Skip to main content
zeroShadow
Back to jobs

Security Risk Advisor

Apply Now
Anywhere | Remote

zeroShadow is a Web3 security company protecting the next generation of decentralised systems through proactive security intelligence and rapid incident response.

Our Security Advisors play a pivotal role in guiding zeroShadow’s clients through their security and compliance journeys, while also maintaining the integrity of our internal security posture. Reporting to the Head of Security & Risk Management, this role bridges the gap between formal compliance frameworks (like ISO 27001 and SOC 2) and real-world business operations. The ideal candidate is a pragmatic practitioner who meets clients where they are, delivering tailored, sensible security solutions rather than enforcing rigid Governance, Risk and Compliance frameworks and can lead ISO 27001 Internal Audit efforts.

Key Responsibilities

  • Perform security and compliance assessments to identify risks, gap areas, and practical opportunities for improvement.
  • Guide clients along their security maturity journeys, developing realistic security roadmaps tailored to their current technical and operational maturity.
  • Partner with client stakeholders to turn complex ISO 27001, SOC2, and GRC concepts into pragmatic, business-enabling advice, prioritizing risk remediation over bureaucratic friction.
  • Collaborate with internal Subject Matter Experts (SMEs) across zeroShadow to ensure clients are matched with the right technical expertise and resources for their specific needs.
  • Review client-facing documentation such as incident response plans, policies, and procedures to assess whether it is fit for purpose against industry best practice, providing clients with clear, actionable feedback.
  • Experience crafting and drafting security documentation (e.g., policies, procedures, and incident response plans) from the ground up for clients.
  • Maintain a bidirectional feedback loop: translate lessons learned from client engagements into internal GRC enhancements, and use zeroShadow’s operational successes to reassure and guide clients.

What you'll bring

Must-haves

  • 2-4 years experience in a governance, risk, compliance or information security consulting role including ISO27001 and SOC2 certifications
  • Familiarity with less mature clients and the ability to translate their needs into goals they can prioritize

Nice to haves

  • Basic understanding of Web3 concepts or interest in recent news in the crypto ecosystem
  • Risk management experience with AI systems

Application Form

Loading Application form...