Head of Security

Phaxis

New York (NY)

On-site

USD 180,000 - 320,000

Full time

7 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Phaxis is seeking a hands-on Head of Security to build and lead the information security function from the ground up. This founding-team role offers significant ownership with a clear path toward CISO as the company grows.

You will own security for critical money movement infrastructure, drive SOC 2/NIST-compliant controls, and lead incident response. The position is based in the United States and requires strong AWS expertise and a pragmatic, automation-first mindset.

Qualifications

  • 7+ years of security engineering, cloud security, or related field.
  • Experience securing high-value financial infrastructure (payments/banking/crypto).
  • Strong threat-modeling ability and ability to communicate security decisions to executives/auditors.
  • Hands-on experience with AI-assisted development tools and automation.
  • Experience with AWS cloud security including IAM and guardrails.

Responsibilities

  • Own security for critical money movement infrastructure and custody flows.
  • Build and automate controls for SOC 2, FFIEC, and NIST 800-53.
  • Lead end-to-end incident response and runbooks.
  • Drive application and supply-chain security (secure SDLC, secrets, CI/CD).
  • Establish IAM practices with least privilege and periodic reviews.
  • Manage third-party/vendor security assessments and risk reviews.
  • Secure AWS/Terraform infra, with guardrails and disaster recovery.
  • Leverage AI and automation to reduce manual security processes.

Skills

Security engineering
AWS security
Threat modeling
Automation
Incident response
Executive communication
AI-assisted tooling

Tools

Terraform
IAM
CI/CD security
Security tooling

Job description

Location: United States
Reports to: CTO
Employment: Full-time

Our client is building a modern, API-first bank designed for the global economy, connecting traditional banking infrastructure with public blockchain and onchain payment rails. The platform will support traditional payment networks including Fedwire, ACH, FedNow, RTP, and SWIFT, alongside FX, treasury management, and bank-issued stablecoin capabilities.

Seeking a hands-on Head of Security to build and lead the company's information security function from the ground up. This is a founding-team-level role with significant ownership and autonomy, with a natural path toward CISO as the organization scales.

Key Responsibilities
  • Own security for the bank's critical money movement infrastructure, including stablecoin mint/redeem flows, custody, key management, transaction signing, and sanctions/asset-freeze controls.
  • Build and automate the technical security controls supporting SOC 2, FFIEC, and NIST 800-53 requirements.
  • Lead end-to-end incident response, including detection, escalation, on-call processes, post-incident reviews, and security runbooks.
  • Drive application and supply-chain security, including secure SDLC, secrets management, dependency management, and CI/CD security.
  • Establish identity and access management practices centered around least privilege, JIT access, approvals, auditability, and periodic access reviews.
  • Own third-party/vendor security assessments and risk reviews.
  • Help secure the underlying AWS/Terraform infrastructure, including cloud guardrails, gated releases, observability, and disaster recovery.
  • Leverage AI and automation to eliminate manual security and compliance processes wherever possible.
Ideal Background
  • 7+ years of experience in security engineering, cloud security, detection/response, or a closely related discipline.
  • Strong AWS cloud security experience, including IAM, organization-level guardrails, Terraform, and least-privilege architecture.
  • Proven experience securing high-value financial infrastructure, ideally within payments, banking, crypto, exchanges, custody, or similar environments.
  • Strong threat-modeling capabilities and the ability to communicate technical security decisions clearly to executives, auditors, and regulators.
  • Hands-on experience with AI-assisted development/coding tools and a strong automation mindset.
  • Excellent written communication skills, particularly around security decisions, control narratives, and incident reviews.
Nice-to-Haves
  • Experience with crypto custody, MPC, HSMs, wallet infrastructure, or key ceremonies.
  • Experience operating in regulated/audited environments involving SOC 2, FFIEC, NIST 800-53, or bank examinations.
  • Rust or smart-contract experience/literacy.
  • Experience with stablecoins, blockchain infrastructure, or onchain payments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Operations & GRC Lead
Security Operations & GRC Lead

Pasona N A, Inc. • United States

On-site
USD 150,000 - 200,000
Staff Security Engineer – Digital Asset Security
Staff Security Engineer – Digital Asset Security

Iceberg • San Francisco (CA)

On-site
USD 180,000 - 240,000
Head of Security
Head of Security

Moment • New York (NY)

On-site
USD 150,000 - 250,000
Director of Product Security
Director of Product Security

Harrison Clarke • San Francisco (CA)

On-site
USD 150,000 - 200,000
Head of Security
Head of Security

Cielo Talent • New York (NY)

On-site
USD 180,000 - 280,000
Head of Security
Head of Security

Cielo Projects • New York (NY)

On-site
USD 165,000 - 215,000
Security Engineer
Security Engineer

ether.fi • New York (NY)

On-site
USD 120,000 - 160,000
Principal Security Engineer
Principal Security Engineer

Block • Seattle (WA)

On-site
USD 180,000 - 240,000
Security Engineer (Blockchain & Cryptography)
Security Engineer (Blockchain & Cryptography)

IntePros • New York (NY)

On-site
USD 180,000 - 240,000
Senior IT Security Engineer
Senior IT Security Engineer

Blockwisely • Indiana (PA)

Hybrid
USD 130,000 - 195,000