×
Register Here to Apply for Jobs or Post Jobs. X

Head of Security & Risk

Job in Ithaca, Tompkins County, New York, 14850, USA
Listing for: mLabs
Full Time position
Listed on 2026-09-26
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 200000 - 250000 USD Yearly USD 200000.00 250000.00 YEAR
Job Description & How to Apply Below

Location:

Remote - US Remote (Preference for NYC based candidates) Remote| Full-time Compensation:$200K - $250K

Our client operates shared financial infrastructure designed to enable businesses and institutional partners to launch and manage branded stable coins and advanced digital asset issuance stacks. The platform provides fully interoperable, liquid on-chain solutions that grant businesses programmable control over payment ecosystems while meeting the stringent operational demands of regulated financial institutions.

To support rapid growth and expanding institutional partnerships, our client is seeking a sharp, execution-focused Head of Security & Risk
. This is a foundational, individual contributor (IC) role at a critical inflection point for the organization. In this position, the Head of Security & Risk will build and own the information security and enterprise risk management functions from the ground up.

Reporting directly to the Deputy Chief Operating Officer, the individual will serve as the organization's primary security authority—establishing the enterprise risk framework, driving information security compliance, leading incident response and security operations, and managing institutional due diligence requests. This role requires close collaboration across engineering, product, legal, business development, and operations teams to ensure a proactive, audit-ready, and defensible security posture.

Key Responsibilities:
  • Build and Own Enterprise Risk Management (ERM): Design and execute an enterprise risk management program from scratch. Oversee security, operational, regulatory, and counter party risks, including maintaining the risk register, leading annual risk assessments, performing scenario analyses, and establishing an escalation framework across all legal entities.
  • Lead Information Security Compliance &

    Certifications:

    Drive the compliance certification roadmap across frameworks such as SOC 2 and ISO 27001. Direct non-technical work streams, including policy drafting, auditor coordination, vendor risk evaluations, third-party SaaS reviews, and periodic access reviews to maintain continuous audit readiness.
  • Establish Security Operations & Response Frameworks: Design and maintain the Information Security Management System (ISMS), security policies, and incident response frameworks. Manage external security vendor relationships, lead tabletop exercises across Incident Response (IR), Business Continuity Planning (BCP), and Disaster Recovery (DR) scenarios, and select external security advisory firms for on-call support.
  • Manage Partner Information Security Due Diligence: Act as the primary point of contact for institutional partner security due diligence and inbound questionnaires. Build and maintain a reusable compliance documentation package and collaborate with legal counsel on security representations within commercial agreements.
  • Drive Information Security Culture & Awareness: Develop and own the security awareness training curriculum across all departments. Promote a proactive security culture across engineering, product, legal, and operational units.
Qualifications
  • Experience: 7–10 years of progressive experience in information security, risk management, GRC, or compliance operations, ideally within fintech, digital asset/crypto infrastructure, or B2B SaaS sectors.
  • Compliance Expertise: Demonstrated track record of building compliance programs from the ground up, including direct, hands-on ownership of full SOC 2 audits and ISO 27001 implementation/maintenance.
  • Technical & GRC Tooling: Hands‑on experience with modern GRC automation platforms (e.g., Vanta, Drata), cloud environments (AWS preferred), and infrastructure security integration within Dev Ops/IaaS workflows.
  • Vendor &…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary