Director Security positions focus on delivering results in their domain. This page aggregates open Director Security roles and what employers typically expect.
DIRECTOR OF SECURITY ZODL (Zcash Open Development Lab) Location: Remote Reports to: Head of Engineering and Head of Research and Assurance Compensation: $185K–$230K base + equity ABOUT ZODL Zodl (Zcash Open Development Lab) is building the software necessary to onboard billions of users to Zcash. Created by the original inventors and developers of the Zcash protocol, we deliver world-class UX for ZEC on top of our core protocol work. Our product suite includes Zodl mobile (iOS and Android) with built-in cross-chain swaps, and Zallet, a full-node Zcash wallet written in Rust, built as a replacement for the zcashd wallet. On the horizon: Zodl Vault (a desktop wallet for multisig, inheritance, and institutional use cases), web-based wallets, and headless/agentic wallet infrastructure. THE ROLE Zcash and ZODL have an enviable reputation for security assurance and for the thoroughness of our responses to past security issues. But as Zcash’s market cap increases, so do the risks and potential attention from adversaries. We are seeking a Director of Security to take responsibility for overseeing and improving the following processes within ZODL: - Working with the team leaders and engineers to maintain and further improve the high standards of security and resilience that ZODL and Zcash’s protocols and software have come to be known for. - Administering and improving the security incident response process within ZODL. You will be responsible for managing effective, quick, and thorough responses to security vulnerabilities discovered in our software, supply chains, and infrastructure, interacting with external security researchers who may have found vulnerabilities and representatives of other projects that may be affected. This includes ensuring that staff are familiar with the security incident response process. - Communicating security flaws and their mitigations —with precision, timeliness, actionable information, and the appropriate degree of reassurance— to the Zcash and wider cryptocurrency and infosec communities. You will choose whether and how to respond to instances of misinformation about Zcash’s security properties. - Building and maintaining our relationships with other projects that share Zcash technology, to improve on and surpass industry-standard security disclosure processes in the cryptocurrency space. - Creating and managing relationships with external providers of security assessments. Working with the Head of Research and Assurance, you will find suitable external auditors for implementation and specification audits, schedule audits, provide auditors with the information they need to be most effective, critique and validate their work, and ensure that they are properly incentivized to provide value. You will expand on any themes arising from these assessments, continuously using the feedback to develop and advocate for appropriate security within the company. - Helping ZODL’s staff with advice and resources to secure their computing devices, and to respond to physical and virtual threats against their safety and that of their families, their wealth, and their other possessions. This includes responding to attacks against ZODL staff for which the security incident response process may not be best suited. - On-boarding new staff to relevant security procedures, ensuring that they are able to quickly get up-and-running with the permissions they need and the knowledge to use them securely. You will also administer off-boarding processes to mitigate the risk of past employees’ and contractors’ access being misused. - Directing the maintenance and acquisition of security-relevant infrastructure, devices, and software. You will be responsible for budgeting our security spend each year, taking into account the product and company roadmaps. - Documenting and keeping track of security policy; and maintaining procedures to ensure that actual permissions match intended permissions, consistent with the principle of least pr…