BitPay
Chief Information Security Officer
NEWRemoteFull-timeGlobal
š° USD 200,000 - 250,000/yr
š Executiveš Remote
RemoteRemote work position availableActivePosted within the last 30 days
Job Description
[AI-summarized by JobStash]
You will lead and execute the information security program and IT operations. You will develop security policies and metrics, manage incident response and business continuity, oversee vendor and third-party risk, coordinate audits and regulatory compliance, and hire coach and grow IT and security staff. You will collaborate with executives and stakeholders to align security with business priorities and continuously monitor trends to anticipate and mitigate risks.
Requirements
- ā8+ years of hands-on technical security experience with 4+ years leading teams or programs
- āExperience working with global cross-functional teams
- āExperience leading security compliance projects such as SOC 2 audits cybersecurity risk assessments and regulatory requirements
- āWorking knowledge of systems architecture and implementations including cloud hybrid cloud DevOps and open-source
- āWorking knowledge of secure AI use and best practices
- āKnowledge of security standards and frameworks such as NYDFS Part 500 DORA GDPR and NIST CSF
- āPractical knowledge of securing remote work environments
- āExperience with GPG key management and remote identity authentication
- āHands-on endpoint security management for Mac OS
- āKnowledge of applicable laws and regulations such as SOX and GLBA
- āExcellent oral and written communication skills
- āStrong organizational and time management skills and demonstrated ability to manage teams and set priorities
- āAbility to work remotely and collaborate across time zones
- āBS or MS in Computer Science Computer Security Computer Engineering or related field
- āPreferred Certified Information Security Manager CISM or Certified Information Systems Security Professional CISSP
- āPreferred experience in the crypto industry or fintech payments and experience at an audit or advisory services firm
Responsibilities
- āDevelop and enhance the overall information security program focusing on architecture threat management identity and access management vendor management and regulatory compliance
- āExecute tactical components of the strategic information security vision
- āAnalyze business priorities and risk exposure to protect critical systems and data
- āDevelop and maintain security metrics and goals
- āDraft and maintain information security policies and procedures to meet best practices and regulatory requirements
- āManage expectations of leadership customers third-party partners and employees
- āDirect information governance activities including SOC 2 audits NYDFS Part 500 EU DORA risk assessments and penetration tests
- āLead security committees and working groups
- āManage incident response business continuity and disaster recovery programs
- āManage endpoint security
- āConduct third-party risk assessments and manage audit deliverables
- āRepresent the company in discussions with auditors and regulators
- āManage security vendor and supplier relationships
- āHire train and manage a team of IT and security professionals and conduct performance reviews
- āManage department budgets and build business cases for security and IT investments
- āLead security training and awareness efforts and build a culture of compliance
- āContinuously monitor security trends and plan for emerging risks
- āProvide collaborative leadership and security advisory across departments
Benefits & Perks
- ā100% employer-paid medical and dental insurance
- āTelemedicine coverage
- āLife and disability insurance
- āVision coverage
- ā401(k)
- āTravel assistance
- āGenerous vacation policy including sabbatical and ability to select holidays
- āProfessional development reimbursement
- āOption to receive payment in cryptocurrency and a crypto match program
- āStock option awards
- āHome office allowance and reimbursement for internet and cell expenses
- āComplimentary Amazon Prime and Spotify subscriptions
- āRemote work
Tech Stack
endpoint securitymodel governanceDevOpsDORAincident responsebusiness continuityNYDFSsecurity architectureidentity and access managementinformation security