Head of Security

Profound

$300K — $375K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in security with experience owning a security program
  • Experience as a first or early security hire at a high-growth startup, preferably SaaS/B2B
  • Hands-on technical expertise in application security, cloud security, and incident response
  • Direct experience with SOC 2 (Type II) compliance and additional frameworks like ISO 27001, GDPR
  • Proven experience in leading and developing a small team
  • Exceptional communication skills for translating technical risk to business terms

Responsibilities

  • Own and evolve the security strategy, roadmap, and risk posture as the company scales
  • Build and grow the entire security function and team
  • Serve as the executive owner of security in customer interactions
  • Partner with Engineering, Product, and Leadership to integrate security into the SDLC
  • Mature the compliance posture with SOC 2 Type II and beyond
  • Manage audits, policy development, and vendor risk relationships
  • Lead incident response and guide the Security Engineer's work on security practices

Benefits

  • Build a security program from the ground up in a cutting-edge AI-driven environment
  • Access to high visibility and influence within the leadership and sales teams
  • Collaboration with an existing Security Engineer, providing foundational support
  • Opportunity at a fast-growing, well-funded company with a Series C valuation of $1B
Full Job Description
EPDD
• New York, New York
• In-office

Apply

Refer someone

Apply

Refer someone

About the Role

As our Head of Security you will build and lead the company's security program as it scales into a trusted enterprise platform. This is a foundational, high-impact role: you'll own security strategy end-to-end while staying hands-on, working alongside an existing Security Engineer to mature Profound's program from "does the right things" to "provably does the right things at enterprise scale."

You'll also own IT for the company, making this a role that spans technical security leadership and the practical, day-to-day systems that keep the company running securely.

This is a player-coach role. You should be comfortable setting strategy and talking to enterprise customers' security teams one day, and rolling up your sleeves on a threat model, an incident, or an endpoint policy the next.

What You'll Do

Security Strategy & Leadership
  • Own and evolve Profound's overall security strategy, roadmap, and risk posture as the company scales
  • Own the build-out and growth of the entire security function and team.
  • Serve as the executive-level owner of security in customer conversations, RFPs, and security reviews with enterprise and Fortune 100 prospects and customers
  • Partner closely with Engineering, Product, and Leadership to embed security into the SDLC and product roadmap

Governance, Risk & Compliance
  • Own and mature Profound's compliance posture (SOC 2 Type II and beyond - e.g. ISO 27001, GDPR, and other frameworks as enterprise customers require)
  • Drive audits, policy development, vendor risk management, and control operations
  • Manage relationships with auditors, pen testers, and security vendors

Technical Security
  • Provide technical direction and oversight for application security, cloud security (AWS/GCP), and infrastructure hardening
  • Own incident response: build the program, run tabletop exercises, and lead the response when needed
  • Guide and review the Security Engineer's work on detection, vulnerability management, and secure architecture
  • Evaluate and implement security tooling (SIEM, EDR, vulnerability scanning, etc.)

IT
  • Own IT operations for the company: identity and access management (SSO/MDM), endpoint security, employee onboarding/offboarding, SaaS security posture, and internal tooling
  • Set and enforce IT policies that scale with headcount growth without creating unnecessary friction

What We're Looking For
  • 8+ years in security, with progressively increasing scope, including experience owning a security program (not just executing within one)
  • Prior experience as a first or early security hire at a high-growth startup, ideally SaaS/B2B, strongly preferred
  • Hands-on technical depth - this is not a purely strategic/managerial role. Comfortable engaging directly on application security, cloud security, and incident response
  • Direct experience owning SOC 2 (Type II) and driving compliance programs; experience with additional frameworks (ISO 27001, GDPR, etc.) a plus
  • Experience leading and developing a small team
  • Comfortable being the face of security to enterprise customers, including technical security reviews and questionnaires
  • Experience owning or partnering closely with IT function preferred
  • Excellent communicator who can translate technical risk into business terms for executives and customers alike

Why This Role
  • Build a security program from the ground up at a company at the center of the shift to AI-driven search
  • High visibility - this role sits close to leadership and directly influences enterprise sales and customer trust
  • A strong Security Engineer already on the team, with a clear mandate to grow the function further
  • Fast-growing, well-funded company (Series C, $1B valuation) with strong momentum

Location

This is an on-site role based in our Union Square, NYC office, designed for builders who thrive on speed, iteration, and meaningful impact.

For this role, the expected base salary range is $300,000 to $375,000. Profound's total compensation package is designed to be competitive and includes base salary, equity, and a full range of benefits and perks. Final compensation will depend on factors such as your skills, experience, qualifications, and location, and will be determined during the interview process. Our recruiting team will share more details about the full compensation package and benefits as you move through hiring.

Note: All official communication from Profound will come from a @tryprofound.com email address. If you're contacted by anyone using a different domain, please disregard and report it as spam.

#LI-PRO

Note: All official communication from Profound will come from a @tryprofound.com email address. If you're contacted by anyone using a different domain, please disregard and report it as spam.

Similar Jobs

More Jobs at Profound

  • AI Strategist, Business
    $100K — $170K *
    New York, NY 10025 (New York County)
    Business Services
    In-Person
  • Tech Lead Manager, Context
    $230K — $275K *
    San Francisco, CA 94112 (San Francisco County)
    Enterprise Technology
    In-Person
  • Analytics Engineer
    $180K — $260K *
    New York, NY 10025 (New York County)
    Enterprise Technology
    In-Person
  • Head of Talent
    $250K — $325K *
    New York, NY 10025 (New York County)
    Staffing
    In-Person
  • Marketing Strategy & Planning Manager
    $140K — $190K *
    New York, NY 10025 (New York County)
    Consumer Technology
    In-Person

More Information Technology Jobs

Find similar Head of Security jobs: