🎯 Job Search Agent

← all jobs

Head of Security

Phaxis Β· New York, NY Β· via manual_submit

πŸ—“ Posted: not published by source  Β·  Found by agent: 2026-09-13 17:00

92% match
β€”salary (not stated)
n/a applicants
draftstatus

Open posting β†—

Application documents

Generated draft resume
⬇ Download .docx Β· changes
Cover letter
Your uploaded resume

Score breakdown

ComponentRawWeightContributionEvidence
keywords100.0%30 30.0 cisosocincident responseiamcomplianceinformation security
seniority100.0%25 25.0 Head of
location100.0%20 20.0 nyc-metronew york
salary50.0%15 7.5 salary-not-stated
company100.0%10 10.0 bankbankingcustody

Telegram alerts

2026-09-16T19:44:52+00:00 β†’ chat 5272237815 Β· sent

Synthesis sent: Head of Security for a stealth API-first bank blending traditional rails (Fedwire, ACH, SWIFT) with blockchain/stablecoin infrastructure. Founding-team role building the security function from scratch, with a path to CISO. Reports to the CTO.

full message
βœ… Head of Security
🏒 Phaxis Β· πŸ“ New York, NY

Match: 92%
πŸ’° Salary: not stated in posting
πŸ‘₯ Applicants: n/a β€” not published by manual_submit

Head of Security for a stealth API-first bank blending traditional rails (Fedwire, ACH, SWIFT) with blockchain/stablecoin infrastructure. Founding-team role building the security function from scratch, with a path to CISO. Reports to the CTO.

Key requirements
β€’ 7+ years in security engineering, cloud security, or detection/response
β€’ Strong AWS security expertise (IAM, guardrails, Terraform, least privilege)
β€’ Experience securing high-value financial infra (payments, banking, crypto, custody)
β€’ Ability to build SOC 2/FFIEC/NIST 800-53 controls and lead incident response
β€’ Hands-on automation/AI-assisted development mindset, strong exec/regulator communication

➑️ Apply
πŸ“„ Tailored resume (.docx)
πŸ“ What changed

2026-09-13T21:04:30+00:00 β†’ chat 5272237815 Β· sent

Synthesis sent: email lead 100%

full message
πŸ“§ LinkedIn alert lead β€” initial match 100%
Head of Security
🏒 Phaxis Β· πŸ“ New York, NY

Scored on the alert email only. For full analysis + a tailored resume, open the posting, copy the description, and paste it here:

Resume customization

Variant Lucian_Lipinsky_CV__JPMC__2026.docx engine claude 14076 in / 9524 out tokens βœ“ 10/10 review passed

⬇ Download tailored resume (.docx)  Β·  πŸ“ What changed (changelog)

Keywords injected / gaps: second line of defenseidentity & access management (IAM)vulnerability managementincident responseblockchaincryptographythird-party vendorregulatory examinationscloud environments

10-pass quality review
#PassStatusDetail
1Grammar APPROVED No grammar errors detected; sentences well-formed.
2Spelling APPROVED No spelling errors found in customized resume.
3Formatting consistency APPROVED 1 font(s), 5 size(s), consistent bullets
4Logical layout APPROVED Section order matches base; logical flow retained.
5LLM-artifact detection APPROVED no em dashes or LLM filler phrases detected
6Job-description alignment APPROVED Security, IAM, regulatory terms align naturally with posting focus.
7Accomplishments emphasis APPROVED Key metrics ($1.7T AUM, 45 countries) retained and highlighted.
8No fabrication APPROVED No new employer, title, degree, or metric introduced.
9Consistency with base CV APPROVED Employers, titles, dates match base version; no contradictions.
10Human readability APPROVED Reads naturally, professional tone, no robotic phrasing.
Text preview
Lucian Lipinsky de Orlov
lucian@lipinskyllc.com  β–ͺ  914-656-0324  β–ͺ  linkedin.com/in/lipinsky/
	
	
Senior cyber risk executive | financial services & digital assets
Blockchain & Tokenized Asset Security | Regulatory Advisory
Identity, Vulnerability & Incident Response Leadership
Senior cybersecurity and risk executive with 20+ years of experience across global financial institutions and asset managers, including direct work advising on blockchain and tokenized-asset security as architectural advisor to the world's first SEC-approved tokenized government money fund. Deep background in vulnerability management, incident response, identity and access management, and second-line-of-defense regulatory oversight within highly regulated banking environments. Proven ability to translate complex technical security decisions into clear guidance for executives, auditors, and regulators.
			
	
Professional Experience Highlights
American Express - New York, NY
Senior Director, Risk & Information Security	2025 - Present
Cybersecurity Technology & Resiliency Risk Oversight
Senior Director within American Express' global cyber risk oversight organization, leading a distributed team focused on data security, privacy, and identity & access management (IAM).
Lead global cyber risk oversight for data protection, privacy, and identity & access management (IAM) across enterprise platforms, cloud environments, and third-party vendor ecosystems.
Advise senior executives on cyber risk exposure, control effectiveness, and practical risk-reduction actions impacting customers, employees, and business operations.
Translate complex cybersecurity, privacy, and IAM risks into clear, practical guidance to support executive decision-making and risk awareness among non-technical stakeholders.
Partner with technology, legal, privacy, and business leadership to align cyber risk posture with regulatory expectations and business objectives.
Lead, coach, and set technical and risk standards for a global team of senior cyber risk professionals, establishing best practices across data protection, privacy, and identity domains.
Citigroup - New York, NY
Senior Vice President, Cyber Operational Risk Officer	2023 - 2025
Senior cyber risk leader within Citi's Second Line of Defense, providing independent challenge and oversight across vulnerability management, incident response, threat intelligence, security operations, and regulatory policy governance in a highly regulated banking environment.
Advised senior leadership on cyber risk exposure, residual risk, and prioritization across global financial services operations.
Translated technical findings into executive decision briefs for non-technical leadership.
Served as liaison with global regulators on cybersecurity posture, resilience, and remediation strategy, supporting regulatory examinations and audit readiness.
Oversaw global adversarial emulation exercises with focus on preparedness, judgment, and executive response readiness.
Reviewed and modernized cybersecurity policies, standards, and guidelines to meet regulatory expectations.
Franklin Templeton Investments - New York, NY
Global Director of Security and Risk (CISO)	2019 - 2023
Advised UHNW individuals and family offices within Franklin Templeton's Fiduciary Trust subsidiary on personal and family office cybersecurity risks, including digital assets, privacy exposure, identity compromise, and secure handling of sensitive financial information.
Executive accountable for global cybersecurity and risk management across 45 countries supporting $1.7T AUM.
Advised executive leadership on cyber risk tradeoffs, investment decisions, and incident preparedness.
Led incident response planning, executive tabletop exercises, and crisis simulations to strengthen organizational readiness and response processes.
Architectural advisor to the world's first SEC-approved tokenized government money fund, advising on blockchain infrastructure, cryptography, and operational risk controls for digital asset operations.
QuSecure - San Mateo, CA
Board Advisor (Quantum Security)	2020 - 2023
Provided technical guidance on post-quantum cryptography architecture and applicability in regulated financial services environments.
Translated complex quantum and cryptographic concepts into clear, credible narratives for executive leadership, potential investors, and media.
Citihub - New York, NY
Partner, CISO-for-Hire	2008 - 2015
Served as trusted cybersecurity advisor to C-suite executives across financial services and other industries.
Delivered executive briefings, tabletop exercises, and strategic cyber guidance aligned to business risk.
Deloitte Consulting - New York, NY
Senior Manager, Security SME	2003 - 2008
Advised capital markets, wealth management, and retail banking clients on technology and security risk.
Led large-scale regulatory and security initiatives and delivered C-level presentations.


	
Thought Leadership & Education
Fordham University - Three Minute Thesis (3MT) Competition
First Place Winner (2018)
Recognized for delivering advanced cybersecurity research on AI-driven threat detection to a non-technical audience in under three minutes, demonstrating exceptional clarity, discipline, and executive communication.
Fordham University - Lincoln Center, New York, NY
Adjunct Professor, Center for Cybersecurity 	2019 - Present
Teach undergraduate and graduate courses in computer security systems, encryption, operating system vulnerabilities, and disaster recovery. Program designated by NSA/DHS as a National Center of Academic Excellence in Cyber Defense Education.


Education
MS in Cybersecurity
Fordham University, Graduate School of Arts and Sciences, New York, NY
NSA and DHS National Center of Academic Excellence in Cyber Defense Education Certified
MS in Advanced Technology, Specialization in Computer Science
Thomas J. Watson School of Engineering, Applied Science, and Technology
	Graduated School of State University of New York, Binghamton, NY	
BS in Computer Science
State University of New York, Binghamton, NY
Certification & Training
ISACA CRISC - PMI Project Management Professional (PMP) - ITIL Foundation Certified - Certified Disciplined Agilist - Enterprise Lean Six Sigma Green Belt - CISSP (Candidate) - IBM Certified Professional - Project Management - New York State Notary Public 

Full description (2827 chars)

Open source posting β†—
Head of SecurityLocation: United States
Reports to: CTO
Employment: Full-timeOur client is building a modern, API-first bank designed for the global economy, connecting traditional banking infrastructure with public blockchain and onchain payment rails. The platform will support traditional payment networks including Fedwire, ACH, FedNow, RTP, and SWIFT, alongside FX, treasury management, and bank-issued stablecoin capabilities.Seeking a hands-on Head of Security to build and lead the company's information security function from the ground up. This is a founding-team-level role with significant ownership and autonomy, with a natural path toward CISO as the organization scales.Key Responsibilities
Own security for the bank's critical money movement infrastructure, including stablecoin mint/redeem flows, custody, key management, transaction signing, and sanctions/asset-freeze controls.
Build and automate the technical security controls supporting SOC 2, FFIEC, and NIST 800-53 requirements.
Lead end-to-end incident response, including detection, escalation, on-call processes, post-incident reviews, and security runbooks.
Drive application and supply-chain security, including secure SDLC, secrets management, dependency management, and CI/CD security.
Establish identity and access management practices centered around least privilege, JIT access, approvals, auditability, and periodic access reviews.
Own third-party/vendor security assessments and risk reviews.
Help secure the underlying AWS/Terraform infrastructure, including cloud guardrails, gated releases, observability, and disaster recovery.
Leverage AI and automation to eliminate manual security and compliance processes wherever possible.
Ideal Background
7+ years of experience in security engineering, cloud security, detection/response, or a closely related discipline.
Strong AWS cloud security experience, including IAM, organization-level guardrails, Terraform, and least-privilege architecture.
Proven experience securing high-value financial infrastructure, ideally within payments, banking, crypto, exchanges, custody, or similar environments.
Strong threat-modeling capabilities and the ability to communicate technical security decisions clearly to executives, auditors, and regulators.
Hands-on experience with AI-assisted development/coding tools and a strong automation mindset.
Excellent written communication skills, particularly around security decisions, control narratives, and incident reviews.
Nice-to-Haves
Experience with crypto custody, MPC, HSMs, wallet infrastructure, or key ceremonies.
Experience operating in regulated/audited environments involving SOC 2, FFIEC, NIST 800-53, or bank examinations.
Rust or smart-contract experience/literacy.
Experience with stablecoins, blockchain infrastructure, or onchain payments.
✎ Edit & reprocess description