Head of Security
Leads Exa’s company-wide security strategy, architecture, engineering, governance, incident response, and team development across AI infrastructure, cloud, products, and corporate systems. Requires executive-level security accountability and deep technical credibility in a rapidly scaling technology company.
About the job
Responsibilities
- Define the company-wide security strategy, operating model, risk framework, and multiyear roadmap.
- Establish security posture and risk appetite with the founders and executive team.
- Provide leadership with decision-ready assessments of material risks, incidents, investments, and tradeoffs.
- Own security architecture and engineering across products, APIs, web-scale data pipelines, cloud environments, Kubernetes clusters, model-training systems, GPU infrastructure, and internal platforms.
- Protect customer data, proprietary models, training data, source code, credentials, and other high-value assets from external attacks, insider threats, supply-chain compromise, and misuse.
- Embed security into the product-development lifecycle through threat modeling, architecture reviews, secure defaults, automated controls, vulnerability management, offensive testing, and engineering education.
- Establish identity, access, secrets, key, certificate, and service-trust systems across human users, workloads, training jobs, and AI agents.
- Build detection, investigation, incident response, crisis management, and recovery capabilities; lead significant security incidents.
- Own corporate security, including endpoints, SaaS applications, employee access, security awareness, insider risk, physical-security interfaces, and third-party risk.
- Lead security governance, regulatory readiness, compliance, and customer assurance programs, including SOC 2 and ISO 27001.
- Represent the security program in strategic customer conversations, enterprise reviews, audits, and other high-trust settings.
- Define the security organization’s structure, budget, technology strategy, external partnerships, and hiring plan.
- Recruit, develop, and lead the security team while fostering shared responsibility for security across the company.
- Establish security metrics and communicate posture, priorities, and progress to company leadership.
Requirements
- Experience building or leading security at a technically ambitious, rapidly growing infrastructure, AI, developer-platform, cloud, or enterprise-software company.
- Company-wide accountability for security across multiple disciplines.
- Executive judgment combined with deep technical credibility across strategy, business risk, system architecture, incident investigation, and implementation.
- Builder-and-attacker mindset with the ability to address novel security challenges without established playbooks.
Compensation and Benefits
- Annual salary: $250,000–$350,000.
- Premium medical, dental, and vision coverage.
- Fertility benefits.
- Monthly wellness stipend.
- International visa sponsorship may be available, including STEM OPT, OPT, H1B, O1, and E3.
Skills
Security Strategy, Security Architecture, Cloud Security, Kubernetes, Threat Modeling, Vulnerability Management, Incident Response, Identity And Access Management, Secrets Management, Offensive Security, SOC 2, ISO 27001, Supply Chain Security, Risk Management, Security Governance
Similar jobs
Security Engineering jobsLeads ID.me’s Product Security program and security engineering team, partnering with Product and Engineering to reduce risk through practical, developer-aligned controls. Requires strong technical depth across application and cloud security, outcome-based leadership, and experience building security programs in fast-moving cloud-native environments.
Leads GameChanger’s Information Security and Technology strategy, teams, roadmap, and risk decisions, with primary focus on product and application security. Requires 10+ years of security experience, broad security-program leadership, and experience managing technical leaders and partnering with Engineering and executives.
Leads Chronograph’s information security and IT strategy, combining executive leadership with hands-on oversight of cloud, application, AI, corporate, and compliance security. Requires at least seven years of security experience, broad technical depth, assurance-program leadership, and strong executive communication.
Leads LogicGate’s internal security organization, compliance posture, risk management, and customer trust program while serving as Deputy CISO. Requires 7–10 years of information security experience, substantial people leadership, SaaS compliance expertise, and strong technical knowledge of modern security architectures.
Leads technical security, compliance (SOC 2, GDPR, ISO 42001), vulnerability management, and infrastructure hardening for a fast-growing fintech. Requires 3-7 years in security engineering with hands-on AWS, vuln tooling, and audit experience.