Head of Security & Risk
This foundational individual contributor role reports to the Deputy COO and owns M0's information security and risk function from the ground up. The role spans enterprise risk management, compliance certification, security operations, incident response, ISMS documentation, security policies, partner due diligence, and security awareness across a crypto infrastructure company.
Responsibilities
- Build M0's enterprise risk program covering security, operational, regulatory, and counterparty risk.
- Maintain the risk register, annual assessments, scenario analyses, and escalation framework across entities.
- Own compliance posture across SOC 2, ISO 27001, and other applicable frameworks.
- Drive policy writing, auditor coordination, vendor risk, access reviews, and third-party SaaS evaluations.
- Keep the organization audit-ready and manage external security vendor relationships.
- Design and maintain incident response, ISMS documentation, security policies, and tabletop exercises.
- Serve as the primary contact for institutional partner security due diligence and questionnaires.
- Coordinate with Senior Counsel on information security representations in commercial agreements.
- Design and own security awareness training and build a proactive security culture.
Requirements
- 7–10 years of experience in information security, risk, GRC, or compliance operations.
- Preference for fintech, crypto infrastructure, or B2B SaaS backgrounds.
- Experience building a compliance certification program from scratch.
- End-to-end ownership of SOC 2 audits and ISO 27001 implementation or maintenance.
- Hands-on experience with Vanta, Drata, or equivalent GRC platforms.
- Experience with cloud security, AWS, and BCP/DR program design.
- Experience managing auditors, penetration testing firms, compliance vendors, evidence collection, and report production.
- Working understanding of AWS, GCP, and Azure, including security controls in DevOps and IaaS deployments.
- Preferred certifications include Cloud+, CySA+, CISSP, CISM, or CRISC.
- Familiarity with digital assets, stablecoins, blockchain infrastructure, smart contract security, or on-chain monitoring is advantageous.
Benefits
- Global team and flexibility to work remotely or from hub offices in NYC or Berlin.
- Comprehensive healthcare insurance coverage.
- Wellbeing allowance and gym membership.
- Customizable IT setup with high-quality equipment.
- Annual professional development budget.
- Opportunities to attend conferences and worldwide on-site company events.
- Base salary with equity or token grant, commensurate with experience.