Security Engineer

ONE STOP COLLECTIBLE CORP
New York, NY, United States
1 day ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$300,000.0
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Software as a Service Cloud Computing Security Identity and Access Management Information Technology Operations Information Systems Security Architecture Professional MongoDB Systems Development Life Cycle Search Technologies Security Information and Event Management Software Vulnerability Management
+4 more
Software Security Figma GPT Vulnerability Analysis

Job description

Profound is the marketing platform for the age of AI search. The way brands reach people is being rewritten - AI models like ChatGPT, Perplexity, and Google AI Mode are now the answer layer between companies and their customers. We built the platform marketers use to understand, measure, and win in that world: the analytics, intelligence, and agent automation that turn AI search from a threat into a competitive advantage.

We went from 0 to a $1B valuation in 18 months. Revenue grew 100x last year. Our customers include 15% of the Fortune 500 like Walmart, Wayfair and U.S. Bank, and innovators like Ramp, MongoDB, and Figma. We are backed by Sequoia, Kleiner Perkins, LSVP, and Khosla Ventures - and we are moving fast enough that the people joining now are building the playbook everyone who comes after them will run.

About the Role

As our Head of Security you will build and lead the company’s security program as it scales into a trusted enterprise platform. This is a foundational, high-impact role: you’ll own security strategy end-to-end while staying hands-on, working alongside an existing Security Engineer to mature Profound’s program from “does the right things” to “provably does the right things at enterprise scale.”

You’ll also own IT for the company, making this a role that spans technical security leadership and the practical, day-to-day systems that keep the company running securely.

This is a player-coach role. You should be comfortable setting strategy and talking to enterprise customers’ security teams one day, and rolling up your sleeves on a threat model, an incident, or an endpoint policy the next.

What You’ll Do

Security Strategy & Leadership

  • Own and evolve Profound’s overall security strategy, roadmap, and risk posture as the company scales
  • Own the build-out and growth of the entire security function and team.
  • Serve as the executive-level owner of security in customer conversations, RFPs, and security reviews with enterprise and Fortune 100 prospects and customers
  • Partner closely with Engineering, Product, and Leadership to embed security into the SDLC and product roadmap

Governance, Risk & Compliance

  • Own and mature Profound’s compliance posture (SOC 2 Type II and beyond - e.g. ISO 27001, GDPR, and other frameworks as enterprise customers require)
  • Drive audits, policy development, vendor risk management, and control operations
  • Manage relationships with auditors, pen testers, and security vendors

Technical Security

  • Provide technical direction and oversight for application security, cloud security (AWS/GCP), and infrastructure hardening
  • Own incident response: build the program, run tabletop exercises, and lead the response when needed
  • Guide and review the Security Engineer’s work on detection, vulnerability management, and secure architecture
  • Evaluate and implement security tooling (SIEM, EDR, vulnerability scanning, etc.)

IT

  • Own IT operations for the company: identity and access management (SSO/MDM), endpoint security, employee onboarding/offboarding, SaaS security posture, and internal tooling
  • Set and enforce IT policies that scale with headcount growth without creating unnecessary friction, * Build a security program from the ground up at a company at the center of the shift to AI-driven search
  • High visibility - this role sits close to leadership and directly influences enterprise sales and customer trust
  • A strong Security Engineer already on the team, with a clear mandate to grow the function further
  • Fast-growing, well-funded company (Series C, $1B valuation) with strong momentum

Requirements

  • 8+ years in security, with progressively increasing scope, including experience owning a security program (not just executing within one)
  • Prior experience as a first or early security hire at a high-growth startup, ideally SaaS/B2B, strongly preferred
  • Hands-on technical depth - this is not a purely strategic/managerial role. Comfortable engaging directly on application security, cloud security, and incident response
  • Direct experience owning SOC 2 (Type II) and driving compliance programs; experience with additional frameworks (ISO 27001, GDPR, etc.) a plus
  • Experience leading and developing a small team
  • Comfortable being the face of security to enterprise customers, including technical security reviews and questionnaires
  • Experience owning or partnering closely with IT function preferred
  • Excellent communicator who can translate technical risk into business terms for executives and customers alike

Benefits & conditions

For this role, the expected base salary range is $300,000 to $375,000. Profound’s total compensation package is designed to be competitive and includes base salary, equity, and a full range of benefits and perks. Final compensation will depend on factors such as your skills, experience, qualifications, and location, and will be determined during the interview process. Our recruiting team will share more details about the full compensation package and benefits as you move through hiring.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

40 sec

Generative pre-trained transformer models powering code completions

lgonta lgonta +1 ¡ World Congress 2024

5:04 min

Configuring the Figma MCP for local code generation

Perf + AI

2:01 min

Migrating existing applications from MongoDB to Postgres

Nikita Shamgunov Nikita Shamgunov ¡ World Congress 2024

1:45 min

Transitioning from software development to security roles

Stefania Chaplin ¡ World Congress 2022

51 sec

Assessing GPT-4o performance for pull request feedback

Merrill Lutsky Merrill Lutsky ¡ World Congress 2025

Videos

See all

Related articles

See all