Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
MLabs

Head of Security – Risk

MLabs

. Design and execute an enterprise risk management program from scratch .

Posted 9/24/2026full-timeNew York City • New York • United StatesLead💰 $200,000 - $250,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive experience in designing and executing enterprise risk management programs, with a strong focus on compliance certifications such as SOC 2 and ISO 27001. Proven ability to manage security policies, vendor relationships, and risk assessments while fostering a proactive security culture across various departments.

Highest-signal resume keywords
Enterprise Risk ManagementSOC 2 ComplianceISO 27001 ImplementationGRC Automation PlatformsCloud Security Integration

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Information SecurityRisk ManagementCompliance OperationsIncident Response FrameworksRisk AssessmentDocumentation ManagementVendor Risk EvaluationBusiness Continuity PlanningDisaster RecoverySecurity Policy Development
Soft Skills
Organizational SkillsRelationship BuildingProject ManagementStrategic PlanningTactical Execution
Tools & Technologies
VantaDrataAWSChainalysisBlockAid
Certifications & Qualifications
CISSPCISMCRISCCySA+Cloud+
Industry Keywords
FintechDigital AssetB2B SaaSGENIUS ActMiCADORAGlobal Financial Services Regulations

Tech Stack

Tools & technologies
AWSCloud

About the role

Key responsibilities & impact
  • Design and execute an enterprise risk management program from scratch
  • Oversee security, operational, regulatory, and counterparty risks
  • Maintain the risk register and lead annual risk assessments and scenario analyses
  • Establish an escalation framework across all legal entities
  • Drive the compliance certification roadmap for SOC 2 and ISO 27001
  • Draft policies, coordinate auditors, evaluate vendor risk, review third-party SaaS, and conduct periodic access reviews
  • Design and maintain the Information Security Management System, security policies, and incident response frameworks
  • Manage external security vendor relationships
  • Lead tabletop exercises for Incident Response, Business Continuity Planning, and Disaster Recovery scenarios
  • Select external security advisory firms for on-call support
  • Serve as the primary contact for institutional partner security due diligence and inbound questionnaires
  • Build and maintain a reusable compliance documentation package
  • Collaborate with legal counsel on security representations in commercial agreements
  • Develop and own security awareness training across all departments
  • Promote a proactive security culture across engineering, product, legal, and operational units

Requirements

What you’ll need
  • 7–10 years of progressive experience in information security, risk management, GRC, or compliance operations
  • Ideally experience within fintech, digital asset/crypto infrastructure, or B2B SaaS sectors
  • Demonstrated track record of building compliance programs from the ground up
  • Direct, hands-on ownership of full SOC 2 audits and ISO 27001 implementation/maintenance
  • Hands-on experience with modern GRC automation platforms such as Vanta or Drata
  • Experience with cloud environments, AWS preferred
  • Experience with infrastructure security integration within DevOps/IaaS workflows
  • Proven experience managing external audit relationships, penetration testing partners, and compliance vendors end-to-end
  • Ability to work multiple days per week on-site in the primary hub located in New York City
  • Ability to evaluate risks through likelihood, impact, and mitigation
  • Exceptional organizational skills with a strong focus on documentation, evidence collection, and tracking systems
  • Ability to navigate ambiguity, drive end-to-end projects, and balance strategic planning with tactical execution
  • Ability to build relationships across engineering, legal, product, and business units
  • Preferred: CISSP, CISM, CRISC, CySA+, or Cloud+
  • Preferred: experience with digital assets, stablecoins, smart contract security risks, and on-chain monitoring tools such as Chainalysis or BlockAid
  • Preferred: exposure to the GENIUS Act, MiCA, DORA, or global financial services regulations
  • Preferred: experience operating within multi-entity corporate structures

Benefits

Comp & perks
  • Market-leading base salary with equity/token grant participation tailored to experience
  • Access to global team flexibility with dedicated hub offices in New York City and Berlin
  • Comprehensive health insurance coverage
  • Wellness allowance
  • Sponsored gym access
  • Access to top-tier IT equipment and flexible workspace customization
  • Dedicated annual learning and development budget covering industry conferences, certifications, and international company retreats