This one is closed
Live roles like this one
-
C
2h ago
Synthomer Netherlands
- C 2h ago
-
B
2h ago
Technical Instructor I, Cybersecurity
Per Scholas United States $75k - $80k/yr
-
C
1d ago
ElevenLabs New York · United States
Get new “Security” roles by email
One email a day with what is new in "Security". Nothing new, no email.
We confirm the address first, and every mail carries an unsubscribe link. Alerts are ours, not a third party's.
Why this grade This listing scored 54/100, which is a D. It lost the most ground on pay transparency. See the breakdown
- Description depth 20 / 20 How much the posting actually says about the work, measured in characters of real text.
- Pay transparency 12 / 25 A published salary range, worth more than any other single factor because it is what a candidate cannot find out without applying.
- Role specificity 10 / 10 Whether the listing is tagged well enough to tell what the role actually is.
- Corroboration 10 / 10 Whether more than one source carries this listing.
- Remote clarity 8 / 15 Whether "remote" means anywhere, or is quietly restricted to one country.
- Freshness 4 / 15 How recently it was posted. Older postings are likelier to be filled or abandoned.
-10 Ghost-job penalty — Deducted for signals that this posting may not be a real, currently-open role — staleness, repeated relisting, or talent-pool language.
Every figure above is arithmetic over the posting itself — its salary field, its text, its age, its tags and how many sources carry it. How the grades work →
exec design architecture recruiter customer support marketing content writing ops golang full time digital nomad dev senior medical engineer infosec react embedded technical finance cloud postgres typescript ruby
We're profitable and growing without outside investors. We're fully remote, with a high-documentation, low-meeting culture that leaves more time for the work that mattersâand for your life outside it. Our employee NPS sits in the high 80s.
We move billions of dollars through our systems. That makes security existential, and it's why we're making our first dedicated security hire.
About The Role
You'll be our first Head of Security. There's already a real foundation hereâbug bounty, pen tests, automated code and configuration scanning on the production and code side, phishing simulations on the people side. Youâll add to it across access and identity, SecOps and monitoring, incident response, vendor security, employee security practices, and policy. You'll own the whole posture.
This is a player-coach role. Early on, you'll do the scoping and the hands-on work yourself; this is not a role where you direct from above. As the work demands it, we're fully prepared to build a team hereâand we're looking to you to define what that team should be and when.
You'll report to the VP of Engineering, Tremendous' most senior technical leader. We've deliberately placed security with Engineering so you're set up to drive real implementation fastâembedded with the people whose work you're securing, not siloed in a compliance function. As the security function matures, we'll revisit this.
What You'll Do
- Own Tremendous' security posture end-to-end, partnering with our engineering team on production infrastructure and code security.
- Assess where we have gaps, prioritize them, and tackle our highest-leverage gaps first. Weâll have opinions, but you own the prioritization and implementation.
- Treat incident response as core, not afterthought. We may not be able to prevent a breach, but your job is making sure it's small, contained, and that we know exactly what to do.
- Drive security as a cultural shift across the companyâintroducing controls incrementally, working with teams rather than over them. "Yes, and," not "no."
- Lead our AI-security posture. We invest heavily in AI tooling; your job is to manage that risk and enable it, not to ban it.
- Define when and how to staff up the security function, and hire your own team.
- Real, hands-on security experience at a company that scaledâideally as an early security hire who grew with the business through high growth.
- Deep experience in at least one core security domainâproduct/production security, security operations, or access/identity and policyâwith enough range to reason across the others. You defined the security posture, not just executed someone elseâs playbook.
- An engineer's mindset. You reach for code to solve problems and can read our codebase and understand our infrastructure (Ruby on Rails; TypeScript + React; PostgreSQL; Google Cloud). You won't write much day-to-day, but you're not lost in the code.
- Judgment over checklists. You can explain the actual risk of a given decision, hold a firm line where it matters, and give ground where "best practice" doesn't apply to us or real business need pulls the other way. You can hold your own in a debate about whether to open up broad data access for AI tooling.
- Bedside manner. You drive hard change by bringing the team around to your point of view, rather than just telling them no. Engineers and the rest of the company want to work with you.
- Experience building or co-building a small security team is a plus.
- Fintech, payments, or regulated-industry experience is a plus.
- You define the function. First security leader, with the budget for the required tools and team.
- A real mandate. The push for this hire comes straight from the founders.
- We invest in your tools. Everyone has a $5k/month budget for AI tools. Use it.
- Competitive pay and equity. Base salary $250,000â$330,000, plus meaningful equity.
- Fully remote. Work from anywhere in the Americas.
- Great culture. Read more about how we work in our public handbook.
Please mention the word **GOLDEN** and tag RMmEwMjo0NzgwOjI4OmJhMTQ6OjE= when applying to show you read the job post completely (#RMmEwMjo0NzgwOjI4OmJhMTQ6OjE=). This is a beta feature to avoid spam applicants. Companies can search these words to find applicants that read this and see they're human.
Apply for this role Opens jobs.ashbyhq.com — verified as the employer's own application page
Quick question · anonymous · one tap
Would you apply to this job?
Answer to see what other job seekers said.
Your turn · no account needed
Help the next applicant
You may know something about this listing that we cannot see from here. One tap. No account needed. Signed-in reports earn points once the evidence agrees with you.
I know what it pays
Sign in with Google to earn points for reports — 100 confirmed points buy a week of Early Access.
Where this listing came from
- 06 Aug 2026 RemoteOK first sighting
- 09 Sep 2026 Jobicy also listed, 34 days later
Seen on 2 boards over 64 days. The employer edited the description 1× since we first recorded it.