Senior Cybersecurity GRC
Utila provides institutional digital asset operations infrastructure with MPC wallets, enabling organizations to securely manage, build, and scale on digital assets.
Projects
About Utila
Utila enables institutions to manage digital asset operations across blockchains using MPC wallet infrastructure. The platform provides secure custody, treasury management, trading operations, stablecoin payments, and tokenization capabilities with granular policy controls, compliance integrations, and developer APIs for payment providers, neobanks, custodians, exchanges, and institutional investors.
Skills
About the Role
You will architect and mature governance, risk, and compliance frameworks. You will lead SOC 2 Type II, ISO 27001, and ISO 22301 certification cycles, including evidence collection and auditor reviews. You will develop and maintain security policies, assess risks across SaaS, cloud, corporate IT, and digital-asset infrastructure, and manage third-party risk assessments and monitoring. You will support sales by responding to security questionnaires and client due-diligence requests, and you will run security-awareness, training, and phishing-simulation programs.
Requirements
- 5+ years of experience in IT compliance and GRC
- Hands-on ownership of at least one SOC 2 Type II and ISO 27001 cycle
- Experience working with GCP, GitHub, Jira, and Vanta
- Ability to translate technical and security requirements into audit-grade documentation and business language
- Ability to independently drive initiatives, manage priorities, and guide stakeholders
- Fluent English
- Familiarity with CCSS and cryptocurrency security standards
- Knowledge of cryptography, blockchain technology, or security-sensitive financial systems
- Experience with bank-grade security compliance standards and practices
Responsibilities
- Lead end-to-end SOC 2 Type II, ISO 27001, and ISO 22301 certification cycles
- Develop, implement, and maintain security and compliance policies
- Perform continuous risk assessments across SaaS, cloud, corporate IT, and digital-asset infrastructure
- Lead third-party risk management from vendor assessments through ongoing monitoring
- Respond to information security questionnaires and client due-diligence requests
- Run security-awareness, training, and phishing-simulation programs
