
Head of Information Security
Posted 13 hours ago

Posted 13 hours ago
This is a fully remote position, open to applicants anywhere in the world.
• Take charge of the strategy, design, and ongoing enhancement of OpenZeppelin's Information Security Program.
• Oversee the team responsible for implementing the Information Security Program.
• Establish strategic direction, develop a multi-year roadmap, and define risk posture, while ensuring the delivery of departmental OKRs.
• Manage the IT and technology budget along with technology procurement processes.
• Lead the secure integration of AI, which includes AI governance, reviewing AI tools and agentic workflows, and securing agentic infrastructure.
• Handle critical vendor relationships with frontier model providers, including security and data-handling diligence, commitments for retention and training use, DPAs, and subprocessor flow-downs.
• Address new obligations such as the EU AI Act.
• Develop and execute strategies for audit, certification, and attestation, including penetration testing, SOC 2 Type 2, and ISO/IEC 27001.
• Manage third-party and vendor risk assessments.
• Represent the security program to customer security teams, regulated financial institutions, and auditors.
• Maintain data mappings, classifications, processing records, and inventories of vendors/subprocessors.
• Ensure privacy compliance in collaboration with Legal, including GDPR, CCPA/CPRA, DPAs, contractual security obligations, and privacy-by-design reviews.
• Lead incident response efforts, including developing playbooks, conducting tabletop exercises, managing post-incident reviews, and overseeing breach notifications.
• Manage bug bounty programs and collaborate with development teams on security within the SDLC.
• Oversee identity and access management, provisioning processes, onboarding/offboarding, endpoint security, physical security, disaster recovery, business continuity, and backup solutions.
• Utilize automation and AI-driven workflows to enhance the scalability of IT and security operations.
• A minimum of 10 years of experience in Security and IT.
• At least 3 years of experience leading an IT Security and GRC function, rather than solely IT operations, in a rapidly growing tech company.
• Proven track record of owning security strategy, beyond mere execution.
• A career trajectory aimed at CISO, with complete ownership of a security program.
• Experience presenting to executives or boards.
• Ability to explain the reasoning behind implemented controls.
• Experience securing or overseeing AI/LLM-enabled products or managing enterprise AI adoption, including agentic systems and risks associated with third-party model providers.
• Proficiency in applying privacy and data-protection laws and practices, such as GDPR and CCPA/CPRA, particularly in the context of AI.
• Over 5 years of experience in blockchain or FinTech with an enterprise client base, including rigorous third-party security diligence (preferred).
• Connect with your teammates at company events held globally 😎
• Benefit from the convenience of fully remote work 🌎
• Enjoy flexible time off to take the time you need 🏝
• Receive 8 weeks of paid leave for primary caregivers.
• Get 4 weeks of paid leave for secondary caregivers.
• A one-time baby bonus of $3,600 💙
• Up to $500 in equipment support for setting up a home office 🪑
• Comprehensive medical insurance 🏥
• Opportunities for learning and development 🧠
• Monthly stipend for a preferred co-working space 💻
• Paid work test (up to 20 hours of paid work).
Agile Defense
Stripe
Guild Mortgage
Cambiar Education
Get handpicked remote jobs straight to your inbox weekly.