Risk & Audit Lead
KAST enables global spending of stablecoins through payment cards connected to traditional merchant networks and ATMs worldwide.
Maintainer signals as of 8/29/2026
Funding history
About KAST
KAST lets users spend stablecoins at merchants worldwide through payment cards connected to traditional networks. The platform supports multiple stablecoins within a custodian wallet system. Users can create digital cards for immediate use with mobile payment systems or request physical cards in various tiers. The service operates in multiple countries to facilitate cross-border digital asset spending.
Skills
Candidate Availability
Required and preferred rules are kept separate and reflect the wording in the original posting.
About the Role
You will build and run an independent enterprise-wide risk and audit function. You will own the enterprise risk framework, define risk management activities, lead internal audits, validate controls, assess technology and security processes, oversee cybersecurity testing and remediation, and manage business continuity and disaster recovery exercises. You will also maintain risk and audit frameworks, report findings to leadership, and work with relevant stakeholders to improve controls while maintaining independence.
Requirements
- 8+ years of experience in risk, audit, cybersecurity, or controls
- Strong understanding of enterprise risk management, information security, and technology risk
- Experience auditing business and technology environments and identifying control gaps
- Experience leading compliance certification projects such as ISO, SOC 2, or PCI DSS
- Understanding of access management, data controls, secrets, API keys, and security testing
- Strong stakeholder management skills
- Ability to work with senior technical and business leaders, external auditors, and regulators
- Experience in fintech or payment companies is a plus
Responsibilities
- Build and run an independent enterprise-wide risk and audit function
- Own the enterprise risk framework
- Define and drive risk management activities including RCSA and KRIs
- Lead internal audit activities across the full audit lifecycle
- Validate controls and compliance work independently
- Review security and technology controls, systems, policies, and processes
- Assess cybersecurity practices and oversee penetration testing, vulnerability assessments, and remediation
- Own business continuity, disaster recovery, and business impact assessment practices
- Conduct annual BCP and DR exercises
- Partner with stakeholders to address risks and improve controls
- Develop and maintain risk and audit frameworks, policies, and processes
- Provide regular risk and audit updates to leadership
