Leads customer-facing security reviews and the company’s internal security and compliance program, including SOC 2 Type II, ISO 27001, cloud security, IT operations, and a small technical team. Requires 10+ years of security experience and management experience.
Salary not listed
Remote10+ YOESecurity Engineering
About the role
Responsibilities
Serve as the security point of contact for prospects and customers, leading trust and security reviews across the sales cycle and customer lifecycle.
Own security questionnaires, RFP security sections, and audit-support requests for enterprise security teams.
Own and mature the internal security program across cloud infrastructure, applications, corporate systems, and data, including vulnerability management, monitoring, and incident response.
Maintain SOC 2 Type II and ISO 27001 compliance, including control management, audit coordination, and continuous evidence collection.
Lead and grow a team spanning security engineering and compliance, and own the security roadmap and priorities.
Oversee IT operations, including identity and access, endpoint management, and SaaS administration.
Requirements
10+ years in security or security engineering, including 3+ years in a customer-facing or GRC capacity such as trust reviews, questionnaires, or audits.
2+ years managing security engineers or a comparable technical team.
Strong grounding in cloud security, preferably AWS, including infrastructure, identity and access, and application security.
Ability to represent a security posture credibly to enterprise security teams, CISOs, and auditors, and translate technical controls into clear assurances.
Sound judgment when prioritizing security work against real risk at a fast-moving company.
Nice-to-haves
Experience at a security vendor or a company selling to enterprise security teams.
Familiarity with security operations tooling, SIEM, detection engineering, threat detection, and modern SOC teams.
Experience owning or overseeing IT in a growing company.
Experience scaling a security program from an early- or mid-stage company.
Compensation & Benefits
Competitive salary with equity in the company.
Comprehensive medical, dental, and vision insurance.
Unlimited paid time off.
401(k) retirement plan with company match.
Monthly stipend for home internet and cell phone expenses.
Final compensation depends on experience, qualifications, and location.
Leads NexHealth’s security governance, compliance, IT operations, vendor security, privacy, and incident response programs while building the security function and team. Requires 8+ years of security experience, leadership building programs from the ground up, audit ownership, and a software engineering background.
160k – 200k/yrOn-site8+ YOESecurity Engineering
Director, Information Security & Technology
GameChangerUnited States
Leads GameChanger’s information security and internal technology operations strategy, teams, and roadmap across product, cloud, AI, security operations, GRC, incident response, and employee IT. Requires 10+ years of security experience, leadership of managers, and broad program-building expertise.
220k – 240k/yrRemote10+ YOESecurity Engineering
Director, Security Engineering
Virta HealthUnited States
Leads enterprise security engineering and SecOps, directing a security team, outsourced MDR/SOC operations, incident response, and a Zero Trust transformation. Requires 10+ years in cybersecurity or cloud infrastructure security, leadership experience, and deep GCP, micro-segmentation, workload identity, and CI/CD expertise.
162k – 209k/yrRemote10+ YOESecurity Engineering
Director, Trust & Safety Detection and Intelligence
FetchUnited States
Leads Fetch’s fraud detection and threat intelligence function, overseeing investigations, detection systems, risk prioritization, and anti-abuse strategy. Requires 10+ years in fraud, trust and safety, cybersecurity, or related risk work, plus 5+ years managing senior teams.
176k – 207k/yrRemote10+ YOESecurity Engineering
Head of Security
TremendousUnited States
The first security leader will own Tremendous' end-to-end security posture, including product security, incident response, identity, vendor risk, and AI security. This player-coach role requires hands-on experience scaling security programs, strong engineering judgment, and the ability to build a future team.