Posted 17 Feb 2023, 6:51 pm

IT & Security Lead at Chorus One

Sorry, but this job listing has expired!

Chorus One is one of the leading operators of infrastructure for Proof-of-Stake networks and decentralized protocols. Tens of thousands of retail customers and institutions are staking billions in assets through our infrastructure helping to secure protocols and earn rewards. Our mission is to Operate infrastructure for decentralized networks that increase freedom and sovereignty.

We are a diverse team of around 50 people distributed all over the globe. We value radical transparency, striving for excellence and continuous improvement while treating each other with kindness and generosity. If this sounds like you, we'd love to hear from you.

To support the company’s growing security needs Chorus One is looking for an IT & Security Lead to join our team. You will be the security and compliance subject matter expert within Chorus One and be responsible for leading compliance projects end to end, from planning phase through execution, closure phase and ongoing monitoring. 



  • Act as project lead for the implementation of ISO 27001 certification and subsequent certifications arising from business needs, collaborating with teams and stakeholders to ensure successful implementation within a given timeline.
  • Work with teams and stakeholders to develop, implement, and maintain information security policies, procedures, and standards to comply with business relevant security standards and frameworks (ISO 27001, SOC 2) as well as relevant legal and regulatory requirements.
  • Coordinate vulnerability assessments and penetration tests on network systems and applications (Chorus One’s public APIs).
  • Monitor and conduct internal audits of the system environment, policies and procedures. Develop and maintain timelines, roadmaps, and list of required tasks for various teams based on the outcomes.
  • Analyze and report on security threats and incidents, triage resolution, and develop controls and strategies to mitigate those risks.
  • Research and recommend security solutions to mitigate security risks and improve existing practices and technologies to align with the organization's risk tolerance and ensure regulatory compliance.
  • Assist sales in responding to prospect and customer inquiries about Chorus One’s security and compliance posture.
  • Administer security and awareness training for the team.


  • Administer and configure our services such as Google Workspace, Slack, Bitwarden, Notion, and SSO integration between them, manage software licenses.
  • Provide technical support to our employees and keep our internal knowledge base up to date.
  • Provision laptops for new hires (Mac and Linux, Windows to be decided) and maintain an asset register of our corporate devices.
  • Work with stakeholders to set processes and policies. For example, set up a BYOD policy, streamline our onboarding flow, etc.
  • Adopt processes and tools to ensure that our corporate devices are secure, up to date, and free of malware.
  • Researching, proposing, implementing, documenting, testing and supporting new solutions that make our internal IT easier to manage and secure.
  • Streamline our retreats to make them inclusive for remote attendants, and manage the AV equipment and other hardware for this. Several times per year we meet physically to present and discuss company plans, but now that we’ve grown to more than 50 people, inevitably some people are unable to attend in person, so they dial in through a video call.

What we are looking for:

  • Experience leading and implementing security frameworks, such as ISO 27001, SOC 2, GDPR from start to finish.
  • 5+ years of relevant Information Security experience.
  • Functional knowledge of security domains and information security industry standard and best practices.
  • Proven experience in building and maintaining security policies and controls, processes, and procedures.
  • Expertise in security architecture and design, network security, and data protection.
  • Ability to identify security threats and vulnerabilities within an organization and develop suitable countermeasures.
  • Ability to identify and recommend tools, processes, and software to automate and continuously improve security and compliance practices.
  • Strong organizational skills, proactive and self-sufficient with a proven ability to work independently and prioritize deliverables.
  • Strong communication and interpersonal skills to liaise with stakeholders.
  • Experience with Linux system administration, mostly on the workstation side (e.g. setting up LUKS volumes, user accounts, bootloaders, etc.)

  • Experience with Mac system administration.

  • Experience with centralized device and account management solutions.

  • Knowledge of LDAP and directory servers.

  • Strong troubleshooting skills.

  • Strong security mindset and knowledge of common attack vectors on the hardware and software level.

  • A desire to automate repetitive tasks.


  • Previous work experience in the crypto space and understanding of blockchain technology and associated risks.
  • Certifications such as CISSP, CISM, CISA, ISO 27001 Lead Auditor / Implementer or similar.
  • Prior experience with helping a company grow their IT infrastructure from something that works for ~20 people into something that can handle hundreds of people.

  • Experience with Wireguard.

  • Experience with Windows system administration.

  • Experience with a scripting language such as Python.

What we offer:

  • Autonomy and ownership in a friendly and supportive work environment and the opportunity for rapid growth.
  • Remote, but not alone. We are a strong global collaborative environment.
  • Gather experience and build your network in the crypto ecosystem.
  • 80,000-110,000 EUR/year compensation + benefits, equity
  • All-expense paid quarterly team retreats at various destinations (Coronavirus permitting). Past retreats took place in Greece, Portugal, Egypt, Serbia, Kenya, USA, South Korea, and Dubai.
  • Remote working budget (Laptop, co-working space, etc)
  • Personal development budget

Please mention the word **SPIRITED** and tag RMzUuMTY1LjE3MS4yMjY= when applying to show you read the job post completely (#RMzUuMTY1LjE3MS4yMjY=). This is a beta feature to avoid spam applicants. Companies can search these words to find applicants that read this and see they're human.

The offering company is responsible for the content on this page / the job offer.
Source: Remote Ok