Chief Information Security Officer
๐ข Bakkt ยท all Bakkt jobs
๐ United States
๐
Posted 2026-08-18 ยท via Himalayas
๐ท Chief-Information-Security-Officer,Information-Security-Leadership,Cybersecurity-Management,Financial-Security-Compliance,Security-Architecture,Chief-Information-Security-Officer-(CISO),Chief-Security-Officer,VP-Of-Information-Security,Vice-President-Of-Information-Security,Head-of-Information-Security
Apply on original site โPowering the next generation of global finance
About Us
Founded in 2018, Bakkt , Inc. is a regulated financial technology company building infrastructure for the future of finance. Bakkt 's platform serves financial institutions, fintechs, and consumer finance products โ providing the compliance, security, and scale required to deliver trusted financial services at a global level. Through its core business pillars, Bakkt powers institutional-grade trading capabilities, AI-enabled programmable finance, and cross-border payment infrastructure.
Role Summary
Bakkt is seeking a strategic, Chief Information Security Officer (CISO) to lead our global information security posture and serve as our designated officer for regulatory cybersecurity compliance. This role is designed for an innovative leader who thrives at the intersection of modern engineering velocity and institutional-grade risk management.
As we scale our Agentic AI and Stablecoin settlement infrastructure, you will lead a progressive security function that moves far beyond "check-the-box" compliance. Reporting directly to executive leadership with a dotted line to the Board of Directors, you will have the authority to build a defensible, automated security program that serves as a core enabler for our business growth.
Key Responsibilities
Regulatory Ownership & Executive Governance
-
Designated Regulatory Authority: Serve as the designated CISO responsible for Bakkt 's cybersecurity program in accordance with NYDFS Part 500 requirements. Oversee comprehensive annual risk assessments and manage our annual certification of compliance process.
-
SEC & Public Market Readiness: Lead our organizational process for determining the materiality of cybersecurity incidents. Oversee the timely preparation of all required disclosures and filings in accordance with public market regulations and governance standards.
-
Board Stewardship: Provide quarterly Material Security Risk briefings to the Audit Committee of the Board, translating complex infrastructure threats into actionable business risk metrics.
-
Global Expansion Support: Maintain and evolve our security controls to support international settlement expansion, aligning with global mandates as required (e.g., EU DORA, UK FCA, GDPR).
- AI Governance & Stablecoin Infrastructure
-
Agentic AI Security: Establish the governance and security framework for autonomous AI agents, ensuring programmable money movement is resilient against prompt injection, model poisoning, and unauthorized agentic transactions.
-
Stablecoin Settlement Defense: Oversee the security of our end-to-end stablecoin lifecycle, ensuring the cryptographic integrity of minting/burning protocols and the security of reserve management interfaces.
-
Identity-First (Zero Trust) Architecture: Architect a comprehensive security model that applies consistent rigor to both human and non-human identities, implementing modern phishing-resistant authentication and zero-trust principles across the enterprise.
-
Continuous Compliance: Transition our operations from manual GRC to Continuous Controls Monitoring (CCM), ensuring audit evidence is generated in real-time through Policy-as-Code.
- Security Engineering & DevSecOps
-
Seamless Security (Shift Left): Foster an internal culture where security is built-in from the start. Replace manual gatekeeping with automated guardrails integrated into our development pipeline, allowing engineers to ship securely without losing speed.
-
Smart Risk Management: Move beyond unprioritized vulnerability lists. Implement a threat-modeling process that prioritizes fixes based on real-world business impact, ensuring engineering teams focus on the risks that actually threaten our environment.
Operational Leadership & Resilience
-
Incident Response & Tabletops: Own the global Incident Response and Business Continuity plans. Lead high-stakes tabletop exercises simulating systemic financial f