Skip to content
MomentMoment

Head of Security

Own the end-to-end security program for a fintech infrastructure company, driving strategy, compliance (SOC 2), incident response, and client-facing security reviews for institutional trading systems.

About the job

What You'll Do

  • DRI the security program including application security, cloud infrastructure security, identity and access management, vulnerability management, detection, and incident response. Set standards and run operations.
  • Scale security programs and face off with top-tier RIAs, broker-dealers, and global bank security teams.
  • Own compliance and regulatory posture including SOC 2 and regulatory baselines for broker-dealers and institutional financial infrastructure.
  • Run audits, manage the Trust Center, and partner with Legal and Compliance.
  • Lead incident response: run the room, make calls, communicate to clients, and write postmortems.

Requirements

  • Deeply technical: read code, reason about modern cloud architectures (AWS, Kubernetes), threat-model real systems, and ship security tooling.
  • Experience running a security program at a fintech, trading firm, or financial infrastructure company with real stakes and high regulatory bar.
  • Comfortable presenting to senior client security teams and clearing enterprise security reviews.
  • Builder mindset for a 0-to-1 leadership role.

Nice-to-Haves

  • Prior experience at a broker-dealer, market maker, fund administrator, or core fintech infrastructure provider.
  • SOC 2 Type 2 audit experience as lead or co-lead.
  • Background in security engineering: CSPM, IAM, AppSec, detection engineering, or incident response with shipped work.

Compensation & Benefits

  • Base salary: $275K–$325K + initial equity grant + annual performance-based equity bonuses.
  • Free lunch and dinner.
  • Health, dental, and vision coverage.
  • $150 monthly gym stipend.

Skills

AWS, Kubernetes, Application Security, Cloud Security, Identity And Access Management, Vulnerability Management, Detection Engineering, Incident Response, SOC 2, Threat Modeling

Exa

Exa

San Francisco, CA

Head of Security
$250k+/yrOn-site8+ YOESecurity Engineering

Leads Exa’s company-wide security strategy, architecture, engineering, governance, incident response, and team development across AI infrastructure, cloud, products, and corporate systems. Requires executive-level security accountability and deep technical credibility in a rapidly scaling technology company.

Idme

Idme

Mountain View, CA

Director of Product Security
$244k+/yrOn-site8+ YOESecurity Engineering

Leads ID.me’s Product Security program and security engineering team, partnering with Product and Engineering to reduce risk through practical, developer-aligned controls. Requires strong technical depth across application and cloud security, outcome-based leadership, and experience building security programs in fast-moving cloud-native environments.

GameChanger

GameChanger

United States

Director, Information Security & Technology
$220k+/yrRemote10+ YOESecurity Engineering

Leads GameChanger’s Information Security and Technology strategy, teams, roadmap, and risk decisions, with primary focus on product and application security. Requires 10+ years of security experience, broad security-program leadership, and experience managing technical leaders and partnering with Engineering and executives.

Anthropic

Anthropic

New York, NY
Head of Vulnerability Disclosure & Security Community
$330k+/yrHybrid8+ YOESecurity Engineering

Leads Anthropic’s coordinated vulnerability disclosure and CNA programs, including jailbreak disclosures, external researcher partnerships, public communication, and AI-assisted triage. The role requires disclosure coordination, vulnerability-response operations, and security-community engagement experience.

Chronograph

Chronograph

Brooklyn, NY

Head of Information Security & IT
$215k+/yrOn-site8+ YOESecurity Engineering

Leads Chronograph’s information security and IT strategy, combining executive leadership with hands-on oversight of cloud, application, AI, corporate, and compliance security. Requires at least seven years of security experience, broad technical depth, assurance-program leadership, and strong executive communication.