Head of Security
Defuse Labs
WorldwideremotePosted 1 month ago
D
Skill Required
Security-LeadershipBlockchain-SecurityCybersecurityProtocol-SecurityCrypto-SecurityHead-of-SecurityDirector-of-SecuritySenior-Director-Of-SecurityChief-Security-OfficerDirector-Of-Security-OperationsVP-SecuritysecuritySoliditySystem DesignObservabilityTerraformTestNGdesignCloudAWSGCPGenerative AIAIFulltime
Key highlights
- Role: Head of Security for the NEAR ecosystem.
- Must have proven security leadership at a major on‑chain protocol, top‑tier exchange, custodian, or critical infrastructure.
- Responsible for end‑to‑end security of NEAR Intents, NEAR One, NEAR Foundation, and NEAR AI.
- Fluency in crypto risk required (smart contracts, MPC, validator security, on‑chain forensics).
- Will build a security function from the ground up and decide on tooling strategy.
- Must be comfortable with public incident disclosures, board reporting, and partner communications.
Role overview
NEAR is a leading crypto ecosystem comprising a Layer‑1 protocol, a cross‑chain intents and settlement layer (NEAR Intents), a consumer‑facing financial app, and a rapidly growing AI stack & agent framework (Ironclaw). With rising security challenges from AI‑enabled attacks and institutional demands for a named security owner, the ecosystem requires a senior, credible operator to own security end‑to‑end. The Head of Security will have primary ownership of Defuse Labs (NEAR Intents) and NEAR One—the two entities with the highest operational risk—and will extend security coverage to the NEAR Foundation and NEAR AI in partnership with their leadership.
Responsibilities
- Pragmatically manage hard security risks across companies operating complex financial instruments in adversarial cross‑chain environments, focusing on real practical security rather than paper‑based certifications.
- Protect against state actors, insider threats, and numerous LLM agents across every chain integrated with NEAR, including deep defense against scenarios such as 13‑block Litecoin reorgs or margin‑trading engine exploits in partner protocols.
- Define and operate end‑to‑end security posture for NEAR Intents and NEAR One, covering identity, cloud (AWS/GCP), endpoints, application security, SecOps, smart contract risk, on‑chain monitoring, key management, and validator/infrastructure security.
- Establish security standards, audit strategy, and release gating for production deployments of smart contracts and protocols; own the process of moving code from development to mainnet.
- Lead ecosystem‑wide incident response for both traditional infrastructure and on‑chain events, handling preparation, detection, containment, recovery, and serving as the point of coordination and decision‑making during incidents.
- Design and oversee key management architecture across protocol, treasury, and operational environments, including MPC, custody models, and access controls.
- Define and run a continuous offensive testing strategy, encompassing internal security testing, external audits, red teaming, and bug bounty programs.
- Build a lean, high‑leverage security function from the ground up, deciding where commercial tooling is required versus open‑source or in‑house solutions.
- Establish security practices for AI and agent‑based systems, addressing model integrity, prompt injection risks, and agent execution boundaries.
Requirements
- Proven security leader from an environment where failure was not an option – e.g., a major on‑chain protocol, top‑tier exchange or custodian, critical infrastructure, or a peer ecosystem operating at serious scale; experience building programs, not just maintaining them.
- Deep technical proficiency: able to read Terraform modules, challenge threat models, set budget priorities, and argue with engineers on technical merits.
- First‑principles thinker: understands ROI calculations for audits, the impact of auditor brand, formal verification scope, protections, and limitations.
- Excellent system designer: skilled at isolating risks, limiting blast radius, designing circuit breakers, and rapidly dividing and conquering large projects.
- Fluent in crypto risk (or demonstrably capable of rapid mastery): expertise in smart contracts, on‑chain forensics, MPC, key management, and validator security; must not treat crypto as “just another vertical.”
- Comfortable operating in public: capable of incident disclosures, partner calls, committee and board reporting, and maintaining composure in open environments.
Additional details
- All personal data submitted as part of a job application will be processed exclusively for recruitment and selection purposes; by submitting such data, you acknowledge and consent to its use for assessing qualifications, contacting you regarding relevant opportunities, and maintaining a candidate profile for potential future openings.
- For more detailed information about data processing in recruitment, refer to the Privacy Policy or contact the provided address.
- Originally posted on Himalayas.