Head of Security Assurance

Index Industries · Chicago, IL · Engineering

Posted 2026-09-03

Apply for this role →

Index Industries is a growing startup, and our security and audit posture needs to grow with it. We already run on solid foundations: AWS, Railway, Ethereum and Datadog cover our infrastructure, hosting, blockchain and observability, and we have built real controls into how we operate custody and the protocol. We have policies, structures, and controls in place. As we onboard more institutional investors and expand toward retail with additional financial products, those foundations need to mature from good defaults into practices built for our domain: investors who run their own diligence, auditors who expect evidence rather than assurances, and venues that gate access to demonstrated controls.

This role is about that maturation, not a rebuild. You will take our detection and response, custody operations and platform security stance from solid basics to the best practices our growth demands across web2 and web3 - and produce the technical evidence that lets investors, auditors and counterparties trust it.

What you'll own

The assurance program, end to end. SOC 2 is the anchor, and the certifications that follow it: scoping, auditor selection, remediation planning, evidence, fieldwork, report.

Our external security story. The public trust surface, published audit and attestation material, and a vulnerability disclosure policy researchers can actually use.

Diligence. You will personally front security questionnaires and the calls behind them, with institutional counterparties and their security teams. You'll be responsible for understanding and representing the security stack, from policies to implementation across web2 and web3.

The control program. Policies, risk register, vendor reviews, access reviews, key-management ceremonies, tabletop exercises - you run the cadence and you keep the evidence. The operational surface that carries most of our real risk: multisig ops, treasury ops, incident response, DevOps and infrastructure, DNS and registrar, and identity and accounts. We want each of those independently assessable rather than self-attested.

The money path. Value moves through our system in both fiat and crypto, across more than one legal entity and several settlement paths. You'll hold that whole picture: where funds could be redirected, where an approval could be spoofed or socially engineered, where a reconciliation gap could hide a loss - and close those paths. That includes recommending real tooling, with a clear view of what it buys and what it costs in friction.

Requirements on engineering. You define what detection, logging and access controls must exist and to what standard, then verify delivery. Our engineers build it.

Anticipating what's next. We're building things that don't have an established playbook, so our threat model has to be derived rather than looked up. You'll stay close to the roadmap - new products, new chains, new counterparties, new flows - work out what each one exposes, and land the controls before it ships. The test is whether your input arrives early enough to shape a design rather than late enough to block one.

Automation over toil. A control that depends on someone remembering is a control that fails. You'll push evidence collection, monitoring, access reviews and reporting toward automation, so the programme gets more reliable as we grow rather than more expensive, and the burden on engineers and operators falls while the posture improves.

Reporting to leadership and the board on where we actually are.

We anchor on SOC 2. Beyond it, our direction of travel is NIST CSF 2.0 as the narrative and board-reporting layer, CIS Controls v8.1 (IG2) as the technical baseline, the SEAL frameworks as operational content, and the AICPA's 2025 criteria for token operations as a control-matrix skeleton. That is direction, not doctrine - you will have a real say in what we actually adopt and in what order.

What you'll bring

You have delivered a SOC 2 Type II as the accountable owner, not as a participant.

You have fronted institutional diligence and held your own with a counterparty's security team.

Real technical literacy. You can read a smart contract's access-control model, reason about signing policy and approval quorums in an MPC custody platform, and hold your end of an AWS architecture conversation. You don't need to write the code; you need engineers to respect your requirements.

Digital asset experience. You shouldn't need custody, oracles or on-chain governance explained from first principles.

A background in regulated financial services, or somewhere that taught you a control isn't real until it's evidenced.

You write exceptionally well. Nearly everything you produce is read by someone deciding whether to trust us.

You run a recurring process without being chased. The value here lives in the cadence.

You track the threat landscape closely, across both web2 and web3. You can speak to how DPRK-linked groups and other sophisticated actors actually operate against companies like ours: social engineering, supply-chain compromise, signer targeting, infiltration of hiring pipelines. And you turn that into specific controls rather than general alarm.

Helpful, not required: compliance automation tooling (Vanta, Drata, Secureframe), ISO 27001, CCSS, incident command experience, time at a custodian, exchange or tokenisation platform.

What this role is not

It is not a rebuild. We want someone who will spend their first month understanding why things are built the way they are before proposing changes. It is not a DevOps or infrastructure role. And it is not smart contract auditing. We engage multiple independent firms for that and will continue to.

Apply for this role →

← Back to all jobs