freehire launches on Product Hunt on 26 August.

Follow →

Head of Security

Summary

Lead security strategy, risk posture, and compliance for a fintech/crypto startup, reviewing product/infrastructure changes, managing incidents, and preparing for audits like SOC 2 and DORA.

You will build and own the security function, defining its strategy, roadmap, risk posture, and investment priorities. You will review product and infrastructure changes, lead threat modeling and incident response, oversee audit readiness and vendor risk, and manage the Senior DevSecOps Engineer. You will communicate security risks and progress to executive and board-level stakeholders.

Responsibilities

  • Define and own the security strategy, roadmap, risk posture, and investment decisions
  • Report security posture, risks, and program progress to co-founders
  • Review architecture decisions, product features, and infrastructure changes for security implications
  • Conduct or lead threat modeling across product and infrastructure domains
  • Contribute hands-on during incidents, vulnerability analysis, and high-stakes security reviews
  • Lead audit preparation, evidence readiness, control documentation, and auditor communication
  • Maintain readiness for SOC 2 Type II, DORA, and MiCA-related security requirements
  • Own security reviews for vendors, integrations, and third-party relationships
  • Manage external security partners, penetration testing, and security assessments
  • Manage and develop the Senior DevSecOps Engineer
  • Drive security awareness and communicate risks to non-technical leadership

Requirements

  • 8+ years of security experience
  • At least 3 years of security leadership or program ownership experience
  • Technical fluency in cloud security, application security, and CI/CD security
  • Experience owning a security compliance program through a major audit cycle
  • Software engineering degree or equivalent software engineering experience
  • Familiarity with AI and agentic tools
  • Experience in fintech, payments, or a similarly regulated industry
  • Written and verbal communication skills for executive and board-level risk briefings
  • Experience managing or mentoring security engineers
  • Ability to work flexible hours during incidents
  • Familiarity with DORA, MiCA, or EU financial services regulatory frameworks
  • Experience with crypto or blockchain security threat models
  • Experience building a security function
  • CISSP, CISM, or equivalent certification

Benefits

  • Stock options
  • Access to AI tools and subscriptions
  • Unlimited flexible PTO
  • Parental leave program
  • Flexible work schedule
  • Company laptop
  • Home equipment allowance
  • Daily commuting and/or meal stipend
  • Three company-paid off-sites per year
  • Health insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • Short-term disability insurance
  • Long-term disability insurance
  • 401(k) plan

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available