About the RoleSecurity is now a strategic differentiator for Plenful, and we're building the function from the ground up. As Head of Security, you'll own security across the company - product and application security, cloud infrastructure, corporate security, governance, compliance, and customer trust.
You'll set the strategy, hire the team, and build the processes that let us scale securely without losing the speed of a high-growth startup. You'll partner across Engineering, Product, IT, Legal, and Executive Leadership to embed security into everything we build.
We're looking for a builder - someone who's comfortable in ambiguity, has stood up security programs from zero before, and wants to build an organization that scales with the business.
In your first 12 months, you'll build and execute a company-wide security roadmap, stand up a high-performing security organization, mature our cloud, application, and corporate security capabilities, and strengthen the compliance and customer trust programs that support enterprise growth.
What You'll DoBuild the Security Organization- Define and execute Plenful's long-term security strategy
- Hire, mentor, and lead a high-performing security team
- Establish the organizational structure, operating model, and roadmap for Security
- Build processes that support rapid product development without slowing innovation
- Serve as Plenful's security leader, internally and externally
Product & Application Security- Establish secure software development lifecycle (SSDLC) practices across Engineering
- Integrate security into CI/CD pipelines and developer workflows
- Lead threat modeling, secure architecture reviews, penetration testing, and vulnerability management
- Define security standards for our AI-powered products and ML systems
Cloud & Infrastructure Security- Own cloud security strategy across our AWS infrastructure
- Lead IAM, secrets management, endpoint security, infrastructure hardening, and network security
- Build monitoring, detection, logging, and incident response capabilities
Governance, Risk & Compliance- Lead our security compliance strategy - SOC 2, HIPAA, HITRUST, and what comes next
- Develop company-wide security policies, standards, and governance
- Own vendor risk management and third-party security reviews
- Partner with Legal and Compliance on security and privacy initiatives
Customer Trust & Executive Partnership- Represent Security in enterprise customer security reviews
- Partner with Sales and Customer Success on enterprise deals and due diligence
- Advise executive leadership and the Board on security posture, risk, and investment priorities
- Build a security-first culture through education and partnership
Incident Response- Build and mature Plenful's incident response program
- Lead investigations, postmortems, tabletop exercises, and business continuity planning
- Continuously improve security monitoring and threat detection
You May Be a Fit If- You have 15+ years of progressive experience in cybersecurity, information security, cloud security, or infrastructure security
- You've spent 5+ years leading security organizations at technology companies
- You've built and scaled security programs from the ground up
- You have a strong technical background in modern cloud environments, ideally AWS
- You bring deep expertise in application security, cloud security, IAM, DevSecOps, vulnerability management, and incident response
- You've secured enterprise SaaS platforms
- You have experience with healthcare security and compliance frameworks, including HIPAA and SOC 2
- You've partnered closely with Engineering to build secure development practices
- You communicate exceptionally well - with executives, engineers, customers, and auditors alike
- You have a Bachelor's degree in Computer Science, Cybersecurity, Information Systems, or equivalent practical experience
Bonus points if you:- Have led Security at a startup or high-growth technology company
- Have built organizations through periods of rapid scale
- Have HITRUST certification experience
- Have secured AI/ML platforms and modern data infrastructure
- Have experience with container security, Infrastructure as Code, and cloud-native architectures
- Hold a CISSP, CISM, CCSP, GIAC, or comparable certification
Why You'll Love Working Here- Mission-Driven, World-Class Team - Join an exceptional group of professionals aligned around a meaningful mission and committed to making an impact
- Opportunities for Growth - Strengthen your expertise through collaboration with experienced, high-performing leaders across the organization
- Flexible Hybrid Work Environment - We're remote-first, with meaningful office presence in San Francisco and New York. R&D roles follow a hybrid model, with two days per week in our San Francisco office
Benefits & Perks- Healthcare Coverage - Full medical, dental, and vision insurance for you and participation for your family
- 401(k) with Company Match - Plenful matches 50% of your first 3% contributed
- Equity - Every full-time employee shares in our success
- Unlimited PTO - Take the time you need, when you need it
- Daily Lunch Stipend - $100/week to cover your midday meals
- Wellness Stipend - $100/month to support your health and well-being
- 🚇 Commuter Benefits - $100/month for SF and NYC-based employees
- Parental Leave - Paid leave to support growing families