Alchelyst is a client solutions and infrastructure partner for private markets asset managers. Purpose-built for the expanding demands and sophistication of global private markets, the firm offers a comprehensive managed service offering that can support GPs, private wealth funds and investors. Alchelyst has offices in the US, Ireland, UK, Luxembourg and India.
About the Role
We're seeking an Information Security Lead to join Alchelyst as our first dedicated in-house information security hire. Working closely with strategic security advisors, internal teams, and third-party vendors, you'll own the day-to-day operation, strengthening, and continuous improvement of our security posture — turning risk-appetite guidance into concrete, working controls across our proprietary Aurum platform and the growing ecosystem of vendors and partners that supports it.
It's a broad remit by design. As the first dedicated hire in this space, you'll help shape priorities as much as execute against them, with security operations and policy and culture as the immediate focus, and vendor accountability and the strategic build-out of the function following close behind.
We're looking for someone who wants to build something and leave a mark, not just maintain someone else's system. You're pragmatic — you know the difference between a real risk and a compliance-checkbox risk — and you're comfortable navigating ambiguity, since this role's priorities will take shape as you settle in rather than arriving pre-defined.
What You'll Do
Security Operations & & Continuous Improvement
- Own execution of security improvements and control enhancements across cloud infrastructure, identity, and integration layers.
- Run technical security operations: monitoring, incident response, vulnerability management, and access reviews across cloud and network infrastructure.
Policy, Standards & Culture
- Maintain and evolve security policies and standards, and drive adoption across engineering and vendor teams.
- Partner with Engineering on security development practices — tooling, training, and best practices — so policies translate into day-to-day engineering work.
- Build lightweight, practical security awareness across a non-technical workforce.
Compliance & Emerging Technology
- Support regulatory and audit readiness across regulatory obligations spanning all jurisdictions and entities and contribute into client due-diligence requests.
- Contribute technical input into emerging AI/agentic tooling initiatives from a security standpoint.
Vendor & Partner Management
- Act as primary internal point of contact for third-party security services firms — advisory, vulnerability management, penetration testing — acting as the operational bridge that turns their risk-appetite guidance into concrete controls and projects, and ensuring findings are tracked, prioritized, and resolved.
- Manage the broader security vendor ecosystem, including managed service providers and application/platform vendors.
Strategic Growth of the Function
- Continuously monitor Alchelyst's evolving security needs, ensuring the information security function itself adapts and grows in step with the business — recommending changes in tooling, resourcing, or process as the firm scales.
Qualifications & Experience
- 8+ years in information security, with strong hands-on Security Operations experience; exposure to governance and compliance is a plus, though deep policy-authorship experience is not required.
- Experience in a regulated financial services or fund administration context is a strong plus.
- Experience working with external security partners — for example, penetration testing providers or managed security services — including reviewing findings and holding them to agreed resolution timelines; broad multi-vendor ecosystem exposure is a plus but not essential.
- Comfortable operating in modern cloud environments, supporting a distributed and mobile workforce.
What Success Looks Like
- Within 90 Days: Understands the technology estate, current improvement priorities, and vendor relationships. Establishes working cadences with third-party security firms and internal teams. Begins delivering priority security enhancements.
- Within 6 Months: Owns the security improvement program end-to-end, with clear tracking and vendor accountability. Policies and standards are being actively adopted across engineering. Security awareness activity is underway across the wider firm.
- Within 12 Months: Recognized as the internal owner of day-to-day security across the firm. Has proposed and begun implementing changes to tooling, resourcing, or process to keep pace with business growth. Regulatory and client due diligence requests are handled smoothly and with confidence.
- Ongoing: Consistently ensures security and compliance across both platforms and operations. Champions a pragmatic, risk-based security culture across a non-technical workforce.
This position is open across multiple locations. The expected annual base salary range for this position is €95,000–€145,000 (Dublin), £100,000–£150,000 (London), and $180,000–$240,000 (New York). Ranges reflect job function, level, and geographic market, and are provided in compliance with applicable local salary disclosure requirements. Final compensation is determined based on a candidate's experience and qualifications and may vary from the ranges listed.