HimalayasHimalayas logo
AkoyaAK

Head of Risk & Security

Akoya is transforming how consumer financial data is accessed and shared. Through its secure, API-based Data Access Network, Akoya enables financial institutions, fintechs, and data aggregators to facilitate consumer-permissioned data sharing, prioritizing consumer control and data security. [1, 5, 11]

Akoya

Employee count: 51-200

Salary: 160k-200k USD

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

Meet the future

Akoya is an API-based network backed by major financial institutions that creates a safer and more transparent way for people to safely send their personal financial data to third-party financial apps. If you are inspired and fascinated by innovative technology that solves complex, real-world problems, then join us as we transform how financial data is accessed and shared. Akoya offers a highly collaborative, fast-paced, and fun working environment and our team is comprised of diverse, creative, and driven professionals with expertise in the banking, securities, fintech, and data aggregation industries. We are an equal opportunity employer. Come join us and be part of this exciting journey – check out www.akoya.com for more information!

The Role

Akoya is seeking a seasoned, hands-on Head of Risk & Security to lead and mature our cybersecurity, risk management, and IT governance functions as we scale our secure, API-driven open finance network.

This leader will serve as the operational backbone of Akoya’s security and risk programs — translating strategy into execution. You will lead and develop a team across security engineering, cyber operations, risk, compliance, and IT, while partnering closely with Engineering, Product, Legal, Customer Success, and Business Development.

This role is ideal for a builder — someone who has scaled capabilities in security and risk functions in startup or fintech environments and understands the unique demands of serving both:

  • Financial Institutions (Data Providers) with rigorous regulatory and third-party risk requirements
  • Fintechs and Data Recipients operating in agile, API-first ecosystems

You will play a critical role in protecting Akoya’s Data Access Network and Open Finance Solution while strengthening trust across our ecosystem of financial institutions and fintech partners.

Key Responsibilities

Risk Management

  • Mature and execute Akoya’s enterprise risk management (ERM) framework.
  • Develop and track key risk indicators (KRIs) aligned with business OKRs.
  • Lead third-party risk management across fintech partners, vendors, and service providers.
  • Conduct product risk assessments across new open finance capabilities.
  • Support regulatory readiness related to CFPB Section 1033 and evolving open banking requirements.

Security & Cyber Operations Leadership

  • Lead day-to-day execution of Akoya’s cybersecurity program across product, infrastructure, and corporate environments.
  • Operationalize secure-by-design principles across SDLC in partnership with Engineering.
  • Oversee vulnerability management, penetration testing, red teaming, and incident response.
  • Drive continuous improvement of zero-trust cloud architectures (AWS-centric).
  • Enhance monitoring, automation, and threat intelligence capabilities.

Compliance & Regulatory Alignment

  • Own operational execution of SOC 2 Type II and other certifications.
  • Ensure alignment with NIST, ISO 27001/27002, GLBA, SOX, PCI (as applicable).
  • Partner closely with Legal and Product on regulatory interpretation and implementation.
  • Respond to due diligence inquiries from financial institutions, fintechs, investors, and regulators.

IT Governance & Internal Controls

  • Oversee corporate IT governance in partnership with the IT Systems Administrator (end-user security, device management, identity, remote access).
  • Ensure strong IAM, endpoint protection, DLP, encryption, and secure collaboration tooling.
  • Align IT and Security controls with remote-first operating model.

Team Leadership & Organizational Development

  • Lead and mentor security engineers, risk analysts, and IT personnel.
  • Build scalable team structure aligned with growth in API volume and institutional adoption.
  • Foster a strong security culture where accountability and transparency are embedded across functions.
  • Act as a senior advisor to ELT.

Ecosystem Trust & External Engagement

  • Interface directly with security and risk leaders at major financial institutions and fintech clients.
  • Support sales and customer conversations requiring deep technical credibility.
  • Represent Akoya in industry forums and working groups (e.g., FDX-aligned initiatives).

Qualifications

Not all applicants will have skills that match a job description exactly. Akoya values diverse experiences in other industries, and we encourage everyone who meets the required qualifications to apply. While having “desired” qualifications make for a strong candidate, we encourage applicants with alternative experiences to also apply. If your career is just starting or has not followed a traditional path, do not let that stop you from considering Akoya. We are always looking for people who will bring something new to the table!

Required Experience/skills

  • 12+ years in enterprise risk, cybersecurity, or information security.
  • 5+ years leading risk/security teams in fintech, SaaS, or regulated environments.
  • Experience building or scaling security programs in startup or high-growth organizations.
  • Deep cloud security expertise (AWS required; multi-cloud a plus).
  • Strong hands-on knowledge of:
    • Zero-trust architecture
    • Secure SDLC
    • Threat modeling
    • Vulnerability management
    • Incident response
  • Demonstrated ownership of SOC 2 and regulatory audits.
  • Experience working with both:
    • Regulated financial institutions (bank-side risk expectations)
    • Fintechs or API-based SaaS platforms (data recipient expectations)

Preferred Experience/skills

  • Experience in open banking / open finance ecosystems.
  • Familiarity with FDX standards and OAuth/OIDC-based authentication models.
  • Certifications such as CISSP, CISM, CRISC, or equivalent.
  • Experience briefing executives or board-level stakeholders.

Akoya is an equal-opportunity employer.

This remote position is only available to individuals living in the greater Boston, MA, New York City, NY and Raleigh, NC areas. Candidates who do not live within these areas will not be considered for this role.

The actual base pay offered may take into account the candidate's work location, relevant education, job-related knowledge, skills, and experience, among other factors.
Hiring Range:
$160,000—$200,000 USD

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Salary

Salary: 160k-200k USD

Experience

12 years minimum

Location requirements

Hiring timezones

United States +/- 0 hours

About Akoya

Learn more about Akoya and their company culture.

View company profile

At the heart of Akoya's endeavor is a culture deeply rooted in safeguarding consumer financial data and fostering trust within the financial ecosystem. [11, 23] Our core mission revolves around empowering consumers, granting them unparalleled choice, control, and convenience in the way their financial information is shared and utilized across the digital landscape. We are passionately committed to revolutionizing financial data access, steering the industry away from insecure, outdated practices like screen scraping, and championing a future founded on secure, transparent, and consumer-permissioned API-based connections. [5, 6, 23] This unwavering dedication to security is not merely a component of our services; it is the bedrock upon which Akoya was built and is intricately woven into every facet of our operations, ensuring that consumers retain their peace of mind by never needing to divulge their sensitive login credentials to third-party applications. [11, 23]

Our team embodies a spirit of robust collaboration, working hand-in-hand with an expansive network of over 4,300 financial institutions—ranging from major national banks to local credit unions—alongside data aggregators and pioneering fintech companies. [11, 25] This extensive and influential network, uniquely co-owned by twelve leading North American financial institutions, solidifies Akoya's position as a pivotal, interoperable solution for the entire financial services industry. [5, 12, 14] We champion a model where consumers are firmly in the driver's seat, possessing the explicit ability to grant consent for data sharing on an individual app basis, and the continuous power to monitor and, if they choose, revoke that access at any given moment. It's crucial to understand that Akoya does not control or hold consumer data; instead, we meticulously facilitate a highly secure and transparent pathway that profoundly respects consumer privacy and choice. This approach not only fosters innovation but also cultivates a more reliable and trustworthy financial experience for every participant, paving the way for a future where open finance is intrinsically linked with consumer empowerment and the highest standards of data protection. [23, 25]

Claim this profileAkoya logoAK

Akoya

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

3 remote jobs at Akoya

Explore the variety of open remote roles at Akoya, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Akoya

Remote companies like Akoya

Find your next opportunity by exploring profiles of companies that are similar to Akoya. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan