Head of Security Assurance
Core
Lead the maturation of security assurance, custody operations, and platform security for a Web2/Web3 startup to meet institutional investor and auditor standards.
Role type
Senior IC Head of Security Assurance
Builds
SOC 2 and subsequent certifications, public trust materials, and auditable control programs for custody and treasury operations.
Domain
Web3 / Digital Assets / Regulated Financial Services
Required skills
SOC 2 Type II ownership, institutional security diligence, smart contract access control literacy, MPC custody platform reasoning, AWS architecture understanding, regulated financial services background, technical writing, threat landscape analysis (Web2/Web3), automation of control programs
Preferred skills
ISO 27001, CCSS, incident command experience, time at a custodian/exchange/tokenization platform
Technologies
AWS, Railway, Ethereum, Datadog, SOC 2, NIST CSF 2.0, CIS Controls v8.1, SEAL frameworks, AICPA 2025 criteria
Responsibilities
Own the end-to-end assurance program (scoping, auditor selection, remediation, evidence, fieldwork, reporting); manage external security story and vulnerability disclosure policy; lead institutional security questionnaires and calls; run the control program (policies, risk register, vendor reviews, access reviews, key-management, tabletop exercises); oversee the money path (fiat/crypto flows, settlement paths, fraud prevention); define and verify security requirements for engineering; anticipate security needs for new products/chains/flows; automate evidence collection and monitoring; report to leadership and board.
Seniority
Senior, hands-on IC