> Markdown version of [/jobs/ext/558499-head-of-security-and-compliance](https://www.wearedevelopers.com/jobs/ext/558499-head-of-security-and-compliance). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of Security and Compliance - **Company:** HEN, LLC - **Location:** Livermore, CA, United States - **Experience:** Expert - **Salary:** $225,000.0 - $300,000.0 - **Contract:** Permanent contract - **Skills:** Training Data, Artificial Intelligence, Amazon Web Services, Applications Architecture, Software System Penetration Testing, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Continuous Integration, Information Engineering, Firmware, Github, Identity and Access Management, Intrusion Detection and Prevention, Mobile Application Software, Key Management, Network Planning and Design, Public Key Infrastructure, Systems Development Life Cycle, Web Applications, EndPointSecurity, Data Logging, Data Processing, Google Cloud, Cloud Platform System, Large Language Models, Software Security, Amazon Virtual Private Cloud (VPC), U-Boot, Terraform, IoT Security, Static Application Security Testing - **Published:** June 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6ba224b31bb42e41 ## About the Role Do you have experience in Terraform?, * 12+ years in information security, with at least 4 years leading a security function. * Personally led at least one company through SOC 2 (Type I and Type II) at a similar-stage company - not just "managed compliance at a larger company." * Strong cloud security background, ideally GCP (AWS or Azure depth with willingness to ramp on GCP also works). * Hands-on technical credibility. You can read a Terraform module, review an IAM policy, and have a substantive conversation about TLS configuration. * Engineering directors will respect you because you understand what they do. * Experience embedding security into modern engineering practices: GitHub workflows, CI/CD, IaC, secure SDLC. * Demonstrated experience running vendor risk, incident response, and customer security questionnaire processes. * Excellent written and verbal communication - you will be writing policies, responding to customers, and briefing the leadership, often in the same week., * Direct experience with IoT, embedded, or connected device security (firmware signing, OTA security, device PKI). * Familiarity with AI/ML security and governance: model risk, third-party LLM data handling, prompt injection, edge model integrity. * Public sector or first-responder customer experience: CJIS, HIPAA, NG911, FedRAMP-adjacent procurement. * Relevant certifications (CISSP, CISM, CCSP, GCP Professional Cloud Security Engineer). Certifications alone do not make a candidate; we care about what you have done. * Experience taking a company through ISO 27001 or similar frameworks beyond SOC 2. ## Description We're looking for a hands-on security and compliance leader with a strong SaaS, AI/ML and data oriented application architecture, and experience with IoT systems. This leader will own information security, product security, and compliance across our entire stack - devices, cloud, web, mobile, and AI. You will lead our first SOC 2 audit, build thesecurity program to support Series B due diligence and enterprise fire-department procurement, partner closely with our engineering directors across Cloud/Data, AI/ML, Firmware/IoT, and Hardware, and serve as the executive face of security to customers, investors, and the board., * Security strategy & engineering leadership. Define the security and compliance roadmap aligned with company goals, customer requirements, and the regulatoryenvironment. Build the team over time. * SOC 2 audit (Type I, then Type II). Own the end-to-end SOC 2 program: auditor relationship, compliance tooling (Vanta/Drata or equivalent), policy authoring, control implementation, evidence collection, and remediation. * Cloud security (GCP). Partner with the Head of Cloud and Data engineering to mature GCP security posture: IAM, VPC and network design, KMS, Secret Manager, Security Command Center, Cloud Logging and detection engineering. * Product security across the stack. Embed security into the SDLC for our cloud platform, web app, mobile apps, firmware, and edge AI components. Drive threat modeling, secure design reviews, SAST/SCA/secret scanning, and penetration testing. * IoT and embedded device security. Partner with the Head of Firmware/IoT on device identity and provisioning, secure boot, signed firmware, OTA update security, code-signing key management, and device fleet hygiene. * AI/ML governance. Partner with the Head of AI/ML to establish governance for models, training data, third-party LLM usage, prompt and output handling, and edge inference. Build a defensible AI risk story for customers and investors. * Identity, access & corporate IT security. Own SSO, MFA, least-privilege access, quarterly access reviews, MDM coverage, and endpoint protection across the company. * Vendor and third-party risk. Build and run the vendor risk program. Maintain sub-processor inventory, DPAs, and SOC 2 collection for critical vendors. Review AI/LLM vendor terms for data handling. * Incident response & business continuity. Own the IR plan, BCP and DR plans. Run tabletop exercises and DR tests. Lead response on any material security incident. * Customer trust & enterprise sales support. Be the executive owner of customer security questionnaires, security one-pagers, the trust page, and customer security calls. Support sales on enterprise and fire-department procurements. * Lead security due diligence, and brief the senior leadership on security posture and risk on a regular cadence. * Regulatory readiness. Stay ahead of the regulatory landscape relevant to fire department customers: where applicable, CJIS, HIPAA (for EMS data), state breach notification laws, federal AI executive orders, and emerging IoT security regulation. ## Related Videos - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Agent Smith Gets Hardware: Autonomous IoT Hacking From Debug Port to Cloud API](https://www.wearedevelopers.com/videos/100258-agent-smith-gets-hardware-autonomous-iot-hacking-from-debug-port-to-cloud-api) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)