Head of Security & Compliance
Lead security and compliance for an AI-native banking startup. Build security tooling, manage a team of appsec engineers, own compliance (SOC 2, ISO 27001), and secure AI agent workflows.
About the job
What you'll do
- Build security tooling & processes that engineers actually use. Create internal mechanisms for appsec, identity and access management, and threat detection that naturally integrate into how the team ships.
- Manage, mentor, and grow our team of application security engineers. Mature our Secure SDLC, threat modeling, and vulnerability management processes to ensure our security posture matches our growing responsibility.
- Secure the agent execution surface. Partner with Engineering and Product to establish robust security architecture for our AI-driven workflows, ensuring strict data privacy, mitigating AI-specific vulnerabilities, and maintaining safe agentic identity.
- Drive customer trust. Partner with go-to-market and legal teams to support compliance and customer-driven initiatives. Own and expand our compliance roadmap (SOC 2, SOC 1, ISO 27001), while keeping guardrails pragmatic for a fast-paced startup.
- Lead incident response and detection. Build the detection pipeline, act as the primary commander, and turn every event into systemic improvements.
What you'll bring
- 5+ years in progressive security roles, with at least 2+ years at a B2B tech, fintech, or highly regulated SaaS company.
- Strong fundamentals in secure SDLC, cloud security (AWS/GCP), Web security, and DevSecOps practices.
- Ability to develop lightweight, durable security policies, access controls, and data governance frameworks. A track record of building "practical security, not checkbox theater."
- You can review a penetration test, debate architecture with a lead engineer, and present to a bank's CISO…all in the same day.
- You’re comfortable with incident response - calm, methodical, and effective under pressure; experience leading incidents end to end & driving the fixes that follow.
- You thrive in ambiguity, know how to ruthlessly prioritize fixes to eliminate the highest risks first, and understand the balance between security and business velocity.
Nice to have
- Experience securing LLM usage for both coding and in product use cases, and mitigating risks specific to agentic systems (e.g., unauthorized actions taken by autonomous agents, prompt injection, and data poisoning).
- Proven track record of owning SOC 2 Type II and/or ISO 27001 compliance.
- Experience in fintech or banking.
Skills
Secure Sdlc, Cloud Security, AWS, GCP, Web Security, DevSecOps, Application Security, Identity And Access Management, Threat Detection, Incident Response, SOC 2, ISO 27001, Penetration Testing, Data Governance
Similar jobs
Security Engineering jobsLeads LogicGate’s internal security organization, compliance posture, risk management, and customer trust program while serving as Deputy CISO. Requires 7–10 years of information security experience, substantial people leadership, SaaS compliance expertise, and strong technical knowledge of modern security architectures.
Leads Chronograph’s information security and IT strategy, combining executive leadership with hands-on oversight of cloud, application, AI, corporate, and compliance security. Requires at least seven years of security experience, broad technical depth, assurance-program leadership, and strong executive communication.
Leads technical security, compliance (SOC 2, GDPR, ISO 42001), vulnerability management, and infrastructure hardening for a fast-growing fintech. Requires 3-7 years in security engineering with hands-on AWS, vuln tooling, and audit experience.
Leads GameChanger’s Information Security and Technology strategy, teams, roadmap, and risk decisions, with primary focus on product and application security. Requires 10+ years of security experience, broad security-program leadership, and experience managing technical leaders and partnering with Engineering and executives.
Leads ID.me’s Product Security program and security engineering team, partnering with Product and Engineering to reduce risk through practical, developer-aligned controls. Requires strong technical depth across application and cloud security, outcome-based leadership, and experience building security programs in fast-moving cloud-native environments.