Head of Security

Compound Foundation supports the long-term growth of the Compound ecosystem.

Distributed
About Compound Foundation

Compound Foundation is presented as the stewardship organization for the Compound ecosystem. Its activities include strategic planning, ecosystem development, partnerships, governance coordination, community engagement, risk and capital management, engineering, and protocol security.

View jobs by Compound Foundation

Skills

About the Role

Own security across Foundation operations, protocol development, infrastructure, tooling, access, custody interfaces, vendors, and incident readiness. Lead security strategy and hands-on execution across smart-contract security, infrastructure, incident response, vendor management, and operational security while supporting the broader ecosystem.

Requirements

  • 8+ years of security experience with hands-on security engineering, application security, or infrastructure security experience.
  • Demonstrated end-to-end ownership of a security function.
  • Direct crypto, DeFi, smart-contract, blockchain infrastructure, or protocol security experience.
  • Strong understanding of smart-contract audits, vulnerability management, bug bounties, and secure deployment practices.
  • Experience hardening cloud, GitHub, CI/CD, identity, access, secrets management, and endpoint environments.
  • Experience leading incident response for high-severity technical or security events.
  • Ability to operate as both a security strategist and hands-on builder in a small team.
  • Strong judgment, communication, autonomy, and precision in ambiguous, fast-moving environments.
  • Experience with formal verification, threat modeling, bug-bounty programs, or on-chain exploit response is preferred.

Responsibilities

  • Own the Foundation security program across protocol, infrastructure, applications, internal tools, vendors, and access controls.
  • Coordinate secure development practices, audits, vulnerability handling, contributor guidance, and incident response readiness.
  • Manage security service providers, audit firms, formal verification specialists, and incident response providers.
  • Partner with engineering leadership on secure architecture, secure SDLC, code review, and deployment practices.
  • Implement incident-response procedures for vulnerabilities, exploits, access compromise, vendor compromise, and operational security events.
  • Harden identity, access, secrets, GitHub, cloud, CI/CD, endpoint, and offboarding practices.
  • Support wallet, multisig, key-management, and custody security standards.
  • Evaluate security vendors, auditors, bug-bounty platforms, and external experts.
  • Produce decision-ready security updates for leadership and escalate material issues or launch blockers.