Conduct, design, and implement testing of security controls covering identity management, key management, and infrastructure (network and cloud) configurations.
Support client assurance activities, including responding to Requests for Proposals (RFPs), Requests for Information (RFIs), and Due Diligence Questionnaires (DDQs).
Identify and analyze trends in client inquiries and provide feedback to internal teams to improve documentation and control readiness.
Perform security due diligence and ongoing monitoring for Web3/blockchain vendors, including assessing their control maturity, reviewing SOC reports and security documentation, and identifying residual risks.
Facilitate external audit activities, including coordination of walkthroughs, evidence collection, and response tracking.
Identify and analyze gaps in current and new processes, then develop and track remediation recommendations to completion (e.g., onboarding flow).
Develop and maintain understanding of applicable financial regulatory security requirements and ensure alignment of controls.
Research and share information security best practices, emerging threats, and mitigation strategies with internal teams.
Evaluate and propose next-generation security tools, automation, and technologies to enhance overall security posture.
Review blockchain network or protocol upgrades for their potential security impact on the platform.
Requirements
At least 8 years of relevant experience in security assurance, audit, compliance, or cloud security engineering.
Demonstrated experience testing and validating security controls across IAM, key management, and network/cloud environments.
Strong understanding of Identity and Access Management (IAM) principles.
Knowledge of cryptographic key management, HSMs, and KMS systems.
Solid grasp of cloud and network security architecture and configuration.
Proven experience supporting SOC 1, SOC 2, ISO 27001, PCI DSS, or similar external audits and assessments.
Exposure to major cloud platforms (AWS, GCP, Azure) and infrastructure-as-code.
Experience in preparing client assurance materials, RFP/RFI/DDQ responses, and evidence documentation.
Familiarity with blockchain platforms or digital asset custody systems is advantageous.
Can work independently and under pressure.
Excellent verbal and written communication skills
Pragmatic and solution-oriented approach, ability to balance security requirements with operational feasibility and business needs.
Cybersecurity Engineer implementing Zero Trust Reference Architecture solutions at Mythics. Deploying and maintaining Forescout platform within secure environments.
Security Governance Manager at WEBTOON responsible for IT and Security governance framework. Collaborating with Legal, Product, and Engineering teams in Los Angeles headquarters.
Manager of Cybersecurity leading the company's cybersecurity initiatives at Commonwealth Fusion Systems. Responsible for security policies and team management to protect information assets from cyber threats.
Principal Cloud Operations Developer at AVEVA enhancing Cloud security and leading deployment process improvements. Collaborating with development teams to ensure operational security, stability and scalability.
Responsable cybersécurité gérant la sécurité informatique de l'entreprise. Évaluant la conformité des systèmes d'information et pilotant la feuille de route cybersécurité.
Information Security Officer ensuring legal and cybersecurity compliance across IoT product development at Daikin. Supporting development teams and managing security awareness training.
Security employee monitoring site safety at Newell Brands, ensuring compliance with safety protocols. Supports services in emergency response and monitors site safety continually.
Cybersecurity Intern assisting the Cyber GRC team and Project Manager at HF Sinclair. Gaining hands - on experience in Security Operations and Cyber Risk Management during the summer of 2026.
Associate Director overseeing Network Security Governance at Novartis in Prague or Hyderabad. Driving cyber maturity, risk management, and governance frameworks for secure network environments.
Senior Associate Security Consultant at NTT DATA making a difference through technical excellence in diverse teams. Collaborating on innovative technology and consulting projects in security consultancy.