wagey.ggwagey.gg
38,923  jobs38,923  jobs
Browse Tech JobsCompaniesFeaturesPricingFAQs
Log InGet Started Free
Jobs(38,923)/Head of Security Role(33)/M0 (5) - Head of Security & Risk
M0

M0 - Head of Security & Risk

Remote - USA+ Equity1w ago
RemoteDirectorNACryptocurrencyFintechHead of SecurityAuditorB2BTechnical WritingProgram ManagementReportingAWSAzureGCPDocumentationDue DiligenceCircomRisk Management

Requirements

• 7–10 years of experience in information security, risk, GRC, or compliance operations, with meaningful ownership and a preference for fintech, crypto infrastructure, or B2B SaaS backgrounds. • Demonstrated track record of building a compliance certification program from scratch, in-depth knowledge of compliance and regulatory frameworks, including hands-on end-to-end ownership of a full SOC 2 audit cycle, ISO 27001 implementation/maintenance, etc. • Hands-on experience with GRC automation platforms (Vanta, Drata, or equivalent), cloud security environments (AWS preferred), and BCP/DR program design. • Proven experience managing external audit relationships end-to-end (including auditors, penetration testing firms, and compliance vendors) and navigating evidence collection and report production. • Working understanding of AWS, GCP, and Azure, including embedding security controls into DevOps workflows and Infrastructure as a Service (IaaS) deployments. • Preferred certifications: Cloud+, CySA+, CISSP, or CISM. • A Proactive Risk Thinker: You think in terms of likelihood, impact, and mitigation, and you reason from first principles when regulations are unclear, translating complex risk into clear, business-relevant language. • A Proactive Risk Thinker: • Exceptionally Organized and Process-Driven: You maintain rigorous documentation, evidence records, and program trackers across concurrent workstreams. Your outputs need to be right and audit-ready at all times, and you have a track record of improving processes, not just running them. • Exceptionally Organized and Process-Driven • A Builder with High Ownership: You are a self-starter with a "no job too big, no job too small" mentality. You look around corners to creatively solve problems and have a proven ability to own projects from concept to finish. • A Builder with High Ownership • An Excellent Communicator & Partner: You build trust across engineering, legal, product, and business by speaking their language, embedding compliance as a shared operating principle rather than an external checkpoint, and getting things done through influence rather than authority. • An Excellent Communicator & Partner • Adaptable and Intellectually Curious: You have a positive attitude, comfort with ambiguity, and a relentless curiosity about new technologies. You have a passion for or a strong interest in crypto, blockchain technologies, and DeFi. • Adaptable and Intellectually Curious • Security Certifications: Professional certifications in security risk management such as CISSP, CISM, or CRISC are preferred. • Security Certifications • Crypto-Native Familiarity: Familiarity with digital assets, stablecoins, or blockchain infrastructure, including smart contract security risk and on-chain monitoring tools (BlockAid, Chainalysis, or similar). • Crypto-Native Familiarity • Regulatory Exposure: Familiarity with GENIUS Act, MiCA, DORA, or other emerging digital asset and financial services regulatory frameworks and their security and compliance implications. • Regulatory Exposure • Multi-Entity Experience: Prior experience operating across a multi-entity structure (US operating entity, Cayman HoldCo, Swiss Foundation, or equivalent) is a plus. • Location: Ability to work multiple days a week in our main hub office in NYC. • Location

Responsibilities

• Build and Own Enterprise Risk Management: Build M0’s enterprise risk program from scratch. Cover security, operational, regulatory, and counterparty risk, including the risk register, annual assessments, scenario analyses, and escalation framework across all entities. • Build and Own Enterprise Risk Management • Own the Information Security Compliance Certification Program: Own M0's compliance posture across SOC 2, ISO 27001, and other applicable frameworks — driving all non-technical workstreams (policy writing, auditor coordination, vendor risk, access reviews, third-party SaaS vendor evaluations) and keeping the organization audit-ready at all times. • Own the Information Security Compliance Certification Program • Establish the Information Security Operations Framework: Design and maintain M0's incident response framework, ISMS documentation, and security policies — own external security vendor relationships, facilitate tabletop exercises covering IR, BCP, and DR scenarios, and drive the selection of a security advisory firm for on-call support. • Establish the Information Security Operations Framework • Own Partner Information Security Due Diligence: Serve as M0's primary point of contact for institutional partner security due diligence and inbound security questionnaires, build and maintain the reusable documentation package for responding to partner requests, and coordinate with Senior Counsel on information security representations in commercial agreements. • Own Partner Information Security Due Diligence • Build Information Security Awareness & Culture: Design and own M0's security awareness training program, ensure all employees understand their security obligations, and build a proactive security culture across engineering, operations, legal, and business teams. • Build Information Security Awareness & Culture

Benefits

• Competitive compensation (base salary with equity/token grant) commensurate with experience. • Global team and flexibility: Join a truly global team with the flexibility to work remotely or from one of our hubs in NYC or Berlin. • Health and wellness: Enjoy comprehensive healthcare insurance coverage as well as a wellbeing allowance and gym membership to support your physical and mental health. • Customizable IT setup: Tailor your workspace with access to top-notch IT equipment. • Professional development: Benefit from an annual development budget to enhance your skills and grow professionally, including opportunities to participate in conferences and on-site company events worldwide.

Apply in one click

Upload My Resume

Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT

Apply in One Click
Apply in One Click

Similar roles

MasabiMasabi - Head of Security & Compliance1mo ago
·Remote - Canada·$520k - $520k/year
RemoteNADirectorFintechSoftwarePaymentsHead of SecurityAuditorGovernance
KrakenKraken - Senior SOX Auditor – Business Process Controls1mo ago
·Remote - Canada·$104k - $104k/year
RemoteNASeniorCryptocurrencyFintechAuditorReportingFinancial ReportingClose
Akoya ExternalAkoya External - Head of Risk & Security3mo ago
·Remote - in Boston, New York, Raleigh Areas
RemoteNADirectorBankingFintechHead of SecuritySystems AdministratorTeam ManagementAWSRisk ManagementGovernanceCircom
BPM LLPBPM LLP - Assurance Senior / Audit Senior (US Clients)2mo ago
·Remote - Canada·$94k - $115k/year + Equity
RemoteNASeniorFintechLife SciencesAuditorCPAReportingFinancial ReportingRisk Management
Valon TechValon Tech - Head of Security GRC1mo ago
·Remote - United States·$190k - $250k/year + Equity
RemoteNADirectorFintechCybersecurityHead of SecurityData GovernanceRecords ManagementRisk ManagementPrivacy ComplianceGovernance
Grafana LabsGrafana Labs - Director of Internal Audit | United States | Remote2mo ago
·Remote - United States (Remote)·$220k - $270k/year
RemoteNADirectorCybersecurityData AnalyticsAuditorReportingRisk ManagementGovernanceData QualityRisk Assessment
OKXOKX - CISO Office - Security Compliance & Governance Engineer1w ago
·Hong Kong, Hong Kong SAR; Singapore, Singapore
In OfficeAPACC-levelCryptocurrencyFintechCISOAuditorDocumentationReportingAWSGCPAlibaba CloudRisk ManagementMandarinCircomGovernance
RainRain - CISO5mo ago
·Remote - New York, NY, USA·$200k - $270k/year + Equity
RemoteNAC-levelFintechLife InsurancePaymentsInsuranceCISOAuditorRisk ManagementB2BGovernanceReporting
LuminDigitalLuminDigital - Lead, Audit and Assurance1mo ago
·Remote - USA·$27k - $27k/year
RemoteNAStaffBankingFintechAuditorSmart Contract AuditorControllerDocumentationProspectingAWSAzureGCP

Browse more by category

Show 33 moreHead of SecurityShow 132 moreAuditorShow 3,254 moreB2BShow 396 moreTechnical WritingShow 1,035 moreProgram ManagementShow 8,372 moreReportingShow 3,747 moreAWSShow 1,615 moreAzureShow 1,526 moreGCPShow 5,632 moreDocumentation
Privacy·Terms··Contact·FAQ·Wagey on X