Head of Security Assurance

Index Industries

United States

Remote

USD 180,000 - 240,000

Full time

25 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Index Industries is building a security and governance function to mature its assurance posture as we scale. You will lead the SOC 2 program end-to-end, shape the external security narrative, and coordinate diligence with institutional counterparties and auditors across web2 and web3.

You will define detection and access controls with engineering, own the control program, and report to leadership on progress and risk posture as the company grows.

Qualifications

  • Lead SOC 2 Type II program end-to-end, including scoping, auditor liaison, remediation planning, evidence collection and fieldwork.
  • Front institutional diligence processes and security questionnaires with counterparties and their teams.
  • Read and translate security stack details from policies to implementation across web2 and web3.

Responsibilities

  • Own the assurance program end-to-end, SOC 2 anchor and accompanying certifications.
  • Publicly describe external security posture through audit reports and attestation materials.
  • Front security questionnaires with institutional clients and auditors; articulate controls and evidence.
  • Define and verify detection, logging and access controls; coordinate with engineering teams.
  • Oversee control program including policies, risk register, vendor reviews, and incident response.

Skills

SOC 2 Type II
Security governance
Audit coordination
Threat modeling
Cloud security
Regulated finance

Education

Bachelor's degree in a relevant field

Tools

Vanta
Drata
Secureframe
AWS

Job description

Index Industries is a growing startup, and our security and audit posture needs to grow with it. We already run on solid foundations: AWS, Railway, Ethereum and Datadog cover our infrastructure, hosting, blockchain and observability, and we have built real controls into how we operate custody and the protocol. We have policies, structures, and controls in place. As we onboard more institutional investors and expand toward retail with additional financial products, those foundations need to mature from good defaults into practices built for our domain: investors who run their own diligence, auditors who expect evidence rather than assurances, and venues that gate access to demonstrated controls.

This role is about that maturation, not a rebuild. You will take our detection and response, custody operations and platform security stance from solid basics to the best practices our growth demands across web2 and web3 - and produce the technical evidence that lets investors, auditors and counterparties trust it.

What you'll own

  • The assurance program, end to end. SOC 2 is the anchor, and the certifications that follow it: scoping, auditor selection, remediation planning, evidence, fieldwork, report.
  • Our external security story. The public trust surface, published audit and attestation material, and a vulnerability disclosure policy researchers can actually use.
  • Diligence. You will personally front security questionnaires and the calls behind them, with institutional counterparties and their security teams. You'll be responsible for understanding and representing the security stack, from policies to implementation across web2 and web3.
  • The control program. Policies, risk register, vendor reviews, access reviews, key-management ceremonies, tabletop exercises - you run the cadence and you keep the evidence. The operational surface that carries most of our real risk: multisig ops, treasury ops, incident response, DevOps and infrastructure, DNS and registrar, and identity and accounts. We want each of those independently assessable rather than self-attested.
  • The money path. Value moves through our system in both fiat and crypto, across more than one legal entity and several settlement paths. You'll hold that whole picture: where funds could be redirected, where an approval could be spoofed or socially engineered, where a reconciliation gap could hide a loss - and close those paths. That includes recommending real tooling, with a clear view of what it buys and what it costs in friction.
  • Requirements on engineering. You define what detection, logging and access controls must exist and to what standard, then verify delivery. Our engineers build it.
  • Anticipating what's next. We're building things that don't have an established playbook, so our threat model has to be derived rather than looked up. You'll stay close to the roadmap - new products, new chains, new counterparties, new flows - work out what each one exposes, and land the controls before it ships. The test is whether your input arrives early enough to shape a design rather than late enough to block one.
  • Automation over toil. A control that depends on someone remembering is a control that fails. You'll push evidence collection, monitoring, access reviews and reporting toward automation, so the programme gets more reliable as we grow rather than more expensive, and the burden on engineers and operators falls while the posture improves.
  • Reporting to leadership and the board on where we actually are.

We anchor on SOC 2. Beyond it, our direction of travel is NIST CSF 2.0 as the narrative and board-reporting layer, CIS Controls v8.1 (IG2) as the technical baseline, the SEAL frameworks as operational content, and the AICPA's 2025 criteria for token operations as a control-matrix skeleton. That is direction, not doctrine - you will have a real say in what we actually adopt and in what order.

What you'll bring

  • You have delivered a SOC 2 Type II as the accountable owner, not as a participant.
  • You have fronted institutional diligence and held your own with a counterparty's security team.
  • Real technical literacy. You can read a smart contract's access-control model, reason about signing policy and approval quorums in an MPC custody platform, and hold your end of an AWS architecture conversation. You don't need to write the code; you need engineers to respect your requirements.
  • Digital asset experience. You shouldn't need custody, oracles or on-chain governance explained from first principles.
  • A background in regulated financial services, or somewhere that taught you a control isn't real until it's evidenced.
  • You write exceptionally well. Nearly everything you produce is read by someone deciding whether to trust us.
  • You run a recurring process without being chased. The value here lives in the cadence.
  • You track the threat landscape closely, across both web2 and web3. You can speak to how DPRK-linked groups and other sophisticated actors actually operate against companies like ours: social engineering, supply-chain compromise, signer targeting, infiltration of hiring pipelines. And you turn that into specific controls rather than general alarm.

Helpful, not required: compliance automation tooling (Vanta, Drata, Secureframe), ISO 27001, CCSS, incident command experience, time at a custodian, exchange or tokenisation platform.

What this role is not

It is not a rebuild. We want someone who will spend their first month understanding why things are built the way they are before proposing changes. It is not a DevOps or infrastructure role. And it is not smart contract auditing. We engage multiple independent firms for that and will continue to.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Senior Cybersecurity Engineer - Build & Own Controls
Remote Senior Cybersecurity Engineer - Build & Own Controls

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
Security Lead
Security Lead

Sunset • New York (NY)

On-site
USD 170,000 - 230,000
Cloud Security Architect (GCC High)
Cloud Security Architect (GCC High)

Two Five Solutions, LLC. • Washington, Northern (KY)

Hybrid
USD 140,000 - 185,000
Fractional CISO
Fractional CISO

Reflexion • United States

Remote
USD 248,000 - 386,000
Compliance Engineering Lead
Compliance Engineering Lead

Socket • United States

On-site
USD 150,000 - 190,000
Equity program
Health benefits
Remote-first culture
+1
Senior Manager of Information Security
Senior Manager of Information Security

Plume • United States

On-site
USD 180,000 - 240,000
Security & Infrastructure Engineer
Security & Infrastructure Engineer

Engg • San Francisco (CA)

On-site
USD 180,000 - 240,000
Compliance Engineering Lead
Compliance Engineering Lead

Socket • Northern (KY)

On-site
USD 150,000 - 230,000
Equity program
Comprehensive health benefits
Remote-first with team off-sites
+1
Principal Security Engineer
Principal Security Engineer

Valmar Holdings LLC. • Village of Williamsville (NY)

Hybrid
USD 140,000 - 200,000
Head of Security
Head of Security

Phaxis • New York (NY)

On-site
USD 180,000 - 320,000