Job Description

Summary

Position Overview:

  1. Maintain and oversee the functionality of our ISO 27001 Framework and subsequent certifications arising from business needs, collaborating with teams and stakeholders to ensure successful implementation within a given timeline.
  2. Work with teams and stakeholders to develop, implement, and maintain information security policies, procedures, and standards to comply with business relevant security standards and frameworks (ISO 27001, SOC 2) as well as relevant legal and regulatory requirements.
  3. Coordinate vulnerability assessments and penetration tests on network systems and applications.
  4. Monitor and conduct internal audits of the system environment, policies and procedures. Develop and maintain timelines, roadmaps, and list of required tasks for various teams based on the outcomes.
  5. Analyze and report on security threats and incidents, triage resolution, and develop controls and strategies to mitigate those risks.
  6. Research and recommend security solutions to mitigate security risks and improve existing practices and technologies to align with the organization's risk tolerance and ensure regulatory compliance.
  7. Assist sales in responding to prospect and customer inquiries about Chorus One’s security and compliance posture.
  8. Administer security and awareness training for the team.
  9. Administer and configure our services such as Google Workspace, Slack, Bitwarden, Notion, and SSO integration between them, manage software licenses.
  10. Provide technical support to our employees and keep our internal knowledge base up to date.
  11. Provision laptops for new hires (Mac and Linux) and maintain an asset register of our corporate devices.
  12. Work with stakeholders to set processes and policies. For example, set up a BYOD policy, streamline our onboarding flow, etc.
  13. Adopt processes and tools to ensure that our corporate devices are secure, up to date, and free of malware.
  14. Researching, proposing, implementing, documenting, testing and supporting new solutions that make our internal IT easier to manage and secure.
  15. Streamline our retreats to make them inclusive for remote attendants, and manage the AV equipment and other hardware for this. Two times per year we meet physically to present and discuss company plans, but now that we’ve grown to more than 70 people, inevitably some people are unable to attend in person, so they dial in through a video call.

Job requirements

What we are looking for:

  1. Experience leading and implementing security frameworks, such as ISO 27001, SOC 2, GDPR from start to finish.
  2. 5+ years of relevant Information Security experience.
  3. Functional knowledge of security domains and information security industry standard and best practices.
  4. Proven experience in building and maintaining security policies and controls, processes, and procedures.
  5. Expertise in security architecture and design, network security, and data protection.
  6. Ability to identify security threats and vulnerabilities within an organization and develop suitable countermeasures.
  7. Ability to identify and recommend tools, processes, and software to automate and continuously improve security and compliance practices.
  8. Strong organizational skills, proactive and self-sufficient with a proven ability to work independently and prioritize deliverables.
  9. Strong communication and interpersonal skills to liaise with stakeholders.

Nice to have:

  1. Previous work experience in the crypto space and understanding of blockchain technology and associated risks.
  2. Certifications such as CISSP, CISM, CISA, ISO 27001 Lead Auditor / Implementer or similar.

Skills
  • Communications Skills
  • Development
  • Software Architecture
  • Software Engineering
© 2025 cryptojobs.com. All right reserved.