Full time - Paris or full remote from Western EU
The Information Security Officer supports Kilns VP of Security in defining and executing the companys information security program. Acting as the GRC (Governance Risk & Compliance) lead the ISO aligns security strategy with business goals and regulatory standards. The role includes leading risk assessments compliance initiatives KPI development and driving a strong security culture across the organization.
Program Leadership & Governance
Design and run a scalable security program aligned with Kilns growth web3 operations and evolving regulations.
Develop and maintain the security framework (policies standards and processes).
Define and track KPIs/OKRs; present security posture to leadership.
Lead risk management activities including enterprise vendor and emerging threat assessments.
Maintain the risk register and oversee audit readiness (SOC 2 ISO 27001).
Vendor & Third-Party Risk
Build and manage the vendor security program including due diligence monitoring and contractual controls.
Oversee third-party incident coordination and mitigation.
Security Awareness & Incident Management
Promote a security-first culture through training and awareness programs.
Manage incident response planning and execution; lead post-incident reviews to improve resilience.
Regulatory Compliance
Establish compliance monitoring programs to ensure ongoing adherence to applicable laws regulations and industry standards.
Partner with legal and compliance teams to ensure continuous adherence to standards.
Required
Bachelors or Masters in Computer Science or Information Security.
8 years in information security with strong GRC experience in regulated or high-growth environments.
Proven record of building and scaling security programs.
Knowledge of ISO 27001 SOC 2 GDPR and risk management frameworks.
Experience with third-party risk cloud/infrastructure security and compliance metrics.
Nice to Have
Background in blockchain digital assets or fintech.
Familiarity with web3 infrastructure smart contracts and DevSecOps practices.
Knowledge of compliance platforms (e.g. Vanta Drata).
Certifications such as CRISC CISM CISSP or ISO 27001 Lead Implementer.
Kiln is the leading enterprise-grade rewards platform that enables institutional customers to stake assets and integrate staking & DeFi functionality into their offerings. Our API-first platform provides fully automated validators staking & DeFi protocols access and comprehensive data and commission management.
With $13 billion in crypto assets staked through our platform Kiln has established a strong presence on Ethereum managing over 5.4% of the network through 50000 validators all with zero slashing events.
Kiln serves more than 140 leading customers including Binance BitPanda Bitgo Fireblocks VanEck and TrustWallet.
Our team of 100 ecosystem enthusiasts brings experience from industry leaders like Google Circle Ledger Chainalysis and other prominent technology and cryptocurrency companies.
Weve raised $30M in total funding from prominent investors including 1kx Illuminate Financial Consensys Wintermute Kraken Ventures...
Join Kiln and help us make the web more secure stable decentralized and fair!
A fast-paced bureaucracy-free work environment
Equity share options in the business: if Kiln succeeds we all succeed!
Competitive salary
Flexible holiday
Flexible remote working
Choose your IT equipment
Internet connection: 50/month
Significant personal development budget (books training)
Overseas tech conferences budget
Kiln is an Equal Opportunity Employer
We are committed to fostering an inclusive and diverse workplace where everyone is valued and respected. We welcome applications from all backgrounds including women or persons with disabilities.
Our thorough process ensures the best fit for both you and Kiln and we strive to make each step valuable and efficient.
Recruiter Interview (45 min)
Technical Interview (60 min)
Core Values Interview (45 min)
Founders Interview (30 min)
Offer!
Your personal information will be securely stored in our Applicant Tracking System (ATS) and will not be shared with external parties. We comply fully with GDPR regulations to protect your data and privacy.
Please note that we do not sponsor visas for persons without work authorization in your location. This role is for full-time employees only (no B2B or contractors). Thank you!
Required Experience:
Unclear Seniority
Earn rewards on your digital assets through staking and DeFi, or whitelabel earning functionality into your products.