IT Security and Compliance Lead
Chorus One is one of the leading operators of infrastructure for Proof-of-Stake networks and decentralized protocols. Tens of thousands of retail customers and institutions are staking billions in assets through our infrastructure helping to secure protocols and earn rewards. Our mission is to Operate infrastructure for decentralized networks that increase freedom and sovereignty.
We are a diverse team of around 50 people distributed all over the globe. We value radical transparency, striving for excellence and continuous improvement while treating each other with kindness and generosity. If this sounds like you, we’d love to hear from you. To support the company’s growing security needs Chorus One is looking for an IT Security and Compliance Lead to join our team. You will be the security and compliance subject matter expert within Chorus One and be responsible for leading compliance projects end to end, from planning phase through execution, closure phase and ongoing monitoring.
- Work with teams and stakeholders to develop, implement, and maintain information security policies, procedures, and standards to comply with business relevant security standards and frameworks (ISO 27001, SOC 2) as well as relevant legal and regulatory requirements.
- Coordinate vulnerability assessments and penetration tests on network systems and applications (Chorus One’s public APIs).
- Monitor and conduct internal audits of the system environment, policies and procedures. Develop and maintain timelines, roadmaps, and list of required tasks for various teams based on the outcomes.
- Analyze and report on security threats and incidents, triage resolution, and develop controls and strategies to mitigate those risks.
- Research and recommend security solutions to mitigate security risks and improve existing practices and technologies to align with the organization’s risk tolerance and ensure regulatory compliance.
- Assist sales in responding to prospect and customer inquiries about Chorus One’s security and compliance posture.
- Administer security and awareness training for the team.
What we are looking for:
- Experience leading and implementing security frameworks, such as ISO 27001, SOC 2, GDPR from start to finish.
- 5+ years of relevant Information Security experience.
- Functional knowledge of security domains and information security industry standard and best practices.
- Proven experience in building and maintaining security policies and controls, processes, and procedures.
- Expertise in security architecture and design, network security, and data protection.
- Ability to identify security threats and vulnerabilities within an organization and develop suitable countermeasures.
- Ability to identify and recommend tools, processes, and software to automate and continuously improve security and compliance practices.
- Strong organizational skills, proactive and self-sufficient with a proven ability to work independently and prioritize deliverables.
- Strong communication and interpersonal skills to liaise with stakeholders.
- Previous work experience in the crypto space and understanding of blockchain technology and associated risks.
- Certifications such as CISSP, CISM, CISA, ISO 27001 Lead Auditor / Implementer or similar.
What we offer:
- Autonomy and ownership in a friendly and supportive work environment and the opportunity for rapid growth.
- Remote, but not alone. We are a strong global collaborative environment.
- Gather experience and build your network in the crypto ecosystem.
- 80,000-110,000 EUR/year compensation + benefits, equity
- All-expense paid quarterly team retreats at various destinations (Coronavirus permitting). Past retreats took place in Greece, Portugal, Egypt, Serbia, Kenya, USA, South Korea, and Dubai.
- Remote working budget (Laptop, co-working space, etc)
- Personal development budget