Head of Information Security
Job Description
REQUIREMENTS
- 10+ years of Security and IT experience, including 3+ years leading a IT Security and GRC function (not solely IT operations) in a high-growth tech company, with demonstrated ownership of strategy, not just execution.
- A demonstrated trajectory toward CISO: you have owned a security program end-to-end, presented to executives or boards, and can articulate the “why” behind every control you have implemented.
- Experience securing or governing AI/LLM-enabled products or enterprise AI adoption including agentic systems and third-party model-provider risk, with an ability to apply privacy and data-protection laws and practices (e.g., GDPR, CCPA/CPRA) in the AI context.
Nice to have
- 5+ years working in blockchain or a FinTech with an enterprise client base (e.g., financial services), including navigating rigorous third-party security diligence.
RESPONSIBILITES
- Strategy, governance and budget: Set the strategic direction, multi-year roadmap, and risk posture of the Information Security Program; deliver on department OKRs; and own the IT and technology budget, with ultimate responsibility for technology procurement.
- AI security and governance: Own the secure adoption of AI across the company: evolve our AI governance framework, review and approve AI tools and agentic workflows, and secure our agentic infrastructure (identity, least-privilege tool and data access, secrets handling, monitoring, auditability). Manage frontier model providers as critical vendors, covering security and data-handling diligence, retention and training-use commitments, DPAs and subprocessor flow-downs. Meet emerging obligations such as the EU AI Act, so we can make transparent, defensible commitments to enterprise customers about how our products and internal AI usage handle their data.
- Compliance, audit and enterprise trust: Own our audit, certification, and attestation strategy and execution (penetration testing, SOC 2 Type 2, ISO/IEC 27001, successor frameworks) alongside internal security audits; run a third-party and vendor risk management program; and serve as the external face of our security program with customer security teams, regulated financial institutions, and auditors.
- Privacy and data governance: Maintain a comprehensive data map of how data flows into, through, and out of the organization, including flows to model providers and through agentic workflows, with data classification, records of processing, and a vendor/subprocessor inventory. Own privacy compliance in partnership with Legal: GDPR, CCPA/CPRA, DPAs and contractual security commitments, and privacy-by-design reviews of new products and features.
- Security operations and incident response: Own the incident response program end-to-end, including playbooks, tabletop exercises, post-incident reviews, and breach-notification obligations in partnership with Legal. Manage our bug bounty programs, and partner with development teams to embed security best practices in the SDLC and our software offerings.
- IT and infrastructure: Oversee identity and access management, provisioning and onboarding/offboarding, end-user security (MDM, endpoint protection, security training), physical security, disaster recovery, business continuity, and data backup, using automation and AI-powered workflows to make IT and security operations scale faster than headcount.
Are you interested in this position?
Apply by clicking on the “Apply Now” button below!
#CrossChannelJobs #JobSearch
#CareerOpportunities #HiringNow
#Employment #JobOpenings
#JobSeekers