Search...

Chief Information Security Officer

Bakkt logo
Bakkt

Bakkt is a digital asset platform providing stablecoin settlement, programmable payments, and financial infrastructure services for banks, fintechs, and payments providers.

10000 Avalon Boulevard, Suite 1000, Alpharetta, Georgia 30009, United States
About Bakkt

Bakkt provides digital asset services for financial institutions, fintechs, and payments providers, with capabilities spanning stablecoin settlement, programmable payments, and loyalty solutions. Users can access custody, trading, and onramp tools through the platform. The company operates as a financial infrastructure provider focused on banking and payments applications.

View jobs by Bakkt

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will lead Bakkt’s global information security posture, own regulatory cybersecurity compliance, brief executive leadership and the Board, establish security governance for AI and stablecoin infrastructure, implement zero-trust architecture and continuous compliance, integrate security into development pipelines, lead incident response and business continuity, manage third-party risk, and develop a distributed security team.

Requirements

  • CISSP, CISM, CCISO, or CISA credential
  • 12+ years of information security experience
  • Experience in a NYDFS-regulated or SEC-reporting public company
  • Experience leading security in distributed AWS or GCP environments
  • Experience with cybersecurity compliance
  • Experience with incident response and business continuity
  • Experience with stablecoin protocols or AI-driven financial tools is advantageous
  • Master’s degree in Cybersecurity, MIS, or MBA is preferred

Responsibilities

  • Serve as the designated CISO for the cybersecurity program under NYDFS Part 500
  • Oversee annual risk assessments and compliance certification
  • Lead cybersecurity incident materiality determinations and regulatory disclosures
  • Brief the Board Audit Committee on material security risks
  • Align security controls with international mandates including EU DORA, UK FCA, and GDPR
  • Establish security governance for autonomous AI agents
  • Secure the stablecoin minting, burning, and reserve-management lifecycle
  • Implement phishing-resistant authentication and zero-trust principles
  • Transition manual GRC to continuous controls monitoring
  • Integrate automated security guardrails into development pipelines
  • Implement threat modeling based on business impact
  • Own incident response and business continuity plans
  • Lead systemic-failure and AI-driven-fraud tabletop exercises
  • Manage continuous third-party security monitoring
  • Lead and develop a distributed security team

Benefits

  • Remote work