Skip to content
ProtegeProtege

Head of Security

Leads end-to-end security strategy, architecture, operations, and culture for AI training data platform. Builds compliance programs (SOC 2, HIPAA), secures data pipelines, conducts technical reviews, and fosters security-aware culture. Requires 8+ years security experience with 2+ in leadership.

About the job

What You’ll Do

Mature the Security & Compliance Program

  • Audit and improve the existing security program by identifying gaps, prioritizing improvements, and bringing more structure to what exists.
  • Formalize security policies and frameworks appropriate for our stage
  • Own and evolve our compliance posture. We have SOC 2 Type II in place and you'll maintain it, improve our controls, and provide automation wherever needed
  • Ensure compliance with HIPAA and other healthcare data regulations, and build a robust PHI protection program

Protect the Data Pipeline

  • Secure the end-to-end lifecycle of training data which includes ingestion, processing, storage, preparation, and delivery
  • Partner with engineering to embed security into CI/CD pipelines, cloud infrastructure, and data workflows

Be Technical and Hands-On

  • Conduct threat modeling, architecture reviews, and code-level security assessments
  • Lead incident response when things go wrong
  • Evaluate and deploy security tooling

Enable the Business

  • Translate security risks into business language for the executive team and board
  • Serve as the security face to customers, fielding security questionnaires, supporting sales cycles, and building trust with AI company partners and customers
  • Build a security-aware culture across the company through training and lightweight processes that don't slow teams down

Scale the Function

  • Decide what to build, what to buy, and what to outsource
  • Set the roadmap for how security evolves from Series A through a rapid growth stage

What You Bring

Must Haves

  • 8+ years in security roles, with at least 2 years in a leadership capacity
  • Deep technical foundation: you've worked as or alongside engineers and can credibly review architecture, infrastructure, and code
  • Experience building or significantly maturing a security program at an early-stage or high-growth company (not just maintaining one at a large enterprise)
  • Strong understanding of cloud security (AWS, GCP, or Azure), identity/access management, and data protection at scale
  • Hands-on experience with compliance frameworks (SOC 2, ISO 27001). You’ve maintained certifications and know how to expand scope without over-engineering the problem
  • Hands-on experience with HIPAA compliance
  • Comfort operating as an individual contributor and a leader simultaneously

Nice to Haves

  • Experience securing data pipelines or working with data-intensive platforms
  • Experience working in a data infrastructure company
  • Background in AI/ML or companies selling to technical buyers
  • Experience with data provenance, lineage tracking, or data governance in ML contexts
  • Familiarity with supply chain security
  • Prior experience as a customer-facing security leader

Skills

SOC 2, ISO 27001, HIPAA, AWS, GCP, Azure, CI/CD, Threat Modeling, Incident Response, Identity/Access Management, Data Protection, Cloud Security, Data Pipelines, Supply Chain Security

LogicGate

LogicGate

Chicago, IL
Director, Cybersecurity
$190k+/yrOn-site8+ YOESecurity Engineering

Leads LogicGate’s internal security organization, compliance posture, risk management, and customer trust program while serving as Deputy CISO. Requires 7–10 years of information security experience, substantial people leadership, SaaS compliance expertise, and strong technical knowledge of modern security architectures.

GameChanger

GameChanger

United States

Director, Information Security & Technology
$220k+/yrRemote10+ YOESecurity Engineering

Leads GameChanger’s Information Security and Technology strategy, teams, roadmap, and risk decisions, with primary focus on product and application security. Requires 10+ years of security experience, broad security-program leadership, and experience managing technical leaders and partnering with Engineering and executives.

ZoomInfo

ZoomInfo

Ireland

Senior Director, Security Governance
No salary listedRemote10+ YOESecurity Engineering

Leads ZoomInfo’s enterprise security governance, risk, and compliance strategy for Ireland, including continuous compliance, third-party risk, AI-enabled automation, and executive reporting. Requires 10+ years in information security or GRC, senior leadership experience, and strong knowledge of NIST, ISO, and SOC 2 frameworks.

Exa

Exa

San Francisco, CA

Head of Security
$250k+/yrOn-site8+ YOESecurity Engineering

Leads Exa’s company-wide security strategy, architecture, engineering, governance, incident response, and team development across AI infrastructure, cloud, products, and corporate systems. Requires executive-level security accountability and deep technical credibility in a rapidly scaling technology company.

Fetch

Fetch

United States

Director of Information Security
No salary listedRemote8+ YOESecurity Engineering

Leads Fetch’s end-to-end information security program, including application security, vulnerability management, incident response, architecture, GRC, AI risk, and third-party risk. The role requires 7+ years of security experience, incident command capability, and people leadership.