Sobre esta vaga de Security Manager na Decentralized Masters
Who We Are
Catalyst Capital is a profitable, bootstrapped holding company building a diversified financial services group: education, publishing, software, wealth & tax planning tools, investment products and proprietary trading technology. Funded entirely from its own operating cash.
Role summary
Catalyst Capital is hiring a Security Manager to own security across our brands. You will run the security program, lead incident response, and build a small security team as we grow. This is a hands-on leadership role: you set the direction and you still do real technical work.
You report to our Head of Technology and brief our leadership team directly every month. When something goes wrong, you are the person leadership trusts to run the response and explain it in plain language.
What you will own
- Security program. Own the security strategy and roadmap across Decentralized Masters, Legacy, Inflection Club, and future brands. Report on security posture and risk to leadership every month.
- Incident response. Own incident response end to end and lead the room during live incidents. Keep runbooks current, run tabletop exercises, and write postmortems leadership can act on.
- Team leadership. Manage and develop our Security Engineer, and build the security team as the company scales.
- Policy and audit readiness. Write and enforce security policies that people actually follow: access control, acceptable use, data handling, vendor review, and incident response. Prepare the company for audits such as SOC 2, working with Legal & Compliance.
- Phishing and impersonation defense. Own email security, staff training, and phishing simulations. Run brand protection: find and take down fake domains and accounts impersonating our brands on social media platforms.
- Platform and account security. Set the security standards for customer accounts on our platforms, including login protection and account-takeover defense, and work with the engineering teams that own each platform to build them in.
- AI and automation security. Set the rules for how AI agents and automations handle credentials, data, and tool permissions, and review high-risk ones before they go live.
- Security tooling and vendors. Own the security stack (SIEM, endpoint protection, email security, identity and device management) and the vendors behind it. Set the device and access standards that IT runs day to day.
- Member scam awareness. Supply the security content behind our scam-awareness messaging to members, working with Community, Support, and Marketing. Legal approves the wording.
Scope
This role protects our company, our platforms, and our brands. For members' personal wallets and accounts outside our platforms, our role is education: helping members recognize and avoid scams.
Requirements
What you will bring
- 5+ years in security, including at least 2 years leading a security function or serving as senior security personnel at a company of 100+ people.
- Has led live-incident response, not just tabletop exercises.
- Has built or rebuilt a security program from an early stage: policy, tooling, training, and incident response.
- Experience in crypto, fintech, or another high-fraud industry.
- Deep, current knowledge of phishing, social engineering, and impersonation attacks and how to defend against them.
- Hands-on experience with SIEM, endpoint protection, email security, and identity and device management platforms.
- Can write scripts and automation rather than relying only on vendor UIs.
- Writes clear security policy and gets people to follow it.
- Briefs executives in plain language and trains non-technical staff.
- Comfortable leading in a fully remote team spread across many time zones.
Nice to have
- Has prepared a company for SOC 2 or ISO 27001.
- Has run a brand protection or takedown program.
- Experience securing or evaluating AI agents and LLM-based tools.
- Experience with customer-facing security features such as account-takeover defense.
- Certifications such as CISSP, CISM, GCIH, OSTH, or OSCP.
How we hire
Our process ends with every finalist presenting a 90-day security plan to our Head of Technology: what you would look at first, what you would fix, and how you would measure progress.
Benefits
What We Offer
- Competitive compensation package
- Independent Contractor opportunity
- Fully remote, globally distributed team.
- Team offsites
- Collaborative, forward-thinking culture that values innovation and results.
If you are ready to take on a challenge that will shape the future of crypto finance and grow with a team of innovators, we want to hear from you!