Head of Security
Phaxis Β· New York, NY Β· via manual_submit
π Posted: not published by source Β· Found by agent: 2026-09-13 17:00
Application documents
Score breakdown
| Component | Raw | Weight | Contribution | Evidence |
|---|---|---|---|---|
| keywords | 100.0% | 30 | 30.0 | cisosocincident responseiamcomplianceinformation security |
| seniority | 100.0% | 25 | 25.0 | Head of |
| location | 100.0% | 20 | 20.0 | nyc-metronew york |
| salary | 50.0% | 15 | 7.5 | salary-not-stated |
| company | 100.0% | 10 | 10.0 | bankbankingcustody |
Telegram alerts
2026-09-16T19:44:52+00:00 β chat 5272237815 Β· sent
Synthesis sent: Head of Security for a stealth API-first bank blending traditional rails (Fedwire, ACH, SWIFT) with blockchain/stablecoin infrastructure. Founding-team role building the security function from scratch, with a path to CISO. Reports to the CTO.
full message
2026-09-13T21:04:30+00:00 β chat 5272237815 Β· sent
Synthesis sent: email lead 100%
full message
Resume customization
Variant Lucian_Lipinsky_CV__JPMC__2026.docx engine claude 14076 in / 9524 out tokens β 10/10 review passed
β¬ Download tailored resume (.docx) Β· π What changed (changelog)
Keywords injected / gaps: second line of defenseidentity & access management (IAM)vulnerability managementincident responseblockchaincryptographythird-party vendorregulatory examinationscloud environments
10-pass quality review
| # | Pass | Status | Detail |
|---|---|---|---|
| 1 | Grammar | APPROVED | No grammar errors detected; sentences well-formed. |
| 2 | Spelling | APPROVED | No spelling errors found in customized resume. |
| 3 | Formatting consistency | APPROVED | 1 font(s), 5 size(s), consistent bullets |
| 4 | Logical layout | APPROVED | Section order matches base; logical flow retained. |
| 5 | LLM-artifact detection | APPROVED | no em dashes or LLM filler phrases detected |
| 6 | Job-description alignment | APPROVED | Security, IAM, regulatory terms align naturally with posting focus. |
| 7 | Accomplishments emphasis | APPROVED | Key metrics ($1.7T AUM, 45 countries) retained and highlighted. |
| 8 | No fabrication | APPROVED | No new employer, title, degree, or metric introduced. |
| 9 | Consistency with base CV | APPROVED | Employers, titles, dates match base version; no contradictions. |
| 10 | Human readability | APPROVED | Reads naturally, professional tone, no robotic phrasing. |
Text preview
Lucian Lipinsky de Orlov lucian@lipinskyllc.com βͺ 914-656-0324 βͺ linkedin.com/in/lipinsky/ Senior cyber risk executive | financial services & digital assets Blockchain & Tokenized Asset Security | Regulatory Advisory Identity, Vulnerability & Incident Response Leadership Senior cybersecurity and risk executive with 20+ years of experience across global financial institutions and asset managers, including direct work advising on blockchain and tokenized-asset security as architectural advisor to the world's first SEC-approved tokenized government money fund. Deep background in vulnerability management, incident response, identity and access management, and second-line-of-defense regulatory oversight within highly regulated banking environments. Proven ability to translate complex technical security decisions into clear guidance for executives, auditors, and regulators. Professional Experience Highlights American Express - New York, NY Senior Director, Risk & Information Security 2025 - Present Cybersecurity Technology & Resiliency Risk Oversight Senior Director within American Express' global cyber risk oversight organization, leading a distributed team focused on data security, privacy, and identity & access management (IAM). Lead global cyber risk oversight for data protection, privacy, and identity & access management (IAM) across enterprise platforms, cloud environments, and third-party vendor ecosystems. Advise senior executives on cyber risk exposure, control effectiveness, and practical risk-reduction actions impacting customers, employees, and business operations. Translate complex cybersecurity, privacy, and IAM risks into clear, practical guidance to support executive decision-making and risk awareness among non-technical stakeholders. Partner with technology, legal, privacy, and business leadership to align cyber risk posture with regulatory expectations and business objectives. Lead, coach, and set technical and risk standards for a global team of senior cyber risk professionals, establishing best practices across data protection, privacy, and identity domains. Citigroup - New York, NY Senior Vice President, Cyber Operational Risk Officer 2023 - 2025 Senior cyber risk leader within Citi's Second Line of Defense, providing independent challenge and oversight across vulnerability management, incident response, threat intelligence, security operations, and regulatory policy governance in a highly regulated banking environment. Advised senior leadership on cyber risk exposure, residual risk, and prioritization across global financial services operations. Translated technical findings into executive decision briefs for non-technical leadership. Served as liaison with global regulators on cybersecurity posture, resilience, and remediation strategy, supporting regulatory examinations and audit readiness. Oversaw global adversarial emulation exercises with focus on preparedness, judgment, and executive response readiness. Reviewed and modernized cybersecurity policies, standards, and guidelines to meet regulatory expectations. Franklin Templeton Investments - New York, NY Global Director of Security and Risk (CISO) 2019 - 2023 Advised UHNW individuals and family offices within Franklin Templeton's Fiduciary Trust subsidiary on personal and family office cybersecurity risks, including digital assets, privacy exposure, identity compromise, and secure handling of sensitive financial information. Executive accountable for global cybersecurity and risk management across 45 countries supporting $1.7T AUM. Advised executive leadership on cyber risk tradeoffs, investment decisions, and incident preparedness. Led incident response planning, executive tabletop exercises, and crisis simulations to strengthen organizational readiness and response processes. Architectural advisor to the world's first SEC-approved tokenized government money fund, advising on blockchain infrastructure, cryptography, and operational risk controls for digital asset operations. QuSecure - San Mateo, CA Board Advisor (Quantum Security) 2020 - 2023 Provided technical guidance on post-quantum cryptography architecture and applicability in regulated financial services environments. Translated complex quantum and cryptographic concepts into clear, credible narratives for executive leadership, potential investors, and media. Citihub - New York, NY Partner, CISO-for-Hire 2008 - 2015 Served as trusted cybersecurity advisor to C-suite executives across financial services and other industries. Delivered executive briefings, tabletop exercises, and strategic cyber guidance aligned to business risk. Deloitte Consulting - New York, NY Senior Manager, Security SME 2003 - 2008 Advised capital markets, wealth management, and retail banking clients on technology and security risk. Led large-scale regulatory and security initiatives and delivered C-level presentations. Thought Leadership & Education Fordham University - Three Minute Thesis (3MT) Competition First Place Winner (2018) Recognized for delivering advanced cybersecurity research on AI-driven threat detection to a non-technical audience in under three minutes, demonstrating exceptional clarity, discipline, and executive communication. Fordham University - Lincoln Center, New York, NY Adjunct Professor, Center for Cybersecurity 2019 - Present Teach undergraduate and graduate courses in computer security systems, encryption, operating system vulnerabilities, and disaster recovery. Program designated by NSA/DHS as a National Center of Academic Excellence in Cyber Defense Education. Education MS in Cybersecurity Fordham University, Graduate School of Arts and Sciences, New York, NY NSA and DHS National Center of Academic Excellence in Cyber Defense Education Certified MS in Advanced Technology, Specialization in Computer Science Thomas J. Watson School of Engineering, Applied Science, and Technology Graduated School of State University of New York, Binghamton, NY BS in Computer Science State University of New York, Binghamton, NY Certification & Training ISACA CRISC - PMI Project Management Professional (PMP) - ITIL Foundation Certified - Certified Disciplined Agilist - Enterprise Lean Six Sigma Green Belt - CISSP (Candidate) - IBM Certified Professional - Project Management - New York State Notary Public
Full description (2827 chars)
Open source posting βHead of SecurityLocation: United States Reports to: CTO Employment: Full-timeOur client is building a modern, API-first bank designed for the global economy, connecting traditional banking infrastructure with public blockchain and onchain payment rails. The platform will support traditional payment networks including Fedwire, ACH, FedNow, RTP, and SWIFT, alongside FX, treasury management, and bank-issued stablecoin capabilities.Seeking a hands-on Head of Security to build and lead the company's information security function from the ground up. This is a founding-team-level role with significant ownership and autonomy, with a natural path toward CISO as the organization scales.Key Responsibilities Own security for the bank's critical money movement infrastructure, including stablecoin mint/redeem flows, custody, key management, transaction signing, and sanctions/asset-freeze controls. Build and automate the technical security controls supporting SOC 2, FFIEC, and NIST 800-53 requirements. Lead end-to-end incident response, including detection, escalation, on-call processes, post-incident reviews, and security runbooks. Drive application and supply-chain security, including secure SDLC, secrets management, dependency management, and CI/CD security. Establish identity and access management practices centered around least privilege, JIT access, approvals, auditability, and periodic access reviews. Own third-party/vendor security assessments and risk reviews. Help secure the underlying AWS/Terraform infrastructure, including cloud guardrails, gated releases, observability, and disaster recovery. Leverage AI and automation to eliminate manual security and compliance processes wherever possible. Ideal Background 7+ years of experience in security engineering, cloud security, detection/response, or a closely related discipline. Strong AWS cloud security experience, including IAM, organization-level guardrails, Terraform, and least-privilege architecture. Proven experience securing high-value financial infrastructure, ideally within payments, banking, crypto, exchanges, custody, or similar environments. Strong threat-modeling capabilities and the ability to communicate technical security decisions clearly to executives, auditors, and regulators. Hands-on experience with AI-assisted development/coding tools and a strong automation mindset. Excellent written communication skills, particularly around security decisions, control narratives, and incident reviews. Nice-to-Haves Experience with crypto custody, MPC, HSMs, wallet infrastructure, or key ceremonies. Experience operating in regulated/audited environments involving SOC 2, FFIEC, NIST 800-53, or bank examinations. Rust or smart-contract experience/literacy. Experience with stablecoins, blockchain infrastructure, or onchain payments.