Head of Security
Compound Finance operates decentralized markets for earning yield, accessing liquidity, and borrowing against digital assets. Its services support deposits, lending, and overcollateralized borrowing through the Compound protocol.
Maintainer signals as of 8/12/2026
About Compound Foundation
Compound Finance provides secure, audited markets where users can deposit digital assets to earn market-driven yield or borrow against excess collateral. The platform offers liquidity across assets including ETH, WBTC, and stablecoins, with instant withdrawals or borrowing subject to available liquidity. Compound also supports protocol security, governance, ecosystem development, risk and capital management, engineering, partnerships, and community engagement.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will own security across Foundation operations, protocol development, infrastructure, tooling, access, custody interfaces, vendors, and incident readiness. Lead security strategy and hands-on execution across smart-contract security, infrastructure, incident response, vendor management, and operational security while supporting the broader ecosystem.
Requirements
- 8+ years of security experience
- Security engineering
- Application security
- Infrastructure security
- Security-function ownership
- Crypto security
- DeFi security
- Smart-contract security
- Blockchain infrastructure security
- Smart-contract audits
- Vulnerability management
- Bug bounties
- Secure deployment practices
- Cloud security
- GitHub security
- CI/CD security
- Identity and access management
- Secrets management
- Endpoint security
- Incident response
- Security strategy
- Security vendor management
Responsibilities
- Own the Foundation security program
- Coordinate secure development practices, audits, vulnerability handling, contributor guidance, and incident readiness
- Manage security service providers and security deliverables
- Partner with engineering leadership on secure architecture, SDLC, code review, and deployment practices
- Implement incident-response procedures
- Harden identity, access, secrets, GitHub, cloud, CI/CD, endpoint, and offboarding practices
- Support wallet, multisig, key-management, and custody security standards
- Evaluate security vendors, auditors, bug-bounty platforms, and external experts
- Produce security updates for leadership and escalate material issues
