Bakkt

Chief Information Security Officer

Bakkt$210K — $250K *
US-AnywhereRemote in United States
Finance & Insurance
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • CISSP required, or equivalent executive credential
  • 12+ years in Information Security, particularly in NYDFS-regulated or SEC-reporting environments
  • Experience in distributed, cloud-driven environments (AWS/GCP)
  • Strong advantage for experience with stablecoin protocols or AI-driven financial tools
  • Preferred Master's degree in Cybersecurity, MIS, or MBA

Responsibilities

  • Lead and oversee cybersecurity program in accordance with NYDFS Part 500
  • Manage organizational processes for cybersecurity incident disclosures
  • Provide quarterly Material Security Risk briefings to the Audit Committee
  • Enhance security controls for international settlement expansion
  • Establish governance framework for AI agents and stablecoin infrastructure
  • Architect an identity-first security model with zero-trust principles
  • Own global Incident Response and Business Continuity plans

Benefits

  • Opportunity to directly influence and shape the cybersecurity posture of a high-growth company
  • Leadership role reporting directly to executive leadership and the Board
  • Chance to work at the intersection of cutting-edge technologies like AI and stablecoins
  • Alignment with global cybersecurity mandates across multiple jurisdictions
  • Dynamic, remote-first work environment fostering innovative culture
Full Job Description
Role Summary

Bakkt is seeking a strategic, Chief Information Security Officer (CISO) to lead our global information security posture and serve as our designated officer for regulatory cybersecurity compliance. This role is designed for an innovative leader who thrives at the intersection of modern engineering velocity and institutional-grade risk management.

As we scale our Agentic AI and Stablecoin settlement infrastructure, you will lead a progressive security function that moves far beyond "check-the-box" compliance. Reporting directly to executive leadership with a dotted line to the Board of Directors, you will have the authority to build a defensible, automated security program that serves as a core enabler for our business growth.

Key Responsibilities

Regulatory Ownership & Executive Governance

  • Designated Regulatory Authority: Serve as the designated CISO responsible for Bakkt's cybersecurity program in accordance with NYDFS Part 500 requirements. Oversee comprehensive annual risk assessments and manage our annual certification of compliance process.
  • SEC & Public Market Readiness: Lead our organizational process for determining the materiality of cybersecurity incidents. Oversee the timely preparation of all required disclosures and filings in accordance with public market regulations and governance standards.
  • Board Stewardship: Provide quarterly Material Security Risk briefings to the Audit Committee of the Board, translating complex infrastructure threats into actionable business risk metrics.
  • Global Expansion Support: Maintain and evolve our security controls to support international settlement expansion, aligning with global mandates as required (e.g., EU DORA, UK FCA, GDPR).
  • AI Governance & Stablecoin Infrastructure
  • Agentic AI Security: Establish the governance and security framework for autonomous AI agents, ensuring programmable money movement is resilient against prompt injection, model poisoning, and unauthorized agentic transactions.
  • Stablecoin Settlement Defense: Oversee the security of our end-to-end stablecoin lifecycle, ensuring the cryptographic integrity of minting/burning protocols and the security of reserve management interfaces.
  • Identity-First (Zero Trust) Architecture: Architect a comprehensive security model that applies consistent rigor to both human and non-human identities, implementing modern phishing-resistant authentication and zero-trust principles across the enterprise.
  • Continuous Compliance: Transition our operations from manual GRC to Continuous Controls Monitoring (CCM), ensuring audit evidence is generated in real-time through Policy-as-Code.
  • Security Engineering & DevSecOps
  • Seamless Security (Shift Left): Foster an internal culture where security is built-in from the start. Replace manual gatekeeping with automated guardrails integrated into our development pipeline, allowing engineers to ship securely without losing speed.
  • Smart Risk Management: Move beyond unprioritized vulnerability lists. Implement a threat-modeling process that prioritizes fixes based on real-world business impact, ensuring engineering teams focus on the risks that actually threaten our environment.

Operational Leadership & Resilience

  • Incident Response & Tabletops: Own the global Incident Response and Business Continuity plans. Lead high-stakes tabletop exercises simulating systemic financial failures and AI-driven fraud.
  • Third-Party Risk Management (TPRM): Manage the security lifecycle of critical banking and ICT partners, moving beyond point-in-time assessments to continuous, data-driven vendor monitoring.
  • Talent Development: Lead, develop, and motivate a high-performing team of security subject matter experts in our distributed, remote-first environment.Ideal Candidate Profile

Qualifications and Skills

  • The Standard: CISSP required, or a demonstrably equivalent executive credential (CISM, CCISO, or CISA).
  • Financial & Public Co. Pedigree: 12+ years in Information Security, with significant experience operating within a NYDFS-regulated or SEC-reporting public company environment.
  • Infrastructure Depth: Proven success leading security in distributed, cloud-driven (AWS/GCP) environments. Direct experience with stablecoin protocols or AI-driven financial tools is a strong advantage.
  • Preferred Education: Master's degree (Cybersecurity, MIS, or MBA) and/or senior-level professional designations like GSLC or equivalent executive cybersecurity leadership training.
  • Leadership & Soft Skills
  • Strategic & Lateral Thinker: Ability to look at complex regulatory frameworks not as obstacles, but as tools for building robust, continuous process improvement.
  • Operational Resolve: Capable of leading difficult, high-stakes conversations where business velocity and regulatory safety intersect.
  • Agile Leadership: Proven ability to lead through ambiguity and rapid change. You are a decisive leader who can pivot strategies in real-time based on shifting market conditions while maintaining team focus on high-priority outcomes.
  • Collaborative Culture Builder: A sophisticated, modern approach to managing and motivating technical subject matter experts in a remote-first, high-growth environment.

About Bakkt

Bakkt is a subsidiary of Intercontinental Exchange (ICE), a leading operator of global exchanges, clearing houses, data and listings services. Bakkt provides a platform for institutional investors to buy, sell, store, and spend digital assets. The company's platform is designed to enable consumers and institutions to seamlessly buy, sell, store and spend digital assets. Bakkt's platform is powered by the same technology that powers the New York Stock Exchange. Bakkt was founded in 2018 and is headquartered in Alpharetta, Georgia.
Learn more about Bakkt
Size
350 employees
Market Cap
$407.3 million
Industry
NASDAQ

Similar Jobs

More Jobs at Bakkt

More Finance & Insurance Jobs

  • Partner
    $200K — $500K+*
    Confidential Company
    Los Angeles, CA 90001 (Los Angeles County)
  • Senior Tax Associate
    $80K — $100K *
    Godsey & Gibb Wealth Management
    Richmond, VA 23230 (Henrico County)
  • Director, Events & Experience
    $121K — $164K *
    Mackenzie Financial Corporation
    Toronto, ON M3C 0E3
  • Thermo Fisher Scientific
    Manager, FP&A
    $110K — $130K *
    Thermo Fisher Scientific
    Wilmington, NC 28403 (New Hanover County)
  • Institutional Advisor
    $100K — $120K *
    Goelzer Investment Management
    Carmel, IN 46032 (Hamilton County)

Find similar Chief Information Security Officer jobs: