Security & Trust Lead
Own Alex’s information security, compliance, AI governance, and enterprise trust program as its first dedicated Security & Trust hire. The role combines security reviews and customer-facing assurance with audits, regulatory readiness, risk management, and technical control development.
About the job
Responsibilities
- Own enterprise customer security reviews, including infosec questionnaires, SIGs, CAIQs, vendor risk assessments, DPAs, and security addenda.
- Build an answer library, evidence repository, and AI-enabled tooling to automate questionnaire responses.
- Track and interpret the EU AI Act, NYC Local Law 144, GDPR, state AI and biometric laws, bias-auditing requirements, and emerging regulations for automated employment decision tools.
- Lead security, information security, and AI governance calls with enterprise prospects and customers.
- Build and maintain the trust center, security whitepapers, and AI governance documentation.
- Own SOC 2 and drive future compliance initiatives, including ISO 27001, ISO 42001, and regional requirements.
- Manage auditors, penetration tests, and compliance-platform tooling.
- Partner with Engineering on access management, vendor and subprocessor reviews, vulnerability remediation, incident response, cloud security, and CI/CD security.
- Maintain the risk register and operate the security program against it.
- Engage Product and Engineering early on new features and model changes to address security, privacy, and AI-governance concerns during design.
Requirements
- Technical, highly organized, and motivated to develop deep expertise in information security, compliance, and AI risk.
- Ability to own security and compliance programs and communicate effectively with enterprise security teams and customers.
- Ability to work cross-functionally with Engineering, Product, Sales, Operations, and executive leadership.
Nice-to-haves
- Experience with enterprise security reviews and information-security questionnaires.
- Familiarity with SOC 2, ISO 27001, or ISO 42001.
- Knowledge of AI governance, AI regulation, privacy, or automated employment decision tools.
- Experience with security controls, audit management, penetration testing, risk registers, or compliance platforms.
Compensation and Benefits
- $150,000–$180,000 annual compensation, plus equity.
- Healthcare, vision, and dental insurance.
- 401(k).
- Unlimited PTO.
- Company-paid lunches and company events.
Skills
Information Security, Ai Governance, SOC 2, ISO 27001, Iso 42001, GDPR, Eu Ai Act, Risk Management, Incident Response, Penetration Testing, Cloud Security, Ci/Cd Security, Vulnerability Management, Vendor Risk Management, Access Management
Similar jobs
Security Engineering jobsBuild and own Juicebox’s governance, risk, compliance, and customer trust function, leading audits, enterprise security reviews, policies, and AI governance initiatives. Requires 3+ years in GRC or security compliance and experience with SOC 2, ISO 27001, and customer security questionnaires.
Leads a high-leverage fraud intelligence team while personally investigating complex attacks across identities, devices, accounts, and payments. The role combines people leadership, incident response, threat intelligence, and partnerships with product and ML teams to improve fraud detection and prevention.
Provides technical leadership for Security Operations by building cloud security platforms, automated controls, vulnerability-management workflows, and developer-facing security capabilities. Requires senior-level production systems experience, AWS security architecture, Terraform, and strong cross-functional technical ownership.
Lead technical response to security incidents across Twilio's global cloud infrastructure, including triage, containment, remediation, documentation, and post-incident improvements. Requires 5+ years incident response experience, expertise with SIEM/SOAR, cloud platforms, and AI-driven security tools.
Senior Security Engineer on the Red Team performing offensive security, adversarial testing, and red team operations against GenAI/LLM systems, deepfake defenses, cloud infrastructure, and SaaS products. Requires 3+ years of hands-on pen testing/red team experience plus demonstrable GenAI attack experience.