SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Slash is a fast-growing fintech founded in 2021 that powers over $10B annually in business purchasing. The company recently raised a $100M Series C and is building industry-specific business banking infrastructure combining high yields, rewards, and security with tools tailored to how businesses operate.
As the first Chief Information Security Officer, you will own security strategy and execution across the entire organization. This is a hands-on, technical role requiring deep involvement in threat modeling, architecture review, and incident response—not a policy-focused position. You will report to the CTO and collaborate closely with engineering, compliance, legal, risk, and partner banks.
Key responsibilities include:
- Developing and executing Slash's end-to-end security strategy, prioritizing initiatives and determining build-versus-buy decisions
- Building and leading the security team, starting with hiring a Security Engineering lead and scaling a small group of exceptional engineers
- Securing a platform handling real money: card issuing (PCI DSS compliance), ACH and wire flows, stablecoin payments, treasury, working capital, and public APIs
- Leading account security and anti-takeover initiatives, including MFA, passkeys, session/device security, rate limiting, and permission controls
- Defining security approaches for AI agents and automation acting on customer accounts, including permissions, guardrails, auditability, and abuse prevention
- Owning cloud and infrastructure security posture across AWS and Cloudflare (identity, access, secrets, logging, detection, response)
- Building and running incident response programs, including playbooks, on-call processes, and communication with customers, partners, and regulators
- Managing compliance frameworks and audits (SOC 2 Type II, PCI DSS), supporting partner-bank reviews and enterprise customer security assessments
- Establishing third-party and vendor risk management across banking, crypto, lending, and infrastructure partners
- Running penetration testing, bug bounty programs, and red-team exercises
- Communicating security risk to leadership and the board in accessible language
Requirements:
- 10+ years in security with meaningful experience leading security at a fintech, payments company, bank, or crypto company handling real money
- Proven track record building and scaling a security program from early stage through hypergrowth
- Deep technical credibility: ability to review authentication flows line-by-line with senior engineers and explain risks to the board
- Hands-on experience with PCI DSS and SOC 2 compliance, and familiarity with sponsor bank security expectations and FFIEC-style examinations
- Strong cloud security experience, ideally AWS, in modern engineering environments shipping at speed
- Sound judgment on security-engineering tradeoffs; ability to make security the fast path rather than a blocker
- Calm and decisive demeanor during security incidents
- Bonus: experience securing crypto/stablecoin infrastructure, card issuing programs, global/multi-entity payment operations, or founding/early security leadership at high-growth companies