Skip to content
MorphoMorphoParis, France

Head of Security

Leads Morpho's organization-wide security strategy, builds the security function, and remains hands-on across cloud, infrastructure, application, identity, incident response, and counterparty security. The role requires 10+ years of security experience, leadership, crypto/web3 threat-model expertise, and certification experience.

Salary not listed
Remote10+ YOESecurity Engineering

About the role

Responsibilities

  • Own and continuously evolve Morpho's security strategy and roadmap across corporate, cloud/infrastructure, application, supply-chain, identity, and operational security.
  • Build and lead the security function by hiring, growing, and developing a team across security operations and application security.
  • Personally execute critical security work, including threat modeling, architecture reviews, control implementation, and incident command, while the team scales.
  • Establish a coherent governance architecture that connects tooling and controls.
  • Own incident response end to end, including runbooks, incident command, severity and escalation structures, and market communication.
  • Build and run a counterparty security program for curators and partners, including identity verification, screening, operational diligence, and bidirectional incident-coordination channels.
  • Lead the certification strategy, including SOC 2 and ISO 27001.
  • Represent Morpho's security posture internally to executives and externally to fintechs, financial institutions, integrators, and ecosystem partners.
  • Partner cross-functionally with Engineering, Protocol, and Integrations to drive security outcomes through direct ownership and influence.

What Success Looks Like

First 30 Days

  • Build an independent understanding of Morpho's security posture, architecture, threat model, and in-flight work.
  • Establish relationships with owners of critical security surfaces.
  • Understand the path-to-funds attack surface and identify the highest-severity risks and quick wins.
  • Assess incident-response readiness.

First 60 Days

  • Publish a prioritized security roadmap with sequencing, owners, and rationale.
  • Define the team build-out plan and open the first hire.
  • Drive the highest-severity gaps, including identity and authentication enforcement, deployment guardrails, and a documented incident-response runbook.
  • Establish the governance framework and begin the certification path.

First 90 Days

  • Close the highest-priority gaps and enforce key controls.
  • Validate documented incident-response capabilities through at least one tabletop exercise.
  • Begin hiring and establish an operating rhythm with Engineering, Protocol, and Integrations.
  • Develop Morpho's external security posture, including its trust surface, counterparty security program, and ecosystem engagement.

Must-Have Experience & Skills

  • 10+ years in security, including several years building or leading a security function, ideally in crypto/web3, fintech, or financial services.
  • Strong understanding of the crypto/web3 threat model.
  • Experience building and growing a security team from a small base, recruiting across security operations and application/infrastructure security.
  • Deep, hands-on expertise across cloud, infrastructure, CI/CD, supply-chain, identity, and application security.
  • End-to-end incident-response experience, including incident command and external communication.
  • Experience taking an organization through SOC 2, ISO 27001, or equivalent certification.
  • Strong prioritization and ability to drive outcomes through teams without direct authority.
  • Exceptional, organized, and responsive communication with executives and external audiences.
  • Humility.

Nice to Have

  • An established network or public profile in the security or crypto-security community.
  • Comfort representing security work publicly through talks, writing, or framework contributions.
  • Offensive security expertise or experience establishing red/blue capabilities.
  • Familiarity with institutional and regulatory expectations and threat-sharing networks such as Crypto ISAC and TIBER-style frameworks.

Perks & Benefits

  • Top-tier compensation.
  • Flexible work arrangements and time together in Paris.
  • Health coverage.
  • Support for continued learning.

Skills

Cloud Securityinfrastructure securityApplication SecurityCI/CDsupply chain securityidentity and access managementIncident ResponseThreat ModelingSOC 2ISO 27001Kubernetesthreat intelligence
Anvilogic

Director of Security & Compliance

AnvilogicUnited States

Leads customer-facing security reviews and the company’s internal security and compliance program, including SOC 2 Type II, ISO 27001, cloud security, IT operations, and a small technical team. Requires 10+ years of security experience and management experience.

Salary not listedRemote10+ YOESecurity Engineering
NexHealth

Head of IT & Security

NexHealthSan Francisco, CA

Leads NexHealth’s security governance, compliance, IT operations, vendor security, privacy, and incident response programs while building the security function and team. Requires 8+ years of security experience, leadership building programs from the ground up, audit ownership, and a software engineering background.

160k – 200k/yrOn-site8+ YOESecurity Engineering
GameChanger

Director, Information Security & Technology

GameChangerUnited States

Leads GameChanger’s information security and internal technology operations strategy, teams, and roadmap across product, cloud, AI, security operations, GRC, incident response, and employee IT. Requires 10+ years of security experience, leadership of managers, and broad program-building expertise.

220k – 240k/yrRemote10+ YOESecurity Engineering
Virta Health

Director, Security Engineering

Virta HealthUnited States

Leads enterprise security engineering and SecOps, directing a security team, outsourced MDR/SOC operations, incident response, and a Zero Trust transformation. Requires 10+ years in cybersecurity or cloud infrastructure security, leadership experience, and deep GCP, micro-segmentation, workload identity, and CI/CD expertise.

162k – 209k/yrRemote10+ YOESecurity Engineering
Fetch

Director, Trust & Safety Detection and Intelligence

FetchUnited States

Leads Fetch’s fraud detection and threat intelligence function, overseeing investigations, detection systems, risk prioritization, and anti-abuse strategy. Requires 10+ years in fraud, trust and safety, cybersecurity, or related risk work, plus 5+ years managing senior teams.

176k – 207k/yrRemote10+ YOESecurity Engineering