Security Risk Lead
Framework Ventures
About BitMEX. BitMEX stands as a globally leading exchange for crypto derivatives, offering traders a professional‑grade trading platform. Since its inception in 2014, BitMEX has maintained an impeccable security record with “no coin lost, ever!”. Our platform caters to cryptocurrency derivatives traders by providing low latency, deep liquidity, and maximum availability. Currently, BitMEX offers more than 100 derivatives contracts, 16 pairs for spot trading, and an easy covert function between 30+ different cryptocurrencies. In 2015, BitMEX revolutionised the market by inventing the Perpetual Swap, which has since become the most widely traded crypto product. Demonstrating a commitment to transparency, since 2021, BitMEX has been among the first exchanges to regularly publish its on‑chain Proof of Reserves and Proof of Liabilities, ensuring that the funds available exceed the total client balances. For more information on BitMEX, company initiatives and our products, please visit the BitMEX Blog or and follow LinkedIn, Discord, Telegram. Role Overview This is a critical role to bootstrap BitMEX's Security Assurance practice, responsible for architecting our Security Policy and Risk Management frameworks with compliance‑as‑code as the foundational pillar of our strategy. The position is highly technical in nature and is expected to operationalise our security common controls framework. As the Security Risk Lead, you will also collaborate with stakeholders on the successful execution of SOC2 audits and other security initiatives. This role is for a highly experienced technical security engineer ready to expand beyond technical execution. We're seeking a candidate with a strong blend of technical and business acumen, proven experience influencing decisions on regulatory standards, and excellent communication skills. Key Responsibilities Translate regulatory and compliance requirements into code and actionable technical controls. Ensure accurate identification, communication, and mitigation of risks, processes, and internal control gaps with potential adverse operational risk implications. Operationalise the delivery of several security metrics. Deliver various threat modeling spot checks. Perform deep‑dived technical risk assessments. Provide security training and outreach to internal tech teams. Facilitate the execution of external audits over BitMEX's products and internal controls in accordance with, but not limited to, SOC2 and ISO27001. Qualifications 10+ years of security industry experience with a strong background in software development including at least 3 years of hands‑on experience. Demonstrated success in leading technical teams in a cloud‑first environment with deep knowledge of Amazon Web Services and general cloud infrastructure security. Expert on GRC processes to consistently automate and supervise information security controls, testing, and risks. Knowledge of network security architecture concepts, including topology, protocols, components, and principles. Hands‑on experience with Open Policy Agent, InSpec, or CloudFormation Guard. Demonstrated knowledge and expertise in written responses to regulators. Proficient in managing complex global infrastructure as code. Good to have Demonstrated experience researching, building, and implementing defensive security systems that are used against internal and external attack vectors. Comfortable operating across a wide variety of platforms and technologies. Relevant certifications like CISSP, CISA, AWS CCP, CIPP, or CIPT are preferred. Prior experience of working in security and privacy compliance engineering or similar groups at a tech or fintech firm. Why BitMEX? BitMEX offers a dynamic environment that blends intense work, a vibrant culture, and diversity. We actively recruit across time zones to meet growing demands and attract top global talent. We're seeking determined, responsible, and collaborative individuals to join us in building a leading cryptocurrency ecosystem. We value meticulousness, agility, and simplicity. As a 24/7 global exchange, we look for adaptable team players who can excel in a diverse, cross‑market environment. We provide flexible arrangements to our remote contract talents with: Work from home to help you find the perfect balance between work, family and personal life Paid holidays and leave so you won’t miss out on any important events Team building & off‑site events to bring our global team closer Advantage of our Beyond Border Remote Working policy, where you get to work away from your home country Option to choose to be paid in fiat or crypto currency, providing the flexibility to shape your financial freedom #J-18808-Ljbffr
- ...Owner.com is seeking a GRC Specialist to navigate complex Risk, Compliance, and Vulnerability Management as we grow. You will drive compliance efforts, secure systems, and advise senior leadership in security risks. Requires 3+ years in compliance frameworks and 5+ years...RiskRemote work
- ...Framework Ventures is seeking a Security GRC Lead to enhance trust and safeguard reputation by scaling governance, risk, and compliance programs. The ideal candidate will have over 6 years of experience in security governance, risk management, and compliance, with deep...RiskRemote workFlexible hours
- ...Rsi-Security is hiring an External Industry Risk & Security Governance Representative to serve as a voting member of the Impartiality Committee. This role requires over 10 years of experience in enterprise security, risk management, or governance oversight. The candidate...RiskFor contractorsRemote work
- A leading fintech company in New York is seeking a Senior GRC Lead who will bridge compliance... ...manage critical GRC processes to enhance risk management and compliance measures.... ...have over 5 years of experience in GRC or Security Engineering and proficiency in key security...RiskWork at office
- ...Keyrock is looking for a Senior Security Program Manager to lead security initiatives in a high-paced trading environment. You will be responsible for driving execution of security programs, ensuring risk management, and fostering successful collaboration across teams...RiskRemote work
- ...Genie is seeking an experienced professional in information security to oversee governance, risk management, and compliance within their financial wellness platform. The role includes developing policies, leading risk assessments, maintaining compliance, and ensuring...RiskRemote jobFlexible hours
$95k - $105k
...Subsplash is looking for a Senior GRC Analyst to integrate people, policy, and technology to enhance security and risk operations. This role involves leading compliance audits, developing data flows, and tracking risk management metrics. With a competitive compensation...RiskRemote work- ...A growing high-tech company seeks a Cybersecurity Lead to oversee security and compliance for network infrastructure. You will design and implement measures to safeguard assets, manage risk, and ensure compliance with DoD standards. The role requires expertise in security...RiskFull timeRemote work
$140k - $245k
Figma is seeking a Technical Program Manager to enhance their Security Operations team in New York. In this full-time role, you will manage critical programs focusing on risk management and security alignment across various teams. A strong background in program management...RiskFull time- ...Lead Certified CMMC Assessor (Lead CCA) We are MNS Group: cybersecurity professionals,... ...Industrial Base. Our work supports national security, our culture values humility, joy, drive,... ...of federal cybersecurity requirements, risk management, and the ability to communicate...RiskFor contractors
- ...A leading information security platform is seeking an Information Security Consultant to establish and maintain a corporate-wide information security... ...degree in a relevant field and 3-6 years of experience in risk management and information security, with professional...RiskRemote work
$136.8k - $228k
Yext is seeking a Senior Security Governance Manager to enhance its cybersecurity program, ensuring effective governance across key initiatives. The successful candidate will oversee cybersecurity risk management while developing control frameworks and metrics. Key responsibilities...Risk- Dentsu Aegis Network Ltd. is hiring an Information Security Lead in New York. This role is critical for managing security risks within the CxM Practice Area and involves leading information security efforts, embedding security controls, and ensuring the security of client...RiskPermanent employmentFull timeContract work
- ...IAM Lead Consultant We are currently seeking an IAM/PAM Lead Consultant to join our... ...platforms while ensuring strong governance, risk management, and regulatory compliance.... ...auditing Conduct risk assessments and security audits to identify vulnerabilities Develop...Risk
- ...cybersecurity expert to develop and maintain the State's Medicaid Data Warehouse security plans, ensuring compliance with security standards. The role involves collaboration with auditors, vendor risk assessments, and effective communication of security risks to various...RiskRemote work
- ...client goals and tactical execution. You will lead the CMMC readiness Service Delivery... ...final review gate for client deliverables (Risk Assessments, SSPs, Executive Reports).... ...Boards/C‑Suits where applicable to align security initiatives with business objectives. Strategic...RiskRemote work
- ...BitMEX is looking for a Security Risk Lead to bootstrap its Security Assurance practice. The role involves architecting security policies and managing risk frameworks, collaborating on SOC 2 audits, and operationalizing security controls. The ideal candidate has over...RiskRemote work
- ...QinetiQ US is seeking a Cybersecurity Lead to enhance satellite communications security. In this role, you will guide cybersecurity efforts, develop requirements, and perform risk assessments in a dynamic environment supporting the US Space Force. The ideal candidate has...Risk
- ...certified women-owned business in the US seeks a Mainframe Top Secret Security Administrator to oversee data security and compliance. This role... ...should have a deep understanding of security compliance, risk mitigation, and pertinent tools like Informatic Power Exchange....RiskRemote work
- ...AI Security Lead / Architect New York, NY (Hybrid, 3 days in office) Highly competitive compensation package Join an elite technology... ...automation. ~ Demonstrated leadership in making pragmatic, risk-based decisions in situations with high levels of ambiguity....RiskWork at office
- ...GTM Talent Acquisition Lead New York - Hybrid At Oasis Security, we're redefining how enterprises manage access in the age of AI. Every organization deploying AI agents is taking on access risks they can't yet see, and the tools they've relied on were never built...Risk
$118.98k - $195.47k
...Lead – Cyber Risk & Control Monitoring Do you want to be part of a collaborative Cybersecurity Governance team? Are you a problem solver who enjoys diving into security risk, translating complex technical concepts for business partners, and driving meaningful risk reduction...RiskWork at officeFlexible hours3 days per week- ...50+ emails, and pull in Finance, Legal, Security, and IT just to get something approved.... ...approvals and renewals, real-time supplier risk, and complete spend visibility. The opportunity... ...our CTO, product & engineering teams leading all customer deployment work and becoming...RiskContract work
- Oura is seeking a Senior Governance, Risk, Compliance (GRC) Analyst to join the Security Team in New York City. This role involves leading GRC initiatives, managing compliance policies, and performing risk assessments. Candidates should have over 6 years of experience in...RiskRemote workFlexible hours
- ...3days a week in NYC NYC Technical Tech Lead Network Security Manage a small team of talented network security engineers... ...zero trust architecture and micro segmentation to reduce the risk of lateral movement by attackers Conduct risk assessments...Risk
- ...+ emails , and pull in Finance, Legal, Security, and IT just to get something approved.... ...approvals and renewals, real-time supplier risk, and complete spend visibility.... ...we're looking for We're hiring a GTM Lead to own revenue targets and scale our business...RiskWork at office
- ...Application Security Lead Our client is a global financial services firm located in New York City. They are seeking an Application Security... ...security and vulnerability analyses, penetration testing and risk assessments Partnering with Developers to implement security...Risk
- ...The AI Platform Lead owns the definition, creation, and ongoing management of ULS’s enterprise... ...; prioritizing platform reliability, security, governance, and scale; and ensuring... ...Cyber Security, Enterprise Architecture, Risk & Compliance, and strategic vendors to align...RiskLocal areaRemote workFlexible hoursShift work
- A leading crypto company is seeking a Fraud & Risk Lead to oversee fraud operations for its credit card program. This role entails real-time monitoring, strategic fraud detection, and collaboration with engineering teams to enhance fraud prevention mechanisms. The ideal...Risk
- A leading global technology firm is looking for an Information Security Lead in New York to drive security initiatives within the CxM Practice Area. This role involves... ...products and services while managing security risks effectively. The ideal candidate should have relevant...RiskPermanent employmentFull timeContract work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Risk Lead. Be the first to apply!

