Head of Security Assurance

Index IndustriesChicago, IL

About The Position

Index Industries is a growing startup seeking a Head of Security Assurance to mature its security and audit posture. The role involves taking existing foundations in AWS, Railway, Ethereum, and Datadog and evolving them to meet the demands of institutional investors, auditors, and retail expansion. This is a role focused on maturation, not a rebuild, aiming to elevate detection and response, custody operations, and platform security to best practices across web2 and web3, while producing the technical evidence required for trust. The Head of Security Assurance will own the end-to-end assurance program, including SOC 2 and subsequent certifications, manage the external security narrative, lead diligence efforts with counterparties, oversee the control program (policies, risk registers, vendor reviews, etc.), secure the financial transaction paths (fiat and crypto), define and verify engineering requirements for security controls, anticipate future threats and control needs, drive automation over manual processes, and report to leadership and the board. The company anchors on SOC 2 and is moving towards NIST CSF 2.0, CIS Controls v8.1, SEAL frameworks, and AICPA criteria for token operations, with the Head of Security Assurance having significant input into adoption and prioritization.

Requirements

  • Delivered a SOC 2 Type II as the accountable owner.
  • Experience leading institutional diligence and interacting with counterparty security teams.
  • Strong technical literacy, including understanding smart contract access control, MPC custody platforms, and AWS architecture.
  • Experience with digital assets, including custody, oracles, and on-chain governance.
  • Background in regulated financial services or a similar environment where evidenced controls are paramount.
  • Exceptional written communication skills.
  • Ability to run recurring processes reliably and without constant oversight.
  • Close tracking of the threat landscape in both web2 and web3, with the ability to translate threats (e.g., DPRK-linked groups, social engineering, supply-chain compromise) into specific controls.

Nice To Haves

  • Experience with compliance automation tooling (Vanta, Drata, Secureframe).
  • ISO 27001 certification experience.
  • CCSS experience.
  • Incident command experience.
  • Experience at a custodian, exchange, or tokenization platform.

Responsibilities

  • Own the assurance program end-to-end, including SOC 2, auditor selection, remediation planning, evidence collection, fieldwork, and reporting.
  • Manage the company's external security narrative, including published audit and attestation materials, and a vulnerability disclosure policy.
  • Lead security diligence efforts with institutional counterparties, representing the security stack across web2 and web3.
  • Run the control program, including policies, risk register, vendor reviews, access reviews, key-management ceremonies, and tabletop exercises, ensuring evidence is maintained.
  • Oversee the operational surface carrying significant risk, including multisig operations, treasury operations, incident response, DevOps, infrastructure, DNS, registrar, and identity and accounts, ensuring independent assessability.
  • Secure the financial transaction paths for both fiat and crypto, identifying and closing potential vulnerabilities related to redirection, spoofing, social engineering, and reconciliation gaps.
  • Define and verify engineering requirements for detection, logging, and access controls, ensuring they meet defined standards.
  • Anticipate future threats and control needs by staying close to the product roadmap (new products, chains, counterparties, flows) and ensuring controls are implemented before shipping.
  • Drive automation for evidence collection, monitoring, access reviews, and reporting to improve program reliability and reduce the burden on engineers and operators.
  • Report on the company's security posture to leadership and the board.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service