← All rolesHead
Head of Security and Risk
MLabs · Software · 51-200 employees
New York, NY · Hybrid · full_time
One opening, also advertised in United States.
Listed by the employer as “Head of Security & Risk”. Title normalized for comparability.
CLI Career Level
VP-equivalent
Moderate confidence
Opportunity Score
61/100
Solid
Moderate confidence
Executive Fit
Sign in
Add your background to score this role against you
Career Level and Opportunity Score describe the role itself. Executive Fit is the only figure that depends on your profile.
First seen Sep 24, 2026 · Last verified 2 hours ago · Sourced from LinkedIn — Principal / GRC leadership (US)
CLI Take
Scope matches the title
CLI reads this as a VP-equivalent mandate, consistent with how the employer has titled it. CLI's analysis of the posting describes a strategic build or transformation mandate, and it carries SOC 2 and NIST 800-171 accountability. The posting reads closer to an individual contributor mandate: described as an individual contributor; hands-on delivery expected. The reporting line and team size are not disclosed and remain the main open questions before pursuing it.
Why this role scores the way it does
61/100 — solid opportunity quality. CLI reads this as a VP-equivalent mandate. Strongest signal: CLI's analysis of the posting describes a strategic build or transformation mandate. Main drag on the score: The posting reads closer to an individual contributor mandate: described as an individual contributor; hands-on delivery expected. 4 of 10 dimensions are not disclosed, which lowers confidence rather than the score.
Career level read
VP-equivalent — The employer lists this as “Head of Security & Risk”. CLI reads it as VP-equivalent because the role shows global responsibility; multinational responsibility; responsibility across business units.
Moderate confidence
What makes it attractive
- CLI's analysis of the posting describes a strategic build or transformation mandate.
- Scope language covers global responsibility; multinational responsibility; responsibility across business units.
What to probe before applying
- The posting reads closer to an individual contributor mandate: described as an individual contributor; hands-on delivery expected.
- Employer profile: 51-200 employee organization, privately held, bootstrapped.
Scoring components · Solid
Compensation versus comparable roles55 · weight 15%
The employer discloses a base range, but there is no comparable set to benchmark it against yet.
Reporting levelNot disclosed · excluded from the score
Reporting line: not disclosed.
Functional and geographic scope93 · weight 12%
Scope language covers global responsibility; multinational responsibility; responsibility across business units.
Quality of the mandate100 · weight 12%
CLI's analysis of the posting describes a strategic build or transformation mandate.
Executive and board exposureNot disclosed · excluded from the score
Executive and board exposure: not disclosed.
Role authority versus title25 · weight 10%
The posting reads closer to an individual contributor mandate: described as an individual contributor; hands-on delivery expected.
Company scale and trajectory25 · weight 10%
Employer profile: 51-200 employee organization, privately held, bootstrapped.
Team ownershipNot disclosed · excluded from the score
Team size: not disclosed.
Budget ownershipNot disclosed · excluded from the score
Budget ownership: not disclosed.
Risk signals50 · weight 5%
Signals worth probing: This is a foundational, individual contributor (IC) role at a critical inflection point for the organization. (Broad mandate for a single hire without initial headcount); Reporting directly to the Deputy Chief Operating Officer (Reporting line below the executive suite).
Dimensions the employer does not disclose are excluded and the remaining weights are rebalanced, so missing information lowers confidence rather than the score.
Sign in to see how this role scores against your background, and add your career goal to evaluate career value.
Compensation
$200,000 – $250,000 base salary, disclosed by employer
Sample size not yet sufficient for a market comparison
See the full benchmark bands by level and region
The mandate
Build and own the information security and enterprise risk management functions from the ground up as a foundational individual contributor. The leader will serve as the primary security authority, establishing ERM frameworks, driving SOC 2/ISO 27001 compliance, and managing institutional partner due diligence.
Reports to the Deputy Chief Operating Officer as a foundational individual contributor. Remit covers enterprise risk management, information security compliance, security operations, and partner due diligence for a digital asset infrastructure firm.
Domains and regulation
- GRC
- Enterprise Security
- Incident Response
- Third-Party Risk
- Compliance
- Resilience
- SOC 2
- NIST 800-171
Requirements
Must have
- 7-10 years of progressive experience in information security, risk management, GRC, or compliance operations.
- Demonstrated track record of building compliance programs from the ground up, including direct ownership of SOC 2 and ISO 27001.
- Proven experience managing external audit relationships, penetration testing partners, and compliance vendors end-to-end.
- Ability to work multiple days per week on-site in New York City.
Preferred / bonus
- Hands-on experience with modern GRC automation platforms (e.g., Vanta, Drata) and cloud environments (AWS preferred).
Only must-have items are scored as hard constraints in Executive Fit.
Likely challenges
- Foundational role building the entire ERM and InfoSec function from the ground up as an individual contributor.
- Managing institutional due diligence and security questionnaires for high-stakes financial partners.
- Navigating regulatory and operational demands of regulated financial institutions and digital asset infrastructure.
- Maintaining continuous audit readiness across SOC 2 and ISO 27001 in a rapid-growth environment.
Signals worth probing
- This is a foundational, individual contributor (IC) role at a critical inflection point for the organization. (Broad mandate for a single hire without initial headcount)
- Reporting directly to the Deputy Chief Operating Officer (Reporting line below the executive suite)
Not stated in the posting: Specific team size or growth projections for the security department.; Explicit board reporting duties, though the role is described as the 'primary security authority'..
About MLabs
MLabs is a software development consultancy that specializes in Haskell, Rust, and blockchain technologies. They provide engineering services for decentralized finance (DeFi) protocols, smart contract development, and formal verification. The firm operates globally as a remote-first organization focused on high-assurance software delivery.
- Industry
- Software
- Headcount
- 51-200 employees
- Headquarters
- London, United Kingdom
- Founded
- 2018
- Ownership
- Privately held
- Funding
- Bootstrapped
Full company profile for MLabs →
View original job description
Location: Remote - US Remote (Preference for NYC based candidates)Remote | Full-timeCompensation: $200K - $250KOur client operates shared financial infrastructure designed to enable businesses and institutional partners to launch and manage branded stablecoins and advanced digital asset issuance stacks. The platform provides fully interoperable, liquid on-chain solutions that grant businesses programmable control over payment ecosystems while meeting the stringent operational demands of regulated financial institutions.To support rapid growth and expanding institutional partnerships, our client is seeking a sharp, execution-focused Head of Security & Risk. This is a foundational, individual contributor (IC) role at a critical inflection point for the organization. In this position, the Head of Security & Risk will build and own the information security and enterprise risk management functions from the ground up.Reporting directly to the Deputy Chief Operating Officer, the individual will serve as the organization's primary security authority—establishing the enterprise risk framework, driving information security compliance, leading incident response and security operations, and managing institutional due diligence requests. This role requires close collaboration across engineering, product, legal, business development, and operations teams to ensure a proactive, audit-ready, and defensible security posture.Key Responsibilities:Build and Own Enterprise Risk Management (ERM): Design and execute an enterprise risk management program from scratch. Oversee security, operational, regulatory, and counterparty risks, including maintaining the risk register, leading annual risk assessments, performing scenario analyses, and establishing an escalation framework across all legal entitiesLead Information Security Compliance & Certifications: Drive the compliance certification roadmap across frameworks such as SOC 2 and ISO 27001. Direct non-technical workstreams, including policy drafting, auditor coordination, vendor risk evaluations, third-party SaaS reviews, and periodic access reviews to maintain continuous audit readinessEstablish Security Operations & Response Frameworks: Design and maintain the Information Security Management System (ISMS), security policies, and incident response frameworks. Manage external security vendor relationships, lead tabletop exercises across Incident Response (IR), Business Continuity Planning (BCP), and Disaster Recovery (DR) scenarios, and select external security advisory firms for on-call supportManage Partner Information Security Due Diligence: Act as the primary point of contact for institutional partner security due diligence and inbound questionnaires. Build and maintain a reusable compliance documentation package and collaborate with legal counsel on security representations within commercial agreementsDrive Information Security Culture & Awareness: Develop and own the security awareness training curriculum across all departments. Promote a proactive security culture across engineering, product, legal, and operational unitsRequirementsQualificationsExperience: 7-10 years of progressive experience in information security, risk management, GRC, or compliance operations, ideally within fintech, digital asset/crypto infrastructure, or B2B SaaS sectorsCompliance Expertise: Demonstrated track record of building compliance programs from the ground up, including direct, hands-on ownership of full SOC 2 audits and ISO 27001 implementation/maintenanceTechnical & GRC Tooling: Hands-on experience with modern GRC automation platforms (e.g., Vanta, Drata), cloud environments (AWS preferred), and infrastructure security integration within DevOps/IaaS workflowsVendor & Audit Management: Proven experience managing external audit relationships, penetration testing partners, and compliance vendors end-to-endLocation: Ability to work multiple days per week on-site in the primary hub located in New York CitySkills & Core AttributesProactive Risk Mindset: Ability to evaluate risks through likelihood, impact, and mitigation, translating technical and regulatory complexities into clear, business-focused solutionsProcess Rigor & Documentation: Exceptional organizational skills with a strong focus on maintaining pristine documentation, evidence collection, and tracking systemsHigh Ownership & Adaptability: A self-starter capable of navigating ambiguity, driving end-to-end projects, and balancing strategic planning with tactical executionStrong Stakeholder Communication: Ability to build strong relationships across engineering, legal, product, and business units by promoting security as a shared operational standardPreferred / Nice To HavesCertifications: Professional security certifications such as CISSP, CISM, CRISC, CySA+, or Cloud+Digital Asset Familiarity: Experience with digital assets, stablecoins, smart contract security risks, and on-chain monitoring tools (e.g., Chainalysis, BlockAid)Regulatory Knowledge: Exposure to emerging digital asset frameworks such as the GENIUS Act, MiCA, DORA, or global financial services regulationsMulti-Entity Structure: Prior experience operating within multi-entity corporate structures (e.g., US entities, Cayman HoldCos, Swiss Foundations)BenefitsCompetitive Compensation: Market-leading base salary with equity/token grant participation tailored to experienceFlexible Work Model: Access to global team flexibility with dedicated hub offices in New York City and BerlinComprehensive Healthcare & Wellbeing: Comprehensive health insurance coverage, a wellness allowance, and sponsored gym accessCustom Hardware & IT Allowance: Access to top-tier IT equipment and flexible workspace customizationProfessional Growth: Dedicated annual learning and development budget covering industry conferences, certifications, and international company retreatsInterview ProcessBehavioral InterviewHiring Manager Interview (Part I)Hiring Manager Interview (Part II)Hiring Manager Interview (Part III)Founder / CEO InterviewFinal InterviewDue to the high volume of applications we anticipate, we regret that we are unable to provide individual feedback to all candidates. If you do not hear back from us within 4 weeks of your application, please assume that you have not been successful on this occasion. We genuinely appreciate your interest and wish you the best in your job search.Commitment to Equality and Accessibility:At MLabs, we are committed to offer equal opportunities to all candidates. We ensure no discrimination, accessible job adverts, and providing information in accessible formats. Our goal is to foster a diverse, inclusive workplace with equal opportunities for all. If you need any reasonable adjustments during any part of the hiring process or you would like to see the job-advert in an accessible format please let us know at the earliest opportunity by emailing human-resources@mlabs.city.MLabs Ltd collects and processes the personal information you provide such as your contact details, work history, resume, and other relevant data for recruitment purposes only. This information is managed securely in accordance with MLabs Ltd's Privacy Policy and Information Security Policy, and in compliance with applicable data protection laws. Your data may be shared only with clients and trusted partners where necessary for recruitment purposes. You may request the deletion of your data or withdraw your consent at any time by contacting legal@mlabs.city.
Cyber Leadership Index is not the employer and does not represent candidates for these roles. Verify all details with the employer before acting.