Quick Summary
Build and Own Enterprise Risk Management (ERM): Design and execute an enterprise risk management program from scratch. Oversee security, operational, regulatory, and counterparty risks,
7–10 years of progressive experience in information security, risk management, GRC, or compliance operations, ideally within fintech, digital asset/crypto infrastructure, or B2B SaaS sectors.
Responsibilities
~2 min read- →Build and Own Enterprise Risk Management (ERM): Design and execute an enterprise risk management program from scratch. Oversee security, operational, regulatory, and counterparty risks, including maintaining the risk register, leading annual risk assessments, performing scenario analyses, and establishing an escalation framework across all legal entities.
- →Lead Information Security Compliance & Certifications: Drive the compliance certification roadmap across frameworks such as SOC 2 and ISO 27001. Direct non-technical workstreams, including policy drafting, auditor coordination, vendor risk evaluations, third-party SaaS reviews, and periodic access reviews to maintain continuous audit readiness.
- →Establish Security Operations & Response Frameworks: Design and maintain the Information Security Management System (ISMS), security policies, and incident response frameworks. Manage external security vendor relationships, lead tabletop exercises across Incident Response (IR), Business Continuity Planning (BCP), and Disaster Recovery (DR) scenarios, and select external security advisory firms for on-call support.
- →Manage Partner Information Security Due Diligence: Act as the primary point of contact for institutional partner security due diligence and inbound questionnaires. Build and maintain a reusable compliance documentation package and collaborate with legal counsel on security representations within commercial agreements.
- →Drive Information Security Culture & Awareness: Develop and own the security awareness training curriculum across all departments. Promote a proactive security culture across engineering, product, legal, and operational units.
Requirements
~1 min read- Experience: 7–10 years of progressive experience in information security, risk management, GRC, or compliance operations, ideally within fintech, digital asset/crypto infrastructure, or B2B SaaS sectors.
- Compliance Expertise: Demonstrated track record of building compliance programs from the ground up, including direct, hands-on ownership of full SOC 2 audits and ISO 27001 implementation/maintenance.
- Technical & GRC Tooling: Hands-on experience with modern GRC automation platforms (e.g., Vanta, Drata), cloud environments (AWS preferred), and infrastructure security integration within DevOps/IaaS workflows.
- Vendor & Audit Management: Proven experience managing external audit relationships, penetration testing partners, and compliance vendors end-to-end.
- Location: Ability to work multiple days per week on-site in the primary hub located in New York City.
- Proactive Risk Mindset: Ability to evaluate risks through likelihood, impact, and mitigation, translating technical and regulatory complexities into clear, business-focused solutions.
- Process Rigor & Documentation: Exceptional organizational skills with a strong focus on maintaining pristine documentation, evidence collection, and tracking systems.
- High Ownership & Adaptability: A self-starter capable of navigating ambiguity, driving end-to-end projects, and balancing strategic planning with tactical execution.
- Strong Stakeholder Communication: Ability to build strong relationships across engineering, legal, product, and business units by promoting security as a shared operational standard.
Nice to Have
~1 min read- Certifications: Professional security certifications such as CISSP, CISM, CRISC, CySA+, or Cloud+.
- Digital Asset Familiarity: Experience with digital assets, stablecoins, smart contract security risks, and on-chain monitoring tools (e.g., Chainalysis, BlockAid).
- Regulatory Knowledge: Exposure to emerging digital asset frameworks such as the GENIUS Act, MiCA, DORA, or global financial services regulations.
- Multi-Entity Structure: Prior experience operating within multi-entity corporate structures (e.g., US entities, Cayman HoldCos, Swiss Foundations).
What We Offer
~1 min read- Behavioral Interview
- Hiring Manager Interview (Part I)
- Hiring Manager Interview (Part II)
- Hiring Manager Interview (Part III)
- Founder / CEO Interview
- Final Interview
At MLabs, we are committed to offer equal opportunities to all candidates. We ensure no discrimination, accessible job adverts, and providing information in accessible formats. Our goal is to foster a diverse, inclusive workplace with equal opportunities for all. If you need any reasonable adjustments during any part of the hiring process or you would like to see the job-advert in an accessible format please let us know at the earliest opportunity by emailing human-resources@mlabs.city.
MLabs Ltd collects and processes the personal information you provide such as your contact details, work history, resume, and other relevant data for recruitment purposes only. This information is managed securely in accordance with MLabs Ltd’s Privacy Policy and Information Security Policy, and in compliance with applicable data protection laws. Your data may be shared only with clients and trusted partners where necessary for recruitment purposes. You may request the deletion of your data or withdraw your consent at any time by contacting legal@mlabs.city.
Location & Eligibility
Listing Details
- Posted
- September 23, 2026
- First seen
- September 28, 2026
- Last seen
- September 28, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 46%
- Scored at
- September 28, 2026
Signal breakdown
Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.