Head of Security & Risk

MLabs Ltd

New York, Northern (NY, KY)

Hybrid

USD 200,000 - 250,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Equity/token grant participation
Hub offices NYC/Berlin
Healthcare & wellbeing
IT hardware allowance
Learning & development budget

Job summary

MLabs Ltd seeks a Head of Security & Risk to build the information security and enterprise risk program from the ground up. This IC role reports to the Deputy COO and will own ERM, ISMS, and incident response in collaboration with engineering, product, legal, and operations.

The candidate should have 7–10 years in information security, risk management, GRC, or compliance, with hands-on SOC 2 and ISO 27001 work, plus experience with Vanta/Drata and AWS. NYC on-site is required several days weekly.

Qualifications

  • 7–10 years in information security, risk management, or compliance.
  • Proven hands-on experience building SOC 2 audits and ISO 27001.
  • Experience with GRC automation platforms (Vanta, Drata) and AWS.
  • Vendor and audit management experience end-to-end.
  • Willingness to work on-site in NYC multiple days per week.

Responsibilities

  • Build and own enterprise risk management program from scratch.
  • Lead information security compliance and certifications (SOC 2, ISO 27001).
  • Design and maintain ISMS, policies, and incident response frameworks.
  • Manage partner information security due diligence and documentation.
  • Promote security awareness and a proactive security culture.

Skills

Information security
Risk management
GRC
Audit coordination
Vendor management

Tools

Vanta
Drata
AWS

Job description

Location:Remote - US Remote (Preference for NYC based candidates)

Remote| Full-time

Compensation:$200K - $250K

Our client operates shared financial infrastructure designed to enable businesses and institutional partners to launch and manage branded stablecoins and advanced digital asset issuance stacks. The platform provides fully interoperable, liquid on-chain solutions that grant businesses programmable control over payment ecosystems while meeting the stringent operational demands of regulated financial institutions.

To support rapid growth and expanding institutional partnerships, our client is seeking a sharp, execution-focused Head of Security & Risk. This is a foundational, individual contributor (IC) role at a critical inflection point for the organization. In this position, the Head of Security & Risk will build and own the information security and enterprise risk management functions from the ground up.

Reporting directly to the Deputy Chief Operating Officer, the individual will serve as the organization's primary security authority—establishing the enterprise risk framework, driving information security compliance, leading incident response and security operations, and managing institutional due diligence requests. This role requires close collaboration across engineering, product, legal, business development, and operations teams to ensure a proactive, audit-ready, and defensible security posture.

Key Responsibilities
  • Build and Own Enterprise Risk Management (ERM): Design and execute an enterprise risk management program from scratch. Oversee security, operational, regulatory, and counterparty risks, including maintaining the risk register, leading annual risk assessments, performing scenario analyses, and establishing an escalation framework across all legal entities.
  • Lead Information Security Compliance & Certifications: Drive the compliance certification roadmap across frameworks such as SOC 2 and ISO 27001. Direct non-technical workstreams, including policy drafting, auditor coordination, vendor risk evaluations, third‑party SaaS reviews, and periodic access reviews to maintain continuous audit readiness.
  • Establish Security Operations & Response Frameworks: Design and maintain the Information Security Management System (ISMS), security policies, and incident response frameworks. Manage external security vendor relationships, lead tabletop exercises across Incident Response (IR), Business Continuity Planning (BCP), and Disaster Recovery (DR) scenarios, and select external security advisory firms for on‑call support.
  • Manage Partner Information Security Due Diligence: Act as the primary point of contact for institutional partner security due diligence and inbound questionnaires. Build and maintain a reusable compliance documentation package and collaborate with legal counsel on security representations within commercial agreements.
  • Drive Information Security Culture & Awareness: Develop and own the security awareness training curriculum across all departments. Promote a proactive security culture across engineering, product, legal, and operational units.
Qualifications
  • Experience: 7–10 years of progressive experience in information security, risk management, GRC, or compliance operations, ideally within fintech, digital asset/crypto infrastructure, or B2B SaaS sectors.
  • Compliance Expertise: Demonstrated track record of building compliance programs from the ground up, including direct, hands‑on ownership of full SOC 2 audits and ISO 27001 implementation/maintenance.
  • Technical & GRC Tooling: Hands‑on experience with modern GRC automation platforms (e.g., Vanta, Drata), cloud environments (AWS preferred), and infrastructure security integration within DevOps/IaaS workflows.
  • Vendor & Audit Management: Proven experience managing external audit relationships, penetration testing partners, and compliance vendors end‑to‑end.
  • Location: Ability to work multiple days per week on‑site in the primary hub located in New York City.
Skills & Core Attributes
  • Proactive Risk Mindset: Ability to evaluate risks through likelihood, impact, and mitigation, translating technical and regulatory complexities into clear, business‑focused solutions.
  • Process Rigor & Documentation: Exceptional organizational skills with a strong focus on maintaining pristine documentation, evidence collection, and tracking systems.
  • High Ownership & Adaptability: A self‑starter capable of navigating ambiguity, driving end‑to‑end projects, and balancing strategic planning with tactical execution.
  • Strong Stakeholder Communication: Ability to build strong relationships across engineering, legal, product, and business units by promoting security as a shared operational standard.
Preferred / Nice to Haves
  • Certifications: Professional security certifications such as CISSP, CISM, CRISC, CySA+, or Cloud+.
  • Digital Asset Familiarity: Experience with digital assets, stablecoins, smart contract security risks, and on‑chain monitoring tools (e.g., Chainalysis, BlockAid).
  • Regulatory Knowledge: Exposure to emerging digital asset frameworks such as the GENIUS Act, MiCA, DORA, or global financial services regulations.
  • Multi‑Entity Structure: Prior experience operating within multi‑entity corporate structures (e.g., US entities, Cayman HoldCos, Swiss Foundations).
  • Competitive Compensation: Market‑leading base salary with equity/token grant participation tailored to experience.
  • Flexible Work Model: Access to global team flexibility with dedicated hub offices in New York City and Berlin.
  • Comprehensive Healthcare & Wellbeing: Comprehensive health insurance coverage, a wellness allowance, and sponsored gym access.
  • Custom Hardware & IT Allowance: Access to top‑tier IT equipment and flexible workspace customization.
  • Professional Growth: Dedicated annual learning and development budget covering industry conferences, certifications, and international company retreats.
Interview Process
  1. Behavioral Interview
  2. Hiring Manager Interview (Part I)
  3. Hiring Manager Interview (Part II)
  4. Hiring Manager Interview (Part III)
  5. Founder / CEO Interview
  6. Final Interview

Due to the high volume of applications we anticipate, we regret that we are unable to provide individual feedback to all candidates. If you do not hear back from us within 4 weeks of your application, please assume that you have not been successful on this occasion. We genuinely appreciate your interest and wish you the best in your job search.

Commitment to Equality and Accessibility:

At MLabs, we are committed to offer equal opportunities to all candidates. We ensure no discrimination, accessible job adverts, and providing information in accessible formats. Our goal is to foster a diverse, inclusive workplace with equal opportunities for all. If you need any reasonable adjustments during any part of the hiring process or you would like to see the job-advert in an accessible format please let us know at the earliest opportunity by emailing human-resources@mlabs.city.

MLabs Ltd collects and processes the personal information you provide such as your contact details, work history, resume, and other relevant data for recruitment purposes only. This information is managed securely in accordance with MLabs Ltd’s Privacy Policy and Information Security Policy, and in compliance with applicable data protection laws. Your data may be shared only with clients and trusted partners where necessary for recruitment purposes. You may request the deletion of your data or withdraw your consent at any time by contacting legal@mlabs.city.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Head of Security & Risk
Head of Security & Risk

Cyberjobs • New York (NY), Northern (KY)

Hybrid
USD 200,000 - 250,000
Equity/token grants
Health insurance
Wellness allowance
+2
Head of Security & Risk
Head of Security & Risk

mLabs • New York (NY)

Remote
USD 200,000 - 250,000
Competitive compensation
Flexible work model with NYC/Berlin</n
Healthcare & wellbeing
+2
Head of Growth
Head of Growth

MLabs • Los Angeles (CA)

On-site
USD 200,000 - 225,000
Unlimited PTO
Equity opportunities
Generous benefits
Chief of Staff
Chief of Staff

MLabs • New York (NY)

On-site
USD 150,000 - 180,000
100% coverage of medical, vision, and dental insurance
Unlimited PTO policy
Monthly stipends for WiFi, cell phone, and home office
+2
Full Stack Engineer
Full Stack Engineer

MLabs • Austin (TX)

On-site
USD 180,000 - 225,000
Comprehensive Health Coverage
401(k) retirement plan
PTO
+1
Staff Backend Engineer
Staff Backend Engineer

MLabs • Netherlands (MO)

On-site
USD 175,000 - 225,000
Competitive base salary
Equity participation
Performance-based bonuses
Backend Engineer (NYC)
Backend Engineer (NYC)

MLabs • New York (NY)

On-site
USD 180,000 - 320,000
Competitive base salary
Equity ownership options
Token incentives aligned with protocol
+1
Founding Engineer
Founding Engineer

mLabs • New York (NY)

Hybrid
USD 200,000 - 300,000
5% equity
Founder-level ownership
Senior Core Systems Engineer
Senior Core Systems Engineer

MLabs • United States

On-site
USD 180,000 - 260,000
Equity options
Remote-first work model
Healthcare coverage
+2
Founding Full Stack Software Engineer
Founding Full Stack Software Engineer

MLabs • Los Angeles (CA)

On-site
USD 150,000 - 250,000
Competitive salary
Equity options
Visa sponsorship available