Head of Information Security

September 16, 2026
Application ends: December 15, 2026

Job Description

REQUIREMENTS

  • 10+ years of Security and IT experience, including 3+ years leading a IT Security and GRC function (not solely IT operations) in a high-growth tech company, with demonstrated ownership of strategy, not just execution.
  • A demonstrated trajectory toward CISO: you have owned a security program end-to-end, presented to executives or boards, and can articulate the “why” behind every control you have implemented.
  • Experience securing or governing AI/LLM-enabled products or enterprise AI adoption including agentic systems and third-party model-provider risk, with an ability to apply privacy and data-protection laws and practices (e.g., GDPR, CCPA/CPRA) in the AI context.

Nice to have

  • 5+ years working in blockchain or a FinTech with an enterprise client base (e.g., financial services), including navigating rigorous third-party security diligence.

RESPONSIBILITES

  • Strategy, governance and budget: Set the strategic direction, multi-year roadmap, and risk posture of the Information Security Program; deliver on department OKRs; and own the IT and technology budget, with ultimate responsibility for technology procurement.
  • AI security and governance: Own the secure adoption of AI across the company: evolve our AI governance framework, review and approve AI tools and agentic workflows, and secure our agentic infrastructure (identity, least-privilege tool and data access, secrets handling, monitoring, auditability). Manage frontier model providers as critical vendors, covering security and data-handling diligence, retention and training-use commitments, DPAs and subprocessor flow-downs. Meet emerging obligations such as the EU AI Act, so we can make transparent, defensible commitments to enterprise customers about how our products and internal AI usage handle their data.
  • Compliance, audit and enterprise trust: Own our audit, certification, and attestation strategy and execution (penetration testing, SOC 2 Type 2, ISO/IEC 27001, successor frameworks) alongside internal security audits; run a third-party and vendor risk management program; and serve as the external face of our security program with customer security teams, regulated financial institutions, and auditors.
  • Privacy and data governance: Maintain a comprehensive data map of how data flows into, through, and out of the organization, including flows to model providers and through agentic workflows, with data classification, records of processing, and a vendor/subprocessor inventory. Own privacy compliance in partnership with Legal: GDPR, CCPA/CPRA, DPAs and contractual security commitments, and privacy-by-design reviews of new products and features.
  • Security operations and incident response: Own the incident response program end-to-end, including playbooks, tabletop exercises, post-incident reviews, and breach-notification obligations in partnership with Legal. Manage our bug bounty programs, and partner with development teams to embed security best practices in the SDLC and our software offerings.
  • IT and infrastructure: Oversee identity and access management, provisioning and onboarding/offboarding, end-user security (MDM, endpoint protection, security training), physical security, disaster recovery, business continuity, and data backup, using automation and AI-powered workflows to make IT and security operations scale faster than headcount.

Are you interested in this position?


Apply by clicking on the “Apply Now” button below!

#CrossChannelJobs #JobSearch
#CareerOpportunities #HiringNow
#Employment #JobOpenings
#JobSeekers

Related Jobs