC 2, ISO 27001, and other applicable frameworks — driving all non-technical workstreams (policy writing, auditor coordination, vendor risk, access reviews, third-party SaaS vendor evaluations) and keeping the organization audit-ready at all times. - Establish the Information Security Operations Framework: Design and maintain the incident response framework, ISMS documentation, and security policies — own external security vendor relationships, facilitate tabletop exercises covering IR, BCP, and DR scenarios, and drive the selection of a security advisory firm for on-call support. - Own Partner Information Security Due Diligence: Serve as the primary point of contact for institutional partner security due diligence and inbound security questionnaires. Build and maintain the reusable documentation package for responding to partner requests, and coordinate with Senior Counsel on information security representations in commercial agreements. - Build Information Security Awareness & Culture: Design and own the security awareness training program, ensure all employees understand their security obligations, and build a proactive security culture across engineering, operations, legal, and business teams. Requirements - 7–10 years of experience in information security, risk, GRC, or compliance operations, with meaningful ownership; preference for fintech, crypto infrastructure, or B2B SaaS backgrounds - Demonstrated track record of building a compliance certification program from scratch; in-depth knowledge of SOC 2, ISO 27001, CMMC, HIPAA, GDPR, NIST 800-53, etc. - Hands-on experience with GRC automation platforms (Vanta, Drata, or equivalent), cloud security environments (AWS preferred), and BCP/DR program design - Proven experience managing external audit relationships end-to-end, including auditors, penetration testing firms, and compliance vendors - Working understanding of AWS, GCP, and Azure, including embedding security controls into DevOps workflows and IaaS deployments - Preferred certifications: Cloud+, CySA+, CISSP, or CISM Nice to Have - Crypto-native familiarity: knowledge of digital assets, stablecoins, or blockchain infrastructure, including smart contract security risk and on-chain monitoring tools (BlockAid, Chainalysis, or similar) - Regulatory exposure: familiarity with GENIUS Act, MiCA, DORA, or other emerging digital asset and financial services regulatory frameworks - Multi-entity experience: prior experience operating across a multi-entity structure (US operating entity, Cayman HoldCo, Swiss Foundation, or equivalent) Location New York City — ability to work multiple days per week in our NYC hub. Compensation & Benefits - Competitive base salary with equity/token grant commensurate with experience - Comprehensive healthcare insurance coverage plus wellbeing allowance and gym membership - Customizable IT setup with access to top-notch equipment - Annual professional development budget including conferences and company events - Global team with flexibility to work remotely or from hubs in NYC or Berlin
Apply on Deciml

Deciml matches Web3 professionals to roles with AI, free for candidates.