Head of Risk, Security

Posted 142ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Lead and mature cybersecurity, risk management, and IT governance functions at Akoya, a fintech innovator. Drive execution and team development across diverse operational areas.

Responsibilities:

  • Lead and mature Akoya’s cybersecurity, risk management, and IT governance functions
  • Serve as the operational backbone of Akoya’s security and risk programs
  • Translate strategy into execution and lead a team across security engineering, cyber operations, risk, compliance, and IT
  • Mature and execute Akoya’s enterprise risk management (ERM) framework
  • Develop and track key risk indicators (KRIs) aligned with business OKRs
  • Lead third-party risk management across fintech partners, vendors, and service providers
  • Conduct product risk assessments across new open finance capabilities
  • Support regulatory readiness related to CFPB Section 1033
  • Lead day-to-day execution of Akoya’s cybersecurity program
  • Drive continuous improvement of zero-trust cloud architectures (AWS-centric)
  • Enhance monitoring, automation, and threat intelligence capabilities
  • Own operational execution of SOC 2 Type II and other certifications
  • Ensure alignment with NIST, ISO 27001/27002, GLBA, SOX, PCI
  • Partner closely with Legal and Product on regulatory interpretation and implementation
  • Respond to due diligence inquiries from financial institutions, fintechs, investors, and regulators
  • Oversee corporate IT governance in partnership with IT Systems Administrator
  • Lead and mentor security engineers, risk analysts, and IT personnel

Requirements:

  • 12+ years in enterprise risk, cybersecurity, or information security.
  • 5+ years leading risk/security teams in fintech, SaaS, or regulated environments.
  • Experience building or scaling security programs in startup or high-growth organizations.
  • Deep cloud security expertise (AWS required; multi-cloud a plus).
  • Strong hands-on knowledge of:
  • Zero-trust architecture
  • Secure SDLC
  • Threat modeling
  • Vulnerability management
  • Incident response
  • Demonstrated ownership of SOC 2 and regulatory audits.
  • Experience working with regulated financial institutions and fintechs or API-based SaaS platforms.

Benefits:

  • Akoya offers a highly collaborative, fast-paced, and fun working environment
  • Diverse, creative, and driven professionals with expertise in the banking, securities, fintech, and data aggregation industries
  • Equal opportunity employer