Head of Security & Risk

Job not on LinkedIn

🕒 May 27

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of decircle

decircle

1 - 10 employees

Founded 2019

We partner with disruptive organizations to help identify and attract talent. A boutique recruitment agency that focuses on blockchain and web3. We enjoy networking with Web3 and decentralization enthusiasts and help them find their place in the decentralized world.

📋 Description

• Build M0’s enterprise risk program from scratch covering security, operational, regulatory, and counterparty risk, including the risk register, annual assessments, scenario analyses, and escalation framework across all entities. • Own M0's compliance posture across SOC 2, ISO 27001, and other applicable frameworks — driving all non-technical workstreams (policy writing, auditor coordination, vendor risk, access reviews, third-party SaaS vendor evaluations) and keeping the organization audit-ready at all times. • Design and maintain M0's incident response framework, ISMS documentation, and security policies — own external security vendor relationships, facilitate tabletop exercises covering IR, BCP, and DR scenarios, and drive the selection of a security advisory firm for on-call support. • Serve as M0's primary point of contact for institutional partner security due diligence and inbound security questionnaires, build and maintain the reusable documentation package for responding to partner requests, and coordinate with Senior Counsel on information security representations in commercial agreements. • Design and own M0's security awareness training program, ensure all employees understand their security obligations, and build a proactive security culture across engineering, operations, legal, and business teams.

🎯 Requirements

• 7–10 years of experience in information security, risk, GRC, or compliance operations, with meaningful ownership and a preference for fintech, crypto infrastructure, or B2B SaaS backgrounds. • Demonstrated track record of building a compliance certification program from scratch, in-depth knowledge of compliance and regulatory frameworks, including hands-on implementation of SOC 2, ISO 27001, CMMC, HIPAA, GDPR, NIST 800-53, etc. • Hands-on experience with GRC automation platforms (Vanta, Drata, or equivalent), cloud security environments (AWS preferred), and BCP/DR program design. • Proven experience managing external audit relationships end-to-end (including auditors, penetration testing firms, and compliance vendors) and navigating evidence collection and report production. • Working understanding of AWS, GCP, and Azure, including embedding security controls into DevOps workflows and Infrastructure as a Service (IaaS) deployments. • Preferred certifications: Cloud+, CySA+, CISSP, or CISM.

🏖️ Benefits

• Global team and flexibility: Join a truly global team with the flexibility to work remotely or from one of our hubs in NYC or Berlin. • Health and wellness: Enjoy comprehensive healthcare insurance coverage as well as a wellbeing allowance and gym membership to support your physical and mental health. • Customizable IT setup: Tailor your workspace with access to top-notch IT equipment. • Professional development: Benefit from an annual development budget to enhance your skills and grow professionally, including opportunities to participate in conferences and on-site company events worldwide.

Apply Now

Similar Jobs

🕒 May 27

PTC

5001 - 10000

🏢 Enterprise

Staff Product Security Engineer providing cyber security expertise for SaaS solutions at PTC. Responsible for security assessments, implementing technologies and guiding teams.

AWS

Azure

Cloud

Cyber Security

Google Cloud Platform

Java

JavaScript

Python

TypeScript

Go

🕒 May 27

Order.co

51 - 200

☁️ SaaS

💳 Fintech

🤝 B2B

Staff Security Engineer at Order.co driving security architecture and mentoring engineers. Overseeing technical improvements and complex security initiatives to protect company data.

🇺🇸 United States – Remote

💵 $180k - $220k / year

💰 $30M Series B - Order on 2022-01

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

AWS

Cloud

Linux

Postgres

Ruby

Ruby on Rails

🕒 May 27

Common Securitization Solutions

201 - 500

💸 Finance

💳 Fintech

🏠 Real Estate

Director leading Cyber Security Architecture and Engineering at U.S. Fin Tech. Overseeing design and execution while ensuring compliance to cyber security policies.

AWS

Cloud

Cyber Security

🕒 May 26

DDN

1001 - 5000

🤖 Artificial Intelligence

Principal Engineer responsible for defining security architecture strategy in high-performance data storage at DDN. Collaborating cross-functionally to embed security principles in distributed systems.

Cloud

Cyber Security

Distributed Systems

🕒 May 26

HubSpot

1001 - 5000

🤝 B2B

☁️ SaaS

Principal Software Engineer at HubSpot shaping detection engineering, threat intelligence, and incident response solutions for a secure platform. Leading automated detection systems and mentor engineers in best practices.

Cloud

Splunk