IT Security Lead
OpenEden is a regulated digital-asset company that tokenizes global financial assets and brings real-world assets on-chain. It operates institutional products including tokenized Treasury and bond-fund products, a yield-bearing stablecoin, a multi-strategy yield portfolio, and the ATLAS tokenization-as-a-service platform.
Funding
Projects
About OpenEden
OpenEden builds regulated, institutional-focused infrastructure and products for bringing real-world financial assets to DeFi. Its offerings include ATLAS, an end-to-end tokenization platform for issuers; TBILL, a tokenized US Treasury fund; USDO, a yield-bearing stablecoin backed by tokenized treasuries; PRISM, a multi-strategy yield portfolio; and HYBOND, a tokenized BNY Investments bond-fund product. The group serves eligible institutional customers, including stablecoin issuers, financial institutions, asset managers, and corporates, subject to onboarding and jurisdictional requirements.
Skills
About the Role
You will oversee and enhance security across cloud infrastructure, internal systems, and digital asset operations. You will design, implement, and manage security controls, perform security reviews of new features and integrations, and maintain the Technology Risk Management register. You will identify and remediate threats, vulnerabilities, misconfigurations, and access risks, monitor system health, investigate alerts, and lead incident response and recovery. You will own relationships with security vendors, lead third-party and vendor risk reviews, and support disaster recovery and resilience testing. You will design and maintain institutional-grade wallet and transaction security controls to protect minting and redemption processes.
Requirements
- 5–8 years in IT security, security engineering, or DevSeCOps with at least 2–3 years in crypto or web3 environments
- Experience working within a regulated environment (e.g. MAS, BMA, FCA, SEC) preferred
- Strong hands-on experience in cloud security, preferably AWS (IAM, logging, networking)
- Strong understanding of blockchain security fundamentals including Ethereum/EVM, smart contract vulnerabilities, and oracle risks
- Hands-on ability to design and implement security solutions independently
- Experience working with or managing external security vendors
- Experience in startups or fast-moving environments
- Familiarity with custody providers (e.g. Fireblocks) preferred
- Experience supporting audits such as ISO and SOC2 preferred
Responsibilities
- Own and maintain security controls across AWS including IAM, access, logging, and network security
- Identify and remediate threats, vulnerabilities, misconfigurations, and access risks across systems
- Maintain and actively manage the Technology Risk Management register including risk identification, tracking, and remediation
- Perform security reviews of new features, smart contract integrations, and system architectures prior to launch
- Manage security vendors including MSSP, monitoring tools, and Web3 security providers
- Monitor system health, investigate security alerts, and lead incident response and escalation
- Design and maintain institutional wallet and transaction security controls for minting and redemption
- Lead third-party and vendor risk reviews and technical due diligence for integrations and protocols
- Support testing and continuous improvement of disaster recovery and resilience processes
- Maintain and enhance recovery procedures for critical systems
Benefits
- Employee Stock Option Scheme eligibility
- Token incentive allocation
- Flexible work arrangements
