Aptos
Head of Security (Aptos Foundation)
Job Summary
The role involves leading the security efforts for the Aptos organization, including developing policies, controls, and frameworks to ensure the safety of digital and physical assets. The candidate will be responsible for defining security goals, conducting training, and reviewing development processes to maintain a secure environment. Significant experience in information security, risk management, and familiarity with industry standards such as ISO/IEC 27001 and NIST is required. The position also includes engaging with various cloud and infrastructure services to uphold security across multiple technical domains.
Required Skills
Benefits
Job Description
Aptos is a people-first blockchain on a mission to help billions of people achieve universal and fair access to decentralized assets in a safe and scalable way.
Founded by some of the original creators and maintainers that researched, designed, and built the Diem blockchain to serve this purpose, we have dedicated several years toward this mission. We believe the open-source Diem technology we have developed is an important foundation of a safe and scalable web3 world where everyone has more equitable opportunities to grow and access financial assets with lower fees and fewer intermediaries.
Aptos (Ohlone for "The People") encompasses our mission and ethos for why we build.
Head of Security, Aptos Foundation
Aptos is a people-first blockchain on a mission to help billions of people achieve universal and fair access to decentralized assets in a safe and scalable way.
Founded by some of the original creators and maintainers that researched, designed, and built the Diem blockchain to serve this purpose, we have dedicated several years toward this mission. We believe the open-source Diem technology we have developed is an important foundation of a safe and scalable web3 world where everyone has more equitable opportunities to grow and access financial assets with lower fees and fewer intermediaries.
Aptos (Ohlone for "The People") encompasses our mission and ethos for why we build.
About the role:
We are seeking an experienced and self-motivated Head of Security (Aptos Foundation) to lead our digital and physical security efforts.The scope of the opportunity for security within our organization encompasses:
- Services like Discord and 1Password
- Company hardware including phones and computers
- Operational deployments of our core infrastructure like Aptos Community page, Aptos Foundation page, Faucets, Indexer APIs, and other services within cloud infrastructure in AWS and GCP
- Operational configuration of validators, fullnodes, and other publicly reusable services that leverage Terraform and Pulumi across various cloud vendors
- Software including:
- Distributed services like consensus, state synchronization, mempool
- Networking services like P2P network infrastructure using Noise, our REST APIs, and our Indexer
- Storage services
- VMs and their interface into the application space
- Library and application smart contracts
- Command-line interface tools
- SDKs across many languages (currently Rust, Python, and Typescript)
- Wallets – browser extension, mobile, custodial solutions
- Our release processes for SDKs, Nodes, Indexers, Operational services, docker containers, and our wallet
What you’ll be doing:
- Audit, define, develop, and maintain an Information and Security Framework across Aptos in line with relevant legislation, regulation, and industry standards as applicable
- Define, build, and maintain the required culture, plans, policies, procedures, systems, controls, reporting mechanisms, and assurance framework
- Leading training classes for both operational and software development security
- Continuously reviewing our ongoing development processes to be engaged early in the process of software development
- Define security goals and objectives, and align the wider team to them
What we’re looking for:
- 7+ years of relevant work experience
Understanding of best practices within Information Security and risk management including standards such as ISO/IEC 27001, NIST-CSF, CIS-20CSC, and CObIT - Security technologies and wider business solutions including identity and access management, Security Incident and Event Management (SIEM) and Security Operation Centre (SOC), remote working, and cloud-first technologies
- Ability to think and plan strategically and systematically while delivering
- Ability to work within a regulatory framework and to articulate its potential as a tool for continuous improvement across the wider organization
- Experience conducting penetration tests and/or managing third-party audit firms
Our Benefits
- 100% insurance premium coverage for medical, dental, and vision for you and your dependents (US Employees)
- Equipment of your choice
- Flexible vacation time, 11 holidays, and floating company days off
- Competitive Salary
- Protocol Token Grants
- 401k matching (US Employees)
- Fun and inclusive in-person and digital events
Aptos is committed to diversity in the workplace, and we’re proud to be an Equal Opportunity Employer. We do not hire on the basis of race, color, religion, creed, gender, national origin, citizenship, age, disability, veteran status, marital status, pregnancy, parental status, sex, gender expression or identity, sexual orientation, or any other basis protected by local, state or federal law. All employment is decided based on qualifications, merit, and business need.
Aptos
Aptos is an independent Layer 1 blockchain platform focused on safety and scalability driving growth within a decentralized network and developer ecosystem.
See more jobsSafe Remote Job Search Tips
Verify Employer Thoroughly
Research the company's identity thoroughly before applying. Check for a professional website with contacts, active social media, and LinkedIn profiles. Verify details across platforms and look for reviews on Glassdoor or Trustpilot to confirm legitimacy.
Never Pay to Get a Job
Legitimate employers never require payment for applications, training, background checks, or equipment. Always reject upfront payment requests or demands for bank details, even if they claim it's for purchasing necessary work gear on your behalf.
Safeguard Your Personal Information
Protect sensitive data like SSN, bank details, or ID copies. Share this only after accepting a formal, written job offer. Ensure it's submitted via a secure company system or portal, never through insecure channels like standard email attachments.
Scrutinize Communication & Interviews
Watch for communication red flags: poor grammar, generic emails (@gmail), vague details, or undue pressure. Be highly suspicious of interviews held only via text or chat apps; legitimate companies typically use video or phone calls.
Beware of Unrealistic Offers
If an offer's salary or benefits seem unrealistically high for the work involved, be cautious. Research standard pay for similar roles. Offers that appear 'too good to be true' are often scams designed to lure you into providing information or payment.
Insist on a Formal Contract
Always secure and review a formal, written job offer or employment contract before starting work or sharing final personal details. Ensure it clearly defines your role, compensation, key terms, and conditions to avoid misunderstandings or scams.