zerohash provides API-first technology and turnkey regulatory infrastructure to launch and scale compliant crypto and stablecoin products quickly and securely.
About the role
zerohash is looking for an experienced Technology & Cyber Risk Manager to own the second-line technology and cyber risk function. You will assess and independently challenge the controls that protect zerohash’s infrastructure, custody systems, and partner-facing platforms — and translate that assessment into quantitative risk views for senior leadership and the board.
What they're looking for
- 5+ years in technology risk, cyber risk, or information security risk management, with at least 2 years in a dedicated second-line role at a bank, regulated fintech, or equivalent
- Direct experience with GSIB-style third-party assessments, either as the assessor or as the party being assessed
- Ability to read and critically assess first-line security deliverables and produce independent risk opinions
- Hands-on experience with quantitative risk modeling — FAIR methodology or equivalent
- Familiarity with AI/ML risk governance concepts: model inventories, use case classification, human-in-the-loop design
- Familiarity with DORA ICT risk requirements or equivalent EU financial regulation
More about this role
zerohash is looking for an experienced Technology & Cyber Risk Manager to own the second-line technology and cyber risk function. You will assess and independently challenge the controls that protect zerohash’s infrastructure, custody systems, and partner-facing platforms — and translate that assessment into quantitative risk views for senior leadership and the board. The role covers the full scope of technology risk at a regulated digital asset platform: infrastructure, application security, model and AI risk, and the evolving threat landscape that comes with operating at the intersection of financial services and crypto.
- Own zerohash’s cyber risk framework: risk methodology, risk appetite metrics, and scenario library; produce independent risk views for senior leadership and the board
- Maintain the technology and cyber risk register as a live, continuously updated record
- Review and challenge first-line security deliverables — penetration test results, vulnerability metrics, and control assessments — and produce independent risk opinions
- Partner with Engineering and Security on risk identification across infrastructure, application, and AI systems
- Own the AI governance...
Browse similar: Startup jobs · Remote jobs