Head of Security

Morpho Labs

Paris

Sur place

EUR 90 000 - 130 000

Plein temps

14 jours+

Recevez plus de réponses des employeurs

Envoyez un CV adapté au poste en quelques minutes.

Avantages offerts par ce poste

Fair, top-tier compensation
Real flexibility
Great health coverage
Support for continuous learning

Résumé du poste

Morpho Labs in Paris is seeking a Head of Security to define and drive the security strategy across corporate and IT domains. You will lead the security function while staying hands-on with critical tasks. The ideal candidate has over 10 years in security, particularly within fintech or crypto/web3 sectors.

This role comes with competitive compensation, flexibility, and strong support for personal growth. You'll need excellent communication skills and experience with incident response, certifications, and team leadership.

Qualifications

  • 10+ years in security, ideally in fintech or crypto/web3.
  • Experience in building or leading a security function.
  • Hands-on technical expertise across cloud and infrastructure security.

Responsabilités

  • Own and evolve Morpho's security strategy.
  • Build and lead the security function.
  • Execute critical security work while the team scales.

Connaissances

10+ years in security
Strong grasp of crypto/web3 threat model
Proven experience building a security team
Technical expertise across multiple security domains
Experience with incident response
Taken an organization through certifications
Exceptional communication skills

Description du poste

Everyone has the potential to build something great for the world. But fulfilling that ambition almost always requires more: people willing to trust you with their capital. Yet access to capital still depends on where you live, who you know, and which institutions are willing to trust you. Even when capital is available, it sits fragmented across disconnected networks and hidden behind intermediaries. The result is a system that fails most of the people it should serve. Borrowers overpay. Lenders earn less than they should. Many are shut out entirely, not because they are unworthy of credit, but because today's infrastructure was never built to connect them. Morpho exists to solve this. Full article here .

Location

Paris or remote (from -5h GMT up to +2h GMT to ensure sufficient overlap with the rest of the team).

Role

As Head of Security, you'll define and drive Morpho's security strategy across the entire organization - corporate and IT, cloud and infrastructure, application, supply chain, identity, incident response, threat intelligence, and counterparty security - and you'll build the team and function to deliver it. This is a hands-on leadership role: in the early days you'll personally do the work while you hire, and you'll stay close enough to the technical detail to earn the trust of a deeply technical organization. You'll also be Morpho's credible security voice, internally to leadership, and externally to the integrators, institutions, and ecosystem partners who depend on us. You'll partner closely with Engineering on infrastructure and deployment integrity, and with our Integration team, which works with various partners across the Morpho ecosystem.

Responsibilities
  • Own and continuously evolve Morpho's security strategy and roadmap across corporate, cloud/infrastructure, application, supply-chain, identity, and operational security.
  • Build and lead the security function - hire, grow, and develop the team, recruiting skillsets across security operations and application security.
  • Stay hands-on. Personally execute critical security work - threat modeling, architecture review, control implementation, and incident command - while the team scales.
  • Set the governance architecture: a coherent security framework that ties tooling and controls together, rather than accumulating tools in isolation.
  • Own incident response end to end - runbooks, incident command, severity and escalation structure, and market communication during an event.
  • Build and run a counterparty security program for curators and partners - identity verification, screening, operational diligence, and bidirectional incident-coordination channels.
  • Lead Morpho's certification strategy (e.g. SOC 2, ISO 27001), meeting both the spirit and the letter sustainably.
  • Represent Morpho's security posture externally - to fintechs, financial institutions, and the broader ecosystem - and internally to executives.
  • Partner cross-functionally with Engineering, Protocol, and Integrations, driving security outcomes through both direct ownership and influence.
What Success Looks Like
First 30 Days
  • You've built a clear, independent picture of Morpho's posture, architecture, threat model, and in-flight work - and pressure-tested the existing strategy against it.
  • You've met the team and established working relationships with the people who own the surfaces you'll most depend on.
  • You understand the path-to-funds attack surface in depth and have an early, evidence-based view of the highest-severity risks and quick wins.
  • You know exactly where incident-response readiness stands today.
First 60 Days
  • You've published a clearly prioritized security roadmap with clear sequencing, owners, and the rationale for what's deferred and aligned leadership behind it.
  • You've defined the team build-out plan and opened the first hire.
  • You're personally driving the top-severity gaps - identity and authentication enforcement, deployment guardrails, and a documented incident-response runbook among them.
  • You've set the governance framework and the certification path in motion.
First 90 Days
  • Demonstrable progress closing the highest-priority gaps, with key controls enforced rather than optional.
  • A documented incident-response capability that's been validated by at least one tabletop exercise.
  • Hiring underway, and a clear operating rhythm established with Engineering, Protocol, and Integrations.
  • Morpho's external security posture is taking shape - trust surface, counterparty security program, and ecosystem engagement - and you're recognized internally and externally as Morpho's credible security voice.
Must-have Experience & Skills
  • 10+ years in security, several of them building or leading a security function, ideally at a crypto/web3, fintech, or financial-services company where security is core to the business.
  • Strong grasp of the crypto/web3 threat model
  • Proven experience building and growing a security team from a small base, recruiting across security operations and application/infrastructure security.
  • Deep, hands-on technical expertise across cloud, infrastructure, CI/CD, supply-chain, identity, and application security - you do the work, not just direct it.
  • Owned incident response end to end, including incident command and external communication.
  • Taken an organization through certifications (SOC 2, ISO 27001, or equivalent)
  • Sharp prioritization and the ability to galvanize action through hard and soft influence, including driving outcomes through teams you don't own.
  • Exceptional, organized, responsive communication - credible to executives and to external audiences from fintechs to Fortune 500 institutions.
  • Humble.
Nice to Have
  • An established network and public profile in the security or crypto-security community, and comfort representing security work publicly (talks, writing, framework contribution).
  • Offensive security depth, or experience standing up red/blue capabilities.
  • Familiarity with institutional and regulatory expectations and threat-sharing networks (e.g. Crypto ISAC, TIBER-style frameworks).

We design benefits around deep work and growth, so you can do the best work of your career. Expect fair, top-tier compensation, real flexibility, time together in Paris, great health coverage, and support to keep learning.

Equal opportunity

We welcome applicants from all backgrounds and hire based on talent, potential, and values alignment.

Obtenez votre examen gratuit et confidentiel de votre CV.
ou faites glisser et déposez votre fichier ici.
Similar jobs

Postes similaires à comparer

Head of Security
Head of Security

P2P • Île-de-France

Hybride
EUR 80 000 - 120 000
Top-tier compensation
Flexibility in work hours
Great health coverage
Senior Protocol Engineer (Verification)
Senior Protocol Engineer (Verification)

Morpho • Paris

Hybride
EUR 90 000 - 150 000
Fair compensation
Flexibility
Paris time
+2
Staff Fullstack Engineer
Staff Fullstack Engineer

P2P • Île-de-France

Hybride
EUR 75 000 - 95 000
Competitive compensation
Flexibility in work location
Great health coverage
+1
FinOps Analyst
FinOps Analyst

P2P • Paris

Sur place
EUR 65 000 - 100 000
Fair compensation
Flexible work options
Time together in Paris
+2
Staff Fullstack Engineer Remote / Paris / NYC
Staff Fullstack Engineer Remote / Paris / NYC

Morpho Labs • Paris

À distance
EUR 85 000 - 128 000
Competitive compensation
Health coverage
Learning support
Ops Associate - People Success
Ops Associate - People Success

P2P • Paris

Hybride
EUR 12 000 - 18 000
Health coverage
Flexible work style
Learning opportunities
Staff Fullstack Engineer
Staff Fullstack Engineer

Morpho • Paris

Hybride
EUR 140 000 - 190 000
Health coverage
Flexible schedule
Paris team time
Ops Associate - People Success Hybrid - Paris
Ops Associate - People Success Hybrid - Paris

Morpho Labs • Paris

Hybride
EUR 12 000 - 19 000
Apprenticeship/alternance
Chief Security Officer — Hands-On, Crypto/Fintech
Chief Security Officer — Hands-On, Crypto/Fintech

Morpho Labs • Paris

Hybride
EUR 90 000 - 130 000
Fair, top-tier compensation
Real flexibility
Great health coverage
+1
DeFi Risk Analyst
DeFi Risk Analyst

Morpho • Paris

Sur place
EUR 80 000 - 120 000
Top-tier compensation
Real flexibility
Great health coverage
+1