About The Position

zerohash is looking for an experienced Technology & Cyber Risk Manager to own the second-line technology and cyber risk function. You will assess and independently challenge the controls that protect zerohash’s infrastructure, custody systems, and partner-facing platforms — and translate that assessment into quantitative risk views for senior leadership and the board. The role covers the full scope of technology risk at a regulated digital asset platform: infrastructure, application security, model and AI risk, and the evolving threat landscape that comes with operating at the intersection of financial services and crypto.

Requirements

  • 5+ years in technology risk, cyber risk, or information security risk management, with at least 2 years in a dedicated second-line role at a bank, regulated fintech, or equivalent
  • Direct experience with GSIB-style third-party assessments, either as the assessor or as the party being assessed
  • Ability to read and critically assess first-line security deliverables and produce independent risk opinions
  • Hands-on experience with quantitative risk modeling — FAIR methodology or equivalent
  • Familiarity with AI/ML risk governance concepts: model inventories, use case classification, human-in-the-loop design
  • Familiarity with DORA ICT risk requirements or equivalent EU financial regulation
  • Strong written communication — board and regulatory-grade risk reporting is a core deliverable

Nice To Haves

  • Experience at a digital asset, payments, or crypto-adjacent regulated institution
  • Formal FAIR certification or equivalent quantitative risk credential
  • Familiarity with post-quantum cryptography standards and cryptographic inventory frameworks

Responsibilities

  • Own zerohash’s cyber risk framework: risk methodology, risk appetite metrics, and scenario library; produce independent risk views for senior leadership and the board
  • Maintain the technology and cyber risk register as a live, continuously updated record
  • Review and challenge first-line security deliverables — penetration test results, vulnerability metrics, and control assessments — and produce independent risk opinions
  • Partner with Engineering and Security on risk identification across infrastructure, application, and AI systems
  • Own the AI governance program: use case registry, risk classification, and oversight of AI systems touching end-user or transaction data
  • Support regulatory and counterparty risk assessments as the second-line technology risk owner
  • Track emerging technology risks including AI, model risk, and cryptographic risk
  • Provide independent technical risk assessment for custody-critical and security-critical vendors as an input into the broader vendor risk program, supplementing commercial and contractual review owned elsewhere in the business

Benefits

  • Healthcare Insurance: zerohash covers roughly 100% of employee premiums as well as a portion of spouse/children (U.S. only)
  • Vision & Dental Insurance (U.S. only)
  • Chance to earn equity
  • Maternity & Paternity leave (after 6 months)
  • WeWork All Access Membership
  • WFH Yearly Stipend
  • L&D Yearly Stipend (after 6 months)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service