# Head of Security

**Company:** [Morpho](https://hotfix.jobs/companies/morpho)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 10+ years
**Skills:** Cloud Security, infrastructure security, Application Security, CI/CD, supply chain security, identity and access management, Incident Response, Threat Modeling, SOC 2, ISO 27001, Kubernetes, threat intelligence
**Posted:** 2026-06-24

> Leads Morpho's organization-wide security strategy, builds the security function, and remains hands-on across cloud, infrastructure, application, identity, incident response, and counterparty security. The role requires 10+ years of security experience, leadership, crypto/web3 threat-model expertise, and certification experience.

## Job Description

## Responsibilities
- Own and continuously evolve Morpho's security strategy and roadmap across corporate, cloud/infrastructure, application, supply-chain, identity, and operational security.
- Build and lead the security function by hiring, growing, and developing a team across security operations and application security.
- Personally execute critical security work, including threat modeling, architecture reviews, control implementation, and incident command, while the team scales.
- Establish a coherent governance architecture that connects tooling and controls.
- Own incident response end to end, including runbooks, incident command, severity and escalation structures, and market communication.
- Build and run a counterparty security program for curators and partners, including identity verification, screening, operational diligence, and bidirectional incident-coordination channels.
- Lead the certification strategy, including SOC 2 and ISO 27001.
- Represent Morpho's security posture internally to executives and externally to fintechs, financial institutions, integrators, and ecosystem partners.
- Partner cross-functionally with Engineering, Protocol, and Integrations to drive security outcomes through direct ownership and influence.

## What Success Looks Like
### First 30 Days
- Build an independent understanding of Morpho's security posture, architecture, threat model, and in-flight work.
- Establish relationships with owners of critical security surfaces.
- Understand the path-to-funds attack surface and identify the highest-severity risks and quick wins.
- Assess incident-response readiness.

### First 60 Days
- Publish a prioritized security roadmap with sequencing, owners, and rationale.
- Define the team build-out plan and open the first hire.
- Drive the highest-severity gaps, including identity and authentication enforcement, deployment guardrails, and a documented incident-response runbook.
- Establish the governance framework and begin the certification path.

### First 90 Days
- Close the highest-priority gaps and enforce key controls.
- Validate documented incident-response capabilities through at least one tabletop exercise.
- Begin hiring and establish an operating rhythm with Engineering, Protocol, and Integrations.
- Develop Morpho's external security posture, including its trust surface, counterparty security program, and ecosystem engagement.

## Must-Have Experience & Skills
- 10+ years in security, including several years building or leading a security function, ideally in crypto/web3, fintech, or financial services.
- Strong understanding of the crypto/web3 threat model.
- Experience building and growing a security team from a small base, recruiting across security operations and application/infrastructure security.
- Deep, hands-on expertise across cloud, infrastructure, CI/CD, supply-chain, identity, and application security.
- End-to-end incident-response experience, including incident command and external communication.
- Experience taking an organization through SOC 2, ISO 27001, or equivalent certification.
- Strong prioritization and ability to drive outcomes through teams without direct authority.
- Exceptional, organized, and responsive communication with executives and external audiences.
- Humility.

## Nice to Have
- An established network or public profile in the security or crypto-security community.
- Comfort representing security work publicly through talks, writing, or framework contributions.
- Offensive security expertise or experience establishing red/blue capabilities.
- Familiarity with institutional and regulatory expectations and threat-sharing networks such as Crypto ISAC and TIBER-style frameworks.

## Perks & Benefits
- Top-tier compensation.
- Flexible work arrangements and time together in Paris.
- Health coverage.
- Support for continued learning.

## Similar roles

- [Director of Security & Compliance](https://hotfix.jobs/jobs/969092f3-4fc3-4400-98f9-4babfad7d7a8) - Anvilogic - Remote
- [Head of IT & Security](https://hotfix.jobs/jobs/9d80b823-e1b2-4da6-8807-713816b09be9) - NexHealth - San Francisco, CA - $160k – $200k/yr
- [Director, Information Security & Technology](https://hotfix.jobs/jobs/206a3607-4d09-42a8-8ff7-ff8d9b3096f3) - GameChanger - Remote - $220k – $240k/yr
- [Director, Security Engineering](https://hotfix.jobs/jobs/121737e7-8a7c-4c2e-a7ba-806e477a9491) - Virta Health - Remote - $162k – $209k/yr
- [Director, Trust & Safety Detection and Intelligence](https://hotfix.jobs/jobs/1f7e0b07-06b8-4f92-9bb2-cd2b6d396d03) - Fetch - Remote - $176k – $207k/yr

**Apply:** https://hotfix.jobs/jobs/dcec0d4d-db7a-4867-ad6a-6e9002bf2dbf
**Canonical:** https://hotfix.jobs/jobs/dcec0d4d-db7a-4867-ad6a-6e9002bf2dbf