Head of Information Security

Posted 13 hours ago

This is a fully remote position, open to applicants anywhere in the world.

📋 Description

• Take charge of the strategy, design, and ongoing enhancement of OpenZeppelin's Information Security Program.

• Oversee the team responsible for implementing the Information Security Program.

• Establish strategic direction, develop a multi-year roadmap, and define risk posture, while ensuring the delivery of departmental OKRs.

• Manage the IT and technology budget along with technology procurement processes.

• Lead the secure integration of AI, which includes AI governance, reviewing AI tools and agentic workflows, and securing agentic infrastructure.

• Handle critical vendor relationships with frontier model providers, including security and data-handling diligence, commitments for retention and training use, DPAs, and subprocessor flow-downs.

• Address new obligations such as the EU AI Act.

• Develop and execute strategies for audit, certification, and attestation, including penetration testing, SOC 2 Type 2, and ISO/IEC 27001.

• Manage third-party and vendor risk assessments.

• Represent the security program to customer security teams, regulated financial institutions, and auditors.

• Maintain data mappings, classifications, processing records, and inventories of vendors/subprocessors.

• Ensure privacy compliance in collaboration with Legal, including GDPR, CCPA/CPRA, DPAs, contractual security obligations, and privacy-by-design reviews.

• Lead incident response efforts, including developing playbooks, conducting tabletop exercises, managing post-incident reviews, and overseeing breach notifications.

• Manage bug bounty programs and collaborate with development teams on security within the SDLC.

• Oversee identity and access management, provisioning processes, onboarding/offboarding, endpoint security, physical security, disaster recovery, business continuity, and backup solutions.

• Utilize automation and AI-driven workflows to enhance the scalability of IT and security operations.


⛳️ Requirements

• A minimum of 10 years of experience in Security and IT.

• At least 3 years of experience leading an IT Security and GRC function, rather than solely IT operations, in a rapidly growing tech company.

• Proven track record of owning security strategy, beyond mere execution.

• A career trajectory aimed at CISO, with complete ownership of a security program.

• Experience presenting to executives or boards.

• Ability to explain the reasoning behind implemented controls.

• Experience securing or overseeing AI/LLM-enabled products or managing enterprise AI adoption, including agentic systems and risks associated with third-party model providers.

• Proficiency in applying privacy and data-protection laws and practices, such as GDPR and CCPA/CPRA, particularly in the context of AI.

• Over 5 years of experience in blockchain or FinTech with an enterprise client base, including rigorous third-party security diligence (preferred).


🏝️ Benefits

• Connect with your teammates at company events held globally 😎

• Benefit from the convenience of fully remote work 🌎

• Enjoy flexible time off to take the time you need 🏝

• Receive 8 weeks of paid leave for primary caregivers.

• Get 4 weeks of paid leave for secondary caregivers.

• A one-time baby bonus of $3,600 💙

• Up to $500 in equipment support for setting up a home office 🪑

• Comprehensive medical insurance 🏥

• Opportunities for learning and development 🧠

• Monthly stipend for a preferred co-working space 💻

• Paid work test (up to 20 hours of paid work).

People also viewed

Agile Defense8 hours ago

Senior Security Architect

US flagDistrict of Columbia, +1 more stateFull-timeCybersecurity / Security Engineer$150k – $155k/year
ApplyView job
Stripe9 hours ago

Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Guild Mortgage10 hours ago

Third-Party Security Manager

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$94.9k – $136.1k/year
ApplyView job
Cambiar Education13 hours ago

Director, IT – Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$140k – $170k/year
ApplyView job
Docker, Inc13 hours ago

Senior Security Engineer – Offensive Security

GB flagUnited Kingdom, +4 more countriesFull-timeCybersecurity / Security Engineer€118.9k – €169.8k/year
ApplyView job
Motive13 hours ago

Red Team Security Engineer

CA flagCanada OnlyFull-timeCybersecurity / Security EngineerC$146k – C$190k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers