Head of Security & Risk
M0
Job Description
Job Description
Intro
M0 is the shared infrastructure where businesses launch their own branded stablecoins and financial institutions power them. Built on a common standard, every stablecoin on M0 is interoperable and liquid from day one – giving businesses programmable control over how money moves in their ecosystems, and giving financial institutions the most advanced issuance stack in the industry.
M0 is seeking a sharp, execution-focused Head of Security & Risk to build and own the information security and risk function from the ground up. This is a foundational IC role at a critical inflection point for the company – M0 is onboarding regulated institutional partners, expanding its on-chain liquidity solutions, and operating infrastructure that regulated entities depend on. The information security and risk posture we establish in the next 12 months will define how M0 is perceived by partners, regulators, and institutional investors for years to come.
About the Role
Reporting to Deputy COO, you will be M0's first dedicated information security and risk professional – responsible for building the enterprise risk management program, owning the information security compliance certification roadmap, establishing the security operations framework, and responding to partner security due diligence requests. You will work daily across engineering, product, legal, BD, and operations to ensure that M0's security posture is proactive, documented, and defensible.
Key Responsibilities
- Build and Own Enterprise Risk Management : Build M0's enterprise risk program from scratch. Cover security, operational, regulatory, and counterparty risk, including the risk register, annual assessments, scenario analyses, and escalation framework across all entities.
- Own the Information Security Compliance Certification Program : Own M0's compliance posture across SOC 2, ISO 27001, and other applicable frameworks — driving all non-technical workstreams (policy writing, auditor coordination, vendor risk, access reviews, third-party SaaS vendor evaluations) and keeping the organization audit-ready at all times.
- Establish the Information Security Operations Framework : Design and maintain M0's incident response framework, ISMS documentation, and security policies — own external security vendor relationships, facilitate tabletop exercises covering IR, BCP, and DR scenarios, and drive the selection of a security advisory firm for on-call support.
- Own Partner Information Security Due Diligence : Serve as M0's primary point of contact for institutional partner security due diligence and inbound security questionnaires, build and maintain the reusable documentation package for responding to partner requests, and coordinate with Senior Counsel on information security representations in commercial agreements.
- Build Information Security Awareness & Culture : Design and own M0's security awareness training program, ensure all employees understand their security obligations, and build a proactive security culture across engineering, operations, legal, and business teams.
Qualifications
- 7–10 years of experience in information security, risk, GRC, or compliance operations, with meaningful ownership and a preference for fintech, crypto infrastructure, or B2B SaaS backgrounds.
- Demonstrated track record of building a compliance certification program from scratch, in-depth knowledge of compliance and regulatory frameworks, including hands-on end-to-end ownership of a full SOC 2 audit cycle, ISO 27001 implementation/maintenance, etc.
- Hands-on experience with GRC automation platforms (Vanta, Drata, or equivalent), cloud security environments (AWS preferred), and BCP/DR program design.
- Proven experience managing external audit relationships end-to-end (including auditors, penetration testing firms, and compliance vendors) and navigating evidence collection and report production.
- Working understanding of AWS, GCP, and Azure, including embedding security controls into DevOps workflows and Infrastructure as a Service (IaaS) deployments.
- Preferred certifications: Cloud+, CySA+, CISSP, or CISM.
Skills & Attributes
- A Proactive Risk Thinker: You think in terms of likelihood, impact, and mitigation, and you reason from first principles when regulations are unclear, translating complex risk into clear, business-relevant language.
- Exceptionally Organized and Process-Driven : You maintain rigorous documentation, evidence records, and program trackers across concurrent workstreams. Your outputs need to be right and audit-ready at all times, and you have a track record of improving processes, not just running them.
- A Builder with High Ownership : You are a self-starter with a "no job too big, no job too small" mentality. You look around corners to creatively solve problems and have a proven ability to own projects from concept to finish.
- An Excellent Communicator & Partner : You build trust across engineering, legal, product, and business by speaking their language, embedding compliance as a shared operating principle rather than an external checkpoint, and getting things done through influence rather than authority.
- Adaptable and Intellectually Curious : You have a positive attitude, comfort with ambiguity, and a relentless curiosity about new technologies. You have a passion for or a strong interest in crypto, blockchain technologies, and DeFi.
Nice to Haves
- Security Certifications : Professional certifications in security risk management such as CISSP, CISM, or CRISC are preferred.
- Crypto-Native Familiarity : Familiarity with digital assets, stablecoins, or blockchain infrastructure, including smart contract security risk and on-chain monitoring tools (BlockAid, Chainalysis, or similar).
- Regulatory Exposure : Familiarity with GENIUS Act, MiCA, DORA, or other emerging digital asset and financial services regulatory frameworks and their security and compliance implications.
- Multi-Entity Experience: Prior experience operating across a multi-entity structure (US operating entity, Cayman HoldCo, Swiss Foundation, or equivalent) is a plus.
- Location : Ability to work multiple days a week in our main hub office in NYC.
- Competitive compensation (base salary with equity/token grant) commensurate with experience.
- Global team and flexibility: Join a truly global team with the flexibility to work remotely or from one of our hubs in NYC or Berlin.
- Health and wellness: Enjoy comprehensive healthcare insurance coverage as well as a wellbeing allowance and gym membership to support your physical and mental health.
- Customizable IT setup: Tailor your workspace with access to top-notch IT equipment.
- Professional development: Benefit from an annual development budget to enhance your skills and grow professionally, including opportunities to participate in conferences and on-site company events worldwide.
- ...euros in interest with their investments. Team The Fraud & Risk Management Operations team protects Raisin’s U.S. business across... ...prevention a competitive advantage. Your Responsibilities The Head of Fraud & Risk Management Operations is Raisin US’s most senior...SuggestedFull timeWork from homeFlexible hoursShift work
- ...strategy, ensuring alignment with business objectives and regulatory requirements. Lead the Information Security function and oversee security operations, governance, risk management, and compliance initiatives. Design and implement enterprise-wide security architecture,...Suggested
$200k - $250k
...re a late‑stage AdTech company with strong internal alignment on security, a recently attained SOC 2 Type II attestation, and a clear... ...Own detection and monitoring across our AWS environment Run our risk management program (intake, triage, acceptance, reporting), ensuring...SuggestedWork at office2 days per week- ...A leading insurance firm in New York is seeking a Chief Underwriting Officer for their new Builders Risk insurance program. This executive will oversee the full buildout, including product development, reinsurance negotiations, and regulatory compliance. The ideal candidate...SuggestedFull time
- Head of Infrastructure Security | Global Alternative Investment Firm Head of Infrastructure Security | Global Alternative Investment Firm Get AI-powered... ...robust strategy that aligns with business objectives and risk posture Oversee secure configuration and operational...SuggestedFull timeWork at officeRemote work
$250k
...Managing Director & Head of Security and Defense, Public Sector Banking page is loaded## Managing Director & Head of Security and Defense, Public... ...and effectively manage the heightened role of franchise risk associated with the security and defense business* Have a broad...Full timeTemporary workWork at officeLocal area$160k - $200k
...Key Responsibilities The Investment Research Group (IRG) Head of Portfolio Risk & Analytics will lead the development and application of quantitative frameworks that support portfolio construction, risk management, and investment research across the Wealth Management...Full timeLocal area- ...architectures (AWS, Kubernetes), threat-model real systems, and ship security tooling yourself when the moment calls for it Experience in... ..., it's a precondition for the contracts we sign We're hiring a Head of Security to own the security function end-to-end. This is the...
$190k - $240k
Blockaid LTD is seeking a Director of Product Marketing to lead their Product Marketing team in New York City. The role involves close collaboration with product and go-to-market teams to create compelling messages that generate demand. Candidates should have strong experience...Full timeWork at officeRelocation package3 days per week- As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong and resilient. You help the firm grow... ...quo and striving to be best-in-class. As an Executive Director, Head of North America Capital Risk Coverage in Capital Risk Management...
- ...credential lifecycle, and fraud signals/decisioning. Design secure APIs and event-driven patterns enabling reusable trust services... ...budgets, disaster recovery, and operational readiness. Architect risk engines and policy frameworks that support adaptive...
$170k - $300k
...strategic messages and new disclosures to respond with the ever-evolving market environment.Investor Relations Director will report to the Head of Equity Investor Relations and has regular interaction with the Head of Investor Relations, Citi’s CFO, Business and Function...Full timeFlexible hours- Director of Investment Strategy We are looking for a Director of Investment Strategy to lead one of the most important commercial levers in the FanDuel Sportsbook business: how we allocate and optimize generosity investment across the lifecycle. This role sits at the...Full timeTemporary workLocal area
- ...Role Overview The Head of US IWPB Client Risk Management is within the First Line of Defense and is accountable for the effective governance... ...risks across Regulatory Compliance, Technology and Cyber Security, Legal, SOX, Operational Resilience, and Product Due Diligence...Full timeWork at office
- FanDuel is seeking a Director of Investment Strategy to lead generosity investment across the customer lifecycle, partnering with Marketing, Data Science, Finance, Go-to-market and Analytics to maximize long-term value. The role defines investment philosophy, capital ...Full time
$170k - $200k
VP, Investor Relations Director (PR/512949) New York, New York Salary: USD170000 - USD200000 per annum Key Responsibilities: Develop and execute comprehensive investor relations strategies tailored to the pharma and biotech sectors to enhance shareholder value and...Full time- Get AI-powered advice on this job and more exclusive features. Our client is a leader in the Digital Asset space and is looking to bring on an experienced Investor Relations professional. Job Description Cultivate and sustain strong relationships with institutional investors...16 hoursFull timeWork at office
$207.3k - $342k
...We are seeking a talented individual to join our Global Security team at Marsh. This role will be based in New York City. This is a hybrid... ..., Investigations, the Workplace Violence Program, Travel Risk Management, Guard Force Management, and Global Security Operations...Minimum wageFull timeWork at officeLocal areaRemote workWorldwideOverseasFlexible hours3 days per week1 day per week- ...resilience, offering a unique opportunity to shape the firm's tech risk strategy and enhance industry compliance. As a Tech Risk &... ...expectations for AI-assisted recommendations while maintaining security, auditability, and regulatory compliance outcomes. ~ Strong executive...
$132.42k - $217.55k
...Head of Risk & Resiliency As the Head of Risk & Resiliency, you will execute the Risk & Resiliency frameworks for Financial Protection & Retirement Solutions (FPRS) and Client Solutions & Wealth Management (CSWM) within Guardian’s Individual Markets lines of business....Full timeWork at officeWork from home- ...chance to achieve financial freedom. About the Role As our Head of Security, you'll help us maintain and radically improve a proactive security... ...ensures compliance with industry standards, mitigates real risks, and enhances client confidence in how we handle sensitive...Full timeCurrently hiringWork at office
- Citibank (Switzerland) AG is seeking an Investor Relations Director to manage relationships with institutional investors and ensure effective financial communications. The role includes developing materials for earnings presentations, drafting communications for senior...Full time
- ...New York University seeks a Director of Investments to develop and implement investment strategy and risk management frameworks across asset classes. Reporting to the CIO, this leader will oversee research, portfolio management, due diligence, and external manager relationships...Full timeWork at office
- Shoptalk is seeking a Director, Strategic Finance & Investor Relations in New York. This critical role requires a candidate with a strong background in corporate finance and analytical capabilities to support the senior leadership team with strategic initiatives and investor...Full time
$140k - $185k
Investor Relations Manager - Career Launch AI Talent Network Location: New York, NY Estimated Compensation: $140,000 - $185,000 total annual compensation (varies by employer) About This Posting This job description represents a sample Investor Relations Manager position...- ...Director Of Security Columbia Grammar and Preparatory School in New York City has engaged DovetailED to lead a search for a Director of Security to start in August 2026. Interested candidates should review the opportunity statement and submit a cover letter, resume...
$75k - $85k
...majority of these clients are diagnosed with mental illness, some dually with chemical addictions as well. Position: Director of Security & Operations Reports To: Vice President Location: Brooklyn, NY What The Director of Security & Operations Does:...Permanent employmentFull timeContract workLive inImmediate start$80k
...the support you need to advance your career while making a meaningful difference in people’s lives. Title Director of Operations & Security Reports to Regional Director Pay Range $80,000 -80,000 per year FLSA Status Exempt Status Full-time (35 hour per week) Role...Permanent employmentFull timeTemporary workWork at officeLocal areaTrial periodMonday to FridayShift work$138.2k - $179.65k
...are integrated into the fabric of how we work every day. To learn more, please see . What you'll do here: As the Director of Security Operations at Cengage, you will play a pivotal role in our ambitious Information Security department. You will lead an...Live inLocal areaWorldwide$95k - $130k
...About the Team Kafene’s Risk team is a key driver of growth for the business. As a Risk Manager, you will report to the VP of Risk and help build Kafene’s profit‑driven consumer underwriting strategies. You will harness complex data sources and machine learning, and partner...Work at officeFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Head of Security & Risk. Be the first to apply!
- chief security officer New York, NY
- head of security New York, NY
- director of corporate security New York, NY
- director of security New York, NY
- head of risk management New York, NY
- risk management manager New York, NY
- enterprise risk manager New York, NY
- director of risk management New York, NY
- risk management associate New York, NY
- operational risk manager New York, NY














