Leads Morpho's organization-wide security strategy, builds the security function, and remains hands-on across cloud, infrastructure, application, identity, incident response, and counterparty security. The role requires 10+ years of security experience, leadership, crypto/web3 threat-model expertise, and certification experience.
Salary not listed
Remote10+ YOESecurity Engineering
About the role
Responsibilities
Own and continuously evolve Morpho's security strategy and roadmap across corporate, cloud/infrastructure, application, supply-chain, identity, and operational security.
Build and lead the security function by hiring, growing, and developing a team across security operations and application security.
Personally execute critical security work, including threat modeling, architecture reviews, control implementation, and incident command, while the team scales.
Establish a coherent governance architecture that connects tooling and controls.
Own incident response end to end, including runbooks, incident command, severity and escalation structures, and market communication.
Build and run a counterparty security program for curators and partners, including identity verification, screening, operational diligence, and bidirectional incident-coordination channels.
Lead the certification strategy, including SOC 2 and ISO 27001.
Represent Morpho's security posture internally to executives and externally to fintechs, financial institutions, integrators, and ecosystem partners.
Partner cross-functionally with Engineering, Protocol, and Integrations to drive security outcomes through direct ownership and influence.
What Success Looks Like
First 30 Days
Build an independent understanding of Morpho's security posture, architecture, threat model, and in-flight work.
Establish relationships with owners of critical security surfaces.
Understand the path-to-funds attack surface and identify the highest-severity risks and quick wins.
Assess incident-response readiness.
First 60 Days
Publish a prioritized security roadmap with sequencing, owners, and rationale.
Define the team build-out plan and open the first hire.
Drive the highest-severity gaps, including identity and authentication enforcement, deployment guardrails, and a documented incident-response runbook.
Establish the governance framework and begin the certification path.
First 90 Days
Close the highest-priority gaps and enforce key controls.
Validate documented incident-response capabilities through at least one tabletop exercise.
Begin hiring and establish an operating rhythm with Engineering, Protocol, and Integrations.
Develop Morpho's external security posture, including its trust surface, counterparty security program, and ecosystem engagement.
Must-Have Experience & Skills
10+ years in security, including several years building or leading a security function, ideally in crypto/web3, fintech, or financial services.
Strong understanding of the crypto/web3 threat model.
Experience building and growing a security team from a small base, recruiting across security operations and application/infrastructure security.
Deep, hands-on expertise across cloud, infrastructure, CI/CD, supply-chain, identity, and application security.
End-to-end incident-response experience, including incident command and external communication.
Experience taking an organization through SOC 2, ISO 27001, or equivalent certification.
Strong prioritization and ability to drive outcomes through teams without direct authority.
Exceptional, organized, and responsive communication with executives and external audiences.
Humility.
Nice to Have
An established network or public profile in the security or crypto-security community.
Comfort representing security work publicly through talks, writing, or framework contributions.
Offensive security expertise or experience establishing red/blue capabilities.
Familiarity with institutional and regulatory expectations and threat-sharing networks such as Crypto ISAC and TIBER-style frameworks.
Perks & Benefits
Top-tier compensation.
Flexible work arrangements and time together in Paris.
Leads customer-facing security reviews and the company’s internal security and compliance program, including SOC 2 Type II, ISO 27001, cloud security, IT operations, and a small technical team. Requires 10+ years of security experience and management experience.
Salary not listedRemote10+ YOESecurity Engineering
Head of IT & Security
NexHealthSan Francisco, CA
Leads NexHealth’s security governance, compliance, IT operations, vendor security, privacy, and incident response programs while building the security function and team. Requires 8+ years of security experience, leadership building programs from the ground up, audit ownership, and a software engineering background.
160k – 200k/yrOn-site8+ YOESecurity Engineering
Director, Information Security & Technology
GameChangerUnited States
Leads GameChanger’s information security and internal technology operations strategy, teams, and roadmap across product, cloud, AI, security operations, GRC, incident response, and employee IT. Requires 10+ years of security experience, leadership of managers, and broad program-building expertise.
220k – 240k/yrRemote10+ YOESecurity Engineering
Director, Security Engineering
Virta HealthUnited States
Leads enterprise security engineering and SecOps, directing a security team, outsourced MDR/SOC operations, incident response, and a Zero Trust transformation. Requires 10+ years in cybersecurity or cloud infrastructure security, leadership experience, and deep GCP, micro-segmentation, workload identity, and CI/CD expertise.
162k – 209k/yrRemote10+ YOESecurity Engineering
Director, Trust & Safety Detection and Intelligence
FetchUnited States
Leads Fetch’s fraud detection and threat intelligence function, overseeing investigations, detection systems, risk prioritization, and anti-abuse strategy. Requires 10+ years in fraud, trust and safety, cybersecurity, or related risk work, plus 5+ years managing senior teams.