Head of Security
- Role
- Security
- Experience
- C-Level
- Employment
- Full-time
Published by
Valeria 🎄 Volotkevich | AI IT Recruiter👆 HiringOpen to RU, US only. Set where you work from to check your eligibility.
No BS summary
Hands-on security leader with 7+ years in information security and prior Head of Security/Security Lead/CISO experience. Must have led SOC 2 Type I/II personally and be able to find and fix product/infra security issues solo. Crypto/web3 security knowledge is required; wallet security is ideal.
Core skills
Required skills
Head of Security (non-custodial crypto wallet) #vacancy #security #ciso #soc2 #web3 #crypto #remote
Сразу расставим точки: «Head» здесь — это про уровень экспертизы, а не про кресло руководителя.
Ни команды, ни подчинённых. Ты — один. Самый сильный безопасник, который сам находит дыры и сам их закрывает.
Продукт — non-custodial крипто-кошелёк: ключи на устройстве, без регистрации и сбора персданных. Вокруг — институциональная платёжная инфраструктура, через которую идёт заметная доля трафика целой L1-сети.
Что предстоит:
— построить security-функцию с нуля и провести продукт через SOC 2 (Type I/II) практически в одиночку — evidence, аудиты, remediation — самому искать слабые места в продукте и инфре и чинить их, а не раздавать таски — принимать и разбирать infra pull requests по существу — понимать, что изменение делает с безопасностью, а не «прожимать апрув» — держать риски кошелька: приватные ключи, seed-фразы, signing-флоу, фишинг, wallet draining — governance по-взрослому: политики, risk register, access control, incident response, vendor risk
DevOps подстрахует, но точечно и только по ключевым вещам. Дефолт — руки твои.
Кому зайдёт:
— 7+ лет в ИБ, был Head of Security / Security Lead / CISO — проводил SOC 2 сам как лид минимум раз — не «рядом стоял» — настоящий hands-on: читаешь код и инфру, а не только стратегию — понимаешь crypto/web3-security, в идеале кошельки
Кому не зайдёт: если твоя сила — управлять командой, а руками давно не трогал. Тут некем управлять.
Формат: remote, full-time, USDT.
Твоя история — пиши 👉
Знаешь такого человека — рефералы приветствуются 🤝
What you'll do
- Build the security function from scratch and lead SOC 2 Type I/II nearly solo
- Handle SOC 2 evidence, audits, and remediation
- Find and fix product and infrastructure vulnerabilities hands-on
- Review infrastructure pull requests for security impact
- Manage wallet risks around private keys, seed phrases, signing flows, phishing, and wallet draining
- Own security governance including policies, risk register, access control, incident response, and vendor risk
What they require
- 7+ years in information security
- Prior Head of Security, Security Lead, or CISO experience
- Led SOC 2 personally at least once
- Hands-on ability to read code and infrastructure, not only strategy
- Understanding of crypto/web3 security
- Ideally experience with crypto wallets
- Not suited for someone focused mainly on managing teams rather than hands-on security work
Benefits
- Referral welcome
Non-custodial crypto wallet with keys stored on-device, no registration or personal data collection, connected to institutional payment infrastructure carrying a significant share of traffic for an L1 network.