Help us maintain the quality of our job listings. If you find any issues with this job post, please let us know.
Select the reason you're reporting this job:
Toku is the first comprehensive, global solution for token compensation & tax compliance.
Toku’s comprehensive suite of services include: token-based payroll, token-based grant administration, employment and tax compliance, and WorkDAO – a unique set of employment and compensation services tailored for the needs of decentralized autonomous organizations (DAOs).
Amidst an environment of increasing regulatory scrutiny in web3, Toku provides their customers peace of mind with 100% tax compliance on all token-based compensation in over 100 countries globally.
Toku is the leading provider of compliance infrastructure for crypto companies, enabling them to pay employees in tokens and stablecoins while staying compliant with state, federal, and international tax laws. Our growing client list includes 30% of the crypto companies listed on Robinhood.
Backed by $26M from leading investors including Blockchain Capital and Naval Ravikant, Toku is scaling rapidly to meet the demand for compliance solutions in the evolving regulatory environment. Read more about Toku in Fortune, Yahoo Finance, and CoinDesk.
As Toku’s Compliance and Privacy Officer, you’ll lead privacy and security programs, ensuring adherence to regulatory standards like GDPR, SOC2, and ISO 27001. This pivotal role combines technical expertise and strategic leadership to ensure regulatory adherence and data protection, shaping the future of compliance in the evolving crypto industry.
What you'll do
Oversee Privacy and Compliance Frameworks:
Oversee GDPR compliance practices and drive certification efforts with TrustArc/eTrust, a leading privacy compliance governance certifier.
Design and execute privacy and security programs aligned with regulatory frameworks (e.g., SOC2, GDPR, ISO 27001).
Lead security and privacy program initiatives collaboratively across teams.
Act as a point of contact for privacy-related inquiries and audits.
Manage Security Protocols:
Develop and implement security protocols to ensure data integrity and protection.
Conduct system security audits and penetration testing.
Define access control measures, encryption standards, and secure data transfer protocols.
Technical Leadership:
Lead vulnerability assessments and remediation strategies.
Collaborate with engineering teams to integrate privacy-by-design and security-by-design principles.
Develop Training Programs:
Establish company-wide privacy and security training initiatives.
Stay current with evolving regulations and security threats, adapting strategies accordingly.
What we’re looking for
Bachelor’s or Master’s degree.
4-8 years of experience driving security/privacy engineering, business practices, and programs in a fintech SaaS or HRIS/payroll platform.
Proven track record managing GDPR, SOC2, or ISO 27001 implementations.
Strong understanding of encryption, authentication, and network security.
Familiarity with compliance management platforms like TrustArc or Drata.
Excellent written and verbal communication skills with the ability to simplify complex ideas for diverse audiences.
Certificates preferred
Certified Information Systems Security Professional (CISSP).
Certified Information Privacy Professional (CIPP/E, CIPP/US)ISO 27001.
Lead Implementer certification.
Why you’ll love working at Toku
Shape the future of the crypto compliance space during a pivotal regulatory moment.
Work alongside innovative clients and highly engaged industry-leading investors.
Join a fast-growing startup with a clear market need and a strong product-market fit.
Competitive salary, equity, and remote-friendly work culture.
Toku is an equal opportunity employer, and we are committed to being a diverse team that reflects a broad range of background, thought, and experience. We do not discriminate based on race, color, religion, sex, gender identity, sexual orientation, age, national origin, status as an individual with a disability, status as protected veteran, or any other legally protected characteristics. Women, minorities, LGBTQ+, and people from underrepresented backgrounds are strongly encouraged to apply.
We strongly encourage you use Rezi.ai to vet resume quality before applying.
Required profile
Experience
Level of experience:Senior (5-10 years)
Industry :
Professional Services
Spoken language(s):
English
Check out the description to know which languages are mandatory.