Head of Security & Risk

M0

New York (NY)

Hybrid

USD 120,000 - 160,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Comprehensive healthcare insurance
Wellbeing allowance and gym membership
Annual development budget

Job summary

M0 is seeking a dedicated information security professional to build their enterprise risk management program and oversee certification compliance. This role involves establishing a proactive security framework while collaborating across various departments.

Ideal candidates have 7–10 years of experience in risk management, with hands-on knowledge of compliance frameworks such as SOC 2 and ISO 27001. M0 provides competitive compensation with flexible remote options.

Qualifications

  • 7–10 years of experience in information security, risk, GRC, or compliance operations.
  • In-depth knowledge of compliance frameworks including SOC 2, ISO 27001, and GDPR.
  • Experience with cloud security environments, especially AWS.

Responsibilities

  • Build the enterprise risk management program from scratch.
  • Own M0's information security compliance certification program.
  • Establish the information security operations framework.

Skills

Information security
Risk management
Compliance operations
GRC automation platforms
Cloud security
Excellent communication

Tools

AWS
ISO 27001
SOC 2

Job description

M0 is the shared infrastructure where businesses launch their own branded stablecoins and financial institutions power them. Built on a common standard, every stablecoin on M0 is interoperable and liquid from day one – giving businesses programmable control over how money moves in their ecosystems, and giving financial institutions the most advanced issuance stack in the industry.

About the Role

Reporting to Deputy COO, you will be M0's first dedicated information security and risk professional – responsible for building the enterprise risk management program, owning the information security compliance certification roadmap, establishing the security operations framework, and responding to partner security due diligence requests. You will work daily across engineering, product, legal, BD, and operations to ensure that M0's security posture is proactive, documented, and defensible.

Key Responsibilities
  • Build and Own Enterprise Risk Management: Build M0's enterprise risk program from scratch. Cover security, operational, regulatory, and counterparty risk, including the risk register, annual assessments, scenario analyses, and escalation framework across all entities.
  • Own the Information Security Compliance Certification Program: Own M0's compliance posture across SOC 2, ISO 27001, and other applicable frameworks – driving all non‑technical workstreams (policy writing, auditor coordination, vendor risk, access reviews, third‑party SaaS vendor evaluations) and keeping the organization audit‑ready at all times.
  • Establish the Information Security Operations Framework: Design and maintain M0's incident response framework, ISMS documentation, and security policies – own external security vendor relationships, facilitate tabletop exercises covering IR, BCP, and DR scenarios, and drive the selection of a security advisory firm for on‑call support.
  • Own Partner Information Security Due Diligence: Serve as M0's primary point of contact for institutional partner security due diligence and inbound security questionnaires, build and maintain the reusable documentation package for responding to partner requests, and coordinate with Senior Counsel on information security representations in commercial agreements.
  • Build Information Security Awareness & Culture: Design and own M0's security awareness training program, ensure all employees understand their security obligations, and build a proactive security culture across engineering, operations, legal, and business teams.
Qualifications
  • 7–10 years of experience in information security, risk, GRC, or compliance operations, with meaningful ownership and a preference for fintech, crypto infrastructure, or B2B SaaS backgrounds.
  • Demonstrated track record of building a compliance certification program from scratch, in‑depth knowledge of compliance and regulatory frameworks, including hands‑on implementation of SOC 2, ISO 27001, CMMC, HIPAA, GDPR, NIST 800‑53, etc.
  • Hands‑on experience with GRC automation platforms (Vanta, Drata, or equivalent), cloud security environments (AWS preferred), and BCP/DR program design.
  • Proven experience managing external audit relationships end‑to‑end (including auditors, penetration testing firms, and compliance vendors) and navigating evidence collection and report production.
  • Working understanding of AWS, GCP, and Azure, including embedding security controls into DevOps workflows and Infrastructure as a Service (IaaS) deployments.
  • Preferred certifications: Cloud+, CySA+, CISSP, or CISM.
Skills & Attributes
  • A Proactive Risk Thinker: You think in terms of likelihood, impact, and mitigation, and you reason from first principles when regulations are unclear, translating complex risk into clear, business‑relevant language.
  • Exceptionally Organized and Process‑Driven: You maintain rigorous documentation, evidence records, and program trackers across concurrent workstreams. Your outputs need to be right and audit‑ready at all times, and you have a track record of improving processes, not just running them.
  • A Builder with High Ownership: You are a self‑starter with a “no job too big, no job too small” mentality. You look around corners to creatively solve problems and have a proven ability to own projects from concept to finish.
  • An Excellent Communicator & Partner: You build trust across engineering, legal, product, and business by speaking their language, embedding compliance as a shared operating principle rather than an external checkpoint, and getting things done through influence rather than authority.
  • Adaptable and Intellectually Curious: You have a positive attitude, comfort with ambiguity, and a relentless curiosity about new technologies. You have a passion for or a strong interest in crypto, blockchain technologies, and DeFi.
Nice to Haves
  • Security Certifications: Professional certifications in security risk management such as CISSP, CISM, or CRISC are preferred.
  • Crypto‑Native Familiarity: Familiarity with digital assets, stablecoins, or blockchain infrastructure, including smart contract security risk and on‑chain monitoring tools (BlockAid, Chainalysis, or similar).
  • Regulatory Exposure: Familiarity with GENIUS Act, MiCA, DORA, or other emerging digital asset and financial services regulatory frameworks and their security and compliance implications.
  • Multi‑Entity Experience: Prior experience operating across a multi‑entity structure (US operating entity, Cayman HoldCo, Swiss Foundation, or equivalent) is a plus.
  • Location: Ability to work multiple days a week in our main hub office in NYC.
Compensation
  • Competitive compensation (base salary with equity/token grant) commensurate with experience.
Benefits
  • Global team and flexibility: Join a truly global team with the flexibility to work remotely or from one of our hubs in NYC or Berlin.
  • Health and wellness: Enjoy comprehensive healthcare insurance coverage as well as a wellbeing allowance and gym membership to support your physical and mental health.
  • Customizable IT setup: Tailor your workspace with access to top‑notch IT equipment.
  • Professional development: Benefit from an annual development budget to enhance your skills and grow professionally, including opportunities to participate in conferences and on‑site company events worldwide.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Head of Security & Risk
Head of Security & Risk

M0 • United States

On-site
USD 150,000 - 200,000
Comprehensive healthcare coverage
Flexible remote work option
Professional development budget
Chief Security & Risk Architect
Chief Security & Risk Architect

M0 • United States

Hybrid
USD 150,000 - 200,000
Comprehensive healthcare coverage
Flexible remote work option
Professional development budget
Security & Risk Leader for FinTech & Crypto
Security & Risk Leader for FinTech & Crypto

M0 • New York (NY)

Hybrid
USD 120,000 - 160,000
Comprehensive healthcare insurance
Wellbeing allowance and gym membership
Annual development budget
Head of Security (NYC / MIA)
Head of Security (NYC / MIA)

Crossmint • Miami (FL)

Hybrid
USD 210,000 - 250,000
Head of Security (NYC / MIA)
Head of Security (NYC / MIA)

Clutch Canada • Miami (FL)

Hybrid
USD 210,000 - 250,000
Unlimited PTO
Parental Leave
Health, dental, vision insurance
+3
Engineering Manager – Identity, Compliance & Risk (NYC / MIA) — Crossmint
Engineering Manager – Identity, Compliance & Risk (NYC / MIA) — Crossmint

The Bitcoin Street Journal • Miami (FL)

Hybrid
USD 250,000 - 280,000
Unlimited PTO
Parental Leave
Laptop & home equipment allowance
+3
Lead Security Engineer
Lead Security Engineer

8090 Solutions Inc • Redwood City (CA)

On-site
USD 180,000 - 350,000
Lead Security Engineer
Lead Security Engineer

Worky • Redwood City (CA)

On-site
USD 180,000 - 350,000
Senior DevSecOps Engineer
Senior DevSecOps Engineer

Greenboard • New York (NY)

Hybrid
USD 165,000 - 240,000
Salary + equity
401(k) match
Medical/Dental/Vision
+3
Engineering Manager - Identity, Compliance & Risk (NYC / MIA)
Engineering Manager - Identity, Compliance & Risk (NYC / MIA)

Crossmint • New York (NY)

On-site
USD 250,000 - 280,000
Stock options
Unlimited PTO
Parental Leave
+3