Head of Security & Risk
M0 is infrastructure for building programmable, interoperable stablecoins with shared liquidity and customizable features.
Maintainer signals as of 8/23/2026
Funding history
About M0
M0 is infrastructure powering builders of safe, programmable, interoperable stablecoins. Developers can build application-specific digital dollars with customizable access, risk, and compliance rules while relying on M0 issuers for robust reserves. All stablecoins built on M0 share native interoperability through composable on-chain operations, creating a unified liquidity layer.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
This foundational individual contributor role reports to the Deputy COO and owns M0's information security and risk function from the ground up. The role spans enterprise risk management, compliance certification, security operations, incident response, ISMS documentation, security policies, partner due diligence, and security awareness across a crypto infrastructure company.
Requirements
- 7–10 years of experience in information security, risk, GRC, or compliance operations.
- Preference for fintech, crypto infrastructure, or B2B SaaS backgrounds.
- Experience building a compliance certification program from scratch.
- End-to-end ownership of SOC 2 audits and ISO 27001 implementation or maintenance.
- Hands-on experience with Vanta, Drata, or equivalent GRC platforms.
- Experience with cloud security, AWS, and BCP/DR program design.
- Experience managing auditors, penetration testing firms, compliance vendors, evidence collection, and report production.
- Working understanding of AWS, GCP, and Azure, including security controls in DevOps and IaaS deployments.
- Preferred certifications include Cloud+, CySA+, CISSP, CISM, or CRISC.
- Familiarity with digital assets, stablecoins, blockchain infrastructure, smart contract security, or on-chain monitoring is advantageous.
Responsibilities
- Build M0's enterprise risk program covering security, operational, regulatory, and counterparty risk.
- Maintain the risk register, annual assessments, scenario analyses, and escalation framework across entities.
- Own compliance posture across SOC 2, ISO 27001, and other applicable frameworks.
- Drive policy writing, auditor coordination, vendor risk, access reviews, and third-party SaaS evaluations.
- Keep the organization audit-ready and manage external security vendor relationships.
- Design and maintain incident response, ISMS documentation, security policies, and tabletop exercises.
- Serve as the primary contact for institutional partner security due diligence and questionnaires.
- Coordinate with Senior Counsel on information security representations in commercial agreements.
- Design and own security awareness training and build a proactive security culture.
Benefits
- Global team and flexibility to work remotely or from hub offices in NYC or Berlin.
- Comprehensive healthcare insurance coverage.
- Wellbeing allowance and gym membership.
- Customizable IT setup with high-quality equipment.
- Annual professional development budget.
- Opportunities to attend conferences and worldwide on-site company events.
- Base salary with equity or token grant, commensurate with experience.
