About the company
LI.FI provides cross-chain bridge & DEX aggregation to power next-gen DeFi projects with superior UX.
Job Summary
About the role:
We're looking for someone who can quickly understand our systems, identify risks, and drive action - not just produce reports. You'll also coordinate external audits and build security awareness across the company. You'll work closely with engineering, AI, automation, and operations teams, and collaborate with our existing security architect to strengthen security practices across the company.
Responsibilities:
📍Lead security efforts across infrastructure, applications, internal systems, and employee devices 📍Identify risks and vulnerabilities across the organisation and ensure they are addressed 📍Establish scalable security processes and best practices across teams 📍Own the organisation's compliance posture - define target frameworks, drive progress against them, and ensure requirements are reflected in day-to-day operations 📍Own relationships with external security firms and auditors 📍Lead the organisation through compliance framework certifications end-to-end 📍Plan and run security reviews and external audits, ensuring findings are tracked and resolved 📍Act as the internal authority on external security requirements and regulatory expectations 📍Define and own the company's security awareness and training programme 📍Set standards for access management, device security, and operational security hygiene 📍Define and own the Secure Software Development Lifecycle (Secure SDLC) across the engineering organisation 📍Work closely with engineering teams to ensure secure design and implementation of products — getting into the detail where needed 📍Personally review tools, frameworks, and architectures for security risks and ensure findings drive action 📍Set the standard for how developers integrate security practices into the development lifecycle 📍Bring a solid understanding of Web3-specific security risks — smart contract vulnerabilities, protocol exploits, wallet and key management, and on-chain threat vectors 📍Work directly with engineering teams to ensure Web3 security considerations are embedded in how we build and ship 📍Stay current on the evolving Web3 threat landscape and ensure the organisation is positioned ahead of emerging risks 📍Identify and mitigate security risks related to AI-driven tooling, agents, and automation 📍Stay ahead of emerging threats introduced by AI integration across our stack 📍Own the security tooling strategy — defining requirements, evaluating solutions, and driving implementation 📍Establish monitoring standards, incident response processes, and security workflows 📍Ensure security is consistently embedded in engineering pipelines and tooling
Requirements:
📍Proven experience owning or leading a security function — not just executing within one 📍Background in security engineering or architecture — you understand how systems are built and where they break 📍Experience building or maturing security programmes in fast-moving engineering organisations 📍Experience in a Web3 or payments fintech environment 📍Solid knowledge of key compliance frameworks including SOC 2, ISO 27001, DORA, MiCA, the EU AI Act, NIS2, and related standards 📍Experience guiding organisations through certification and audit processes end-to-end — not just familiarity with the frameworks, but having done the work 📍Able to translate regulatory and compliance requirements into practical internal programmes and controls 📍Comfortable owning the GRC function and reporting on compliance posture to leadership 📍Strong understanding of modern application security practices 📍Experience with security reviews, threat modelling, and vulnerability management 📍Familiarity with cloud infrastructure security and developer tooling 📍Strategic thinker who can translate risk into priorities and communicate them clearly to leadership 📍Comfortable operating with autonomy in a fast-moving, ambiguous environment 📍Able to influence without authority across engineering and leadership 📍Proactive by default - you identify problems before they're escalated to you 📍Comfortable getting into the detail when the situation calls for it
Nice-to-have: 📍Understanding of AI security risks and emerging attack vectors is a strong plus 📍Experience managing or mentoring security teams is a plus
If this role isn't the perfect fit, there are plenty of exciting opportunities in blockchain technology, cryptocurrency startups, and remote crypto jobs to explore. Check them on our Jobs Board.




