Chief Information Security Officer
Job description
About the role
The owns the definition, execution, and maturation of the company's global cybersecurity strategy in direct support of rapid business growth and IPO readiness. This executive serves as the trusted security advisor to the CTO, the leadership team, and the Board, ensuring that security acts as a business enabler rather than a constraint. The CISO owns the end-to-end security posture, driving resilience and integrity across the global digital asset platform, cloud infrastructure, and application landscape. This role leads the design and implementation of robust security operations, incident response, and governance frameworks that safeguard client and company funds. The CISO is responsible for fostering a pervasive security culture that empowers product innovation while maintaining strict adherence to regulatory and compliance obligations. This position will also shape the evolution of custody security, AI governance, and risk management practices as Blockchain scales globally. The role requires constant collaboration with Engineering, Product, Infrastructure, Legal, Compliance, and Finance to align security initiatives with strategic priorities. Ultimately, the CISO ensures that Blockchain is prepared to meet the security expectations of regulators, auditors, investors, and customers in a rapidly evolving market.
Key facts
What you'll do
- Define and execute Blockchain.com's global cybersecurity strategy aligned with business objectives and IPO readiness.
- Partner with executive leadership and the internal audit team on cybersecurity strategy, enterprise risk, and regulatory readiness.
- Lead and scale the Security Engineering, SOC, and Security GRC organizations to support a rapidly growing platform.
- Strengthen cloud, application, and infrastructure security across a global digital asset platform that serves millions of users.
- Devise robust operational flows and technical systems to safeguard client and company funds against evolving threats.
- Drive incident response, security operations, vulnerability management, and operational resilience programs.
- Embed security into the software development lifecycle while enabling engineering velocity and product innovation.
- Ensure compliance with industry standards and frameworks, including SOC 1/2, ISO 27001, ISO 42001, DoRA, SOX, and other applicable regulatory requirements.
- Devise and implement a comprehensive AI governance and safety strategy to manage emerging risks and opportunities.
- Maintain and operate custody systems, including oversight of critical controls around self-custody solutions and HSMs.
- Provide tailored, executive-level security assessments to Board meetings, regulators, and examiners to demonstrate operational resilience and risk mitigation effectiveness.
- Foster a culture of security across the company by being a strong business-enabler and championing best practices.
- Collaborate closely with IT, SRE, and the broader engineering team to integrate security into delivery pipelines and operational processes.
Requirements
- Proven experience as a CISO or senior security executive in a high-growth technology or financial services company.
- Experience leading security within a US public company or through an IPO, with a strong understanding of SOX, SEC cybersecurity requirements, and corporate governance.
- Deep technical experience in cryptocurrency, digital assets, blockchain, or financial technology.
- Demonstrated success leading global Security Engineering and GRC teams in complex, fast-paced environments.
- Strong knowledge of cloud security across GCP and AWS, application security, incident response, identity and access management, and modern security architectures.
- Operational experience with self-custody systems, including HSMs, and designing processes to safeguard funds and critical assets.
- Experience presenting to executive leadership, Boards of Directors, and regulators in clear, concise, and impactful ways.
- Strong leadership, communication, and stakeholder management skills, with the ability to balance security, innovation, and business growth.
- Familiarity with the specific regulatory landscape for crypto assets and digital financial services is essential.
- Commitment to maintaining the highest standards of integrity, transparency, and accountability in all security practices.
- Willingness to engage deeply with technical and business stakeholders to solve complex problems under tight deadlines.
- Demonstrated ability to manage multiple priorities and deliver results in a dynamic, high-growth environment.
- Understanding of data privacy regulations and practices relevant to global operations, including cross-border data transfers.
- Willingness to work closely with internal audit and third-party assessors to validate controls and ensure compliance.
Nice to have
- Experience in a regulated financial services environment with strong governance and audit readiness.
- Background in developing or operating crypto custody, trading, or wallet infrastructure at scale.
- Familiarity with AI/ML systems and associated risk management practices in a security context.
Practical notes
- This is a role based in our London office, with a mandatory in-office presence four days per week.
- Work from Anywhere Policy: You can work remotely from anywhere in the world for up to 20 days per year.
- Full-time salary based on experience and meaningful equity in an industry-leading company.