Head of Security
Crossmint helps users build blockchain applications by providing wallet infrastructure, payments, tokenization, and authentication tools.
Maintainer signals as of 8/10/2026
Funding history
Projects
About Crossmint
Crossmint helps enterprises and developers build blockchain applications by providing wallet infrastructure, payment processing, tokenization, and authentication tools. With it, you can create wallets, process fiat-to-crypto payments, mint tokens, and authenticate users. Crossmint makes blockchain development accessible without requiring extensive cryptocurrency expertise.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will build and own the security function, defining its strategy, roadmap, risk posture, and investment priorities. You will review product and infrastructure changes, lead threat modeling and incident response, oversee audit readiness and vendor risk, and manage the Senior DevSecOps Engineer. You will communicate security risks and progress to executive and board-level stakeholders.
Requirements
- 8+ years of security experience
- At least 3 years of security leadership or program ownership experience
- Technical fluency in cloud security, application security, and CI/CD security
- Experience owning a security compliance program through a major audit cycle
- Software engineering degree or equivalent software engineering experience
- Familiarity with AI and agentic tools
- Experience in fintech, payments, or a similarly regulated industry
- Written and verbal communication skills for executive and board-level risk briefings
- Experience managing or mentoring security engineers
- Ability to work flexible hours during incidents
- Familiarity with DORA, MiCA, or EU financial services regulatory frameworks
- Experience with crypto or blockchain security threat models
- Experience building a security function
- CISSP, CISM, or equivalent certification
Responsibilities
- Define and own the security strategy, roadmap, risk posture, and investment decisions
- Report security posture, risks, and program progress to co-founders
- Review architecture decisions, product features, and infrastructure changes for security implications
- Conduct or lead threat modeling across product and infrastructure domains
- Contribute hands-on during incidents, vulnerability analysis, and high-stakes security reviews
- Lead audit preparation, evidence readiness, control documentation, and auditor communication
- Maintain readiness for SOC 2 Type II, DORA, and MiCA-related security requirements
- Own security reviews for vendors, integrations, and third-party relationships
- Manage external security partners, penetration testing, and security assessments
- Manage and develop the Senior DevSecOps Engineer
- Drive security awareness and communicate risks to non-technical leadership
Benefits
- Stock options
- Access to AI tools and subscriptions
- Unlimited flexible PTO
- Parental leave program
- Flexible work schedule
- Company laptop
- Home equipment allowance
- Daily commuting and/or meal stipend
- Three company-paid off-sites per year
- Health insurance
- Dental insurance
- Vision insurance
- Life insurance
- Short-term disability insurance
- Long-term disability insurance
- 401(k) plan
