Head of IT & Information Security
Lead security, compliance, and IT functions including SOC 2, ISO 27001, privacy, risk management, and external industry presence. Requires 7+ years in security/compliance/IT with direct experience leading compliance programs.
Responsibilities
Compliance & Privacy
- Own compliance program, including SOC 2 and ISO 27001, and the ISMS that supports them
- Assist with operational privacy processes in support of GDPR and adherence to privacy laws across all US states and international requirements
- Assist the CISO with privacy program implementation
Risk Management
- Lead the third-party risk management program
- Lead AI risk management and governance
Security & IT Leadership
- Drive focus areas: identity and access management, product security, and internal IT operations
Industry Presence & Thought Leadership
- Contribute to security research and thought leadership
- Drive and attend industry events in partnership with the go-to-market team
- Submit to and speak at conferences
Requirements
- 7+ years across security, compliance, and IT, including direct experience leading ISO 27001 and SOC 2 programs
- Working knowledge of GDPR and US state and international privacy requirements
- Experience across identity, product security, risk management, and IT operations
- Comfortable representing the company externally — at events, in research, and on stage
- Clear communicator who can translate technical and regulatory requirements for any audience
Nice to Have
- CISSP, CISM, CIPP/E, ISO 27001 Lead Implementer/Auditor, or equivalent certifications
- Established presence in the security community: publications, talks, or research contributions
Compensation & Benefits
- Competitive base salary + equity
- Equity in a venture-backed, high-growth company
- Comprehensive benefits: health, dental, vision, 401(k)
- Flexible PTO
- Estimated salary range: $160,000 - $225,000/year
- Total compensation may include stock options, sign-on bonus, and other potential future incentives
Senior Security Engineer, Cloud, AI, Product Security
Senior Security Engineer responsible for identifying infrastructure and product risks, defining remediation roadmaps, and building scalable secure engineering systems. Requires 5+ years in security engineering and strong IaC and code review experience.
Senior Software Engineer
Senior Software Engineer on the Core Cryptography team building and operating Tier-0 cryptographic infrastructure including MPC systems that secure 99% of customer assets. Requires 5+ years building highly available distributed systems and experience with applied cryptography, KMS/HSMs, and systems languages (Golang-heavy).
Staff Product Security Engineer
Staff-level product security engineer leading security reviews, threat modeling, penetration testing, and LLM/AI security assessments for Okta's identity platform. Requires deep manual security expertise and strong communication skills.
Security Engineer - Product
Lead product security for a fintech credit card infrastructure platform. Own API security, auth strategy, fraud primitives, secure SDLC, and compliance for partner-facing services. Hands-on engineering role reporting to Head of Engineering.