At Utila, you’ll help build the modern, enterprise-grade platform that powers digital asset operations for more than 300 global institutions. Our technology secures $20B+ in monthly transaction volume and has protected over $100B to date, and we’re growing fast, backed by $50M in funding and a rapidly expanding customer base.
We work on mission-critical systems that demand innovation, precision, and deep technical expertise. If you’re excited by complex challenges, want to work with exceptionally strong teammates, and are looking to make a real impact on the future of financial technology, you’ll feel right at home here.
Why Join Us?
Utila is a place for innovators, problem-solvers, and leaders. You'll be part of a fast-paced, ambitious environment where your contributions make a direct impact. If you're looking to grow your career while helping shape the future of secure virtual transactions, we'd love to hear from you.
We are looking for a hands-on, strategic Cybersecurity GRC Expert to architect and mature our governance, risk, and compliance frameworks. In the fast-evolving digital asset space, this role bridges the gap between complex tech, regulatory compliance, and rapid business growth. You will report directly to the Head of Information Security and ensure our security posture enables trust with tier-1 financial institutions globally.
עיקרי התפקיד
Compliance Leadership: Drive end-to-end certification cycles (SOC 2 Type II, ISO 27001, ISO 22301) from evidence collection to auditor review while developing, implementing, and maintaining actionable policies that align with business operations and regulations with passion & innovation.
Risk Management & Mitigation: Perform continuous risk assessments across our SaaS, Cloud (GCP, AWS, etc.), corporate IT services and digital asset infrastructure.
Third-Party Risk Assessment: Lead third-party risk management (TPRM) end-to-end, from vendor risk assessments to ongoing monitoring, ensuring third-party relationships align with our security and compliance standards.
Sales Partnership: Serve as the go-to security resource for the sales team, driving fast, accurate responses to Information Security questionnaires and due diligence requests from prospective clients. This requires fluent English and the ability to work at deal speed without compromising rigor.
Security Awareness: Drive continuous security awareness, training and phishing simulation programs across the organization.
דרישות
What You'll Bring (Requirements)
Experience: 5+ years in IT compliance and GRC, with hands-on ownership of at least SOC 2 Type II and ISO 27001 cycle.
Tooling Fluency: Comfort working directly in environments like GCP, GitHub, Jira and compliance tooling platforms like Vanta.
Communication Skills: Exceptional ability to translate complex technical/security requirements into audit-grade documentation and simple business language.
Leadership Skills: Proven ability to independently drive initiatives, manage priorities, and provide guidance to organization stakeholders as needed.
יתרון
Familiarity with CCSS and additional cryptocurrency security standards is a strong advantage.
Knowledge in cryptography, blockchain technology, or other security-sensitive financial systems is a plus.
Experience with bank-grade security compliance standards and practices.