About The RoleSnorkel is hiring a Head of Security to build and lead our security function end-to-end - infrastructure security, application security, and governance, risk & compliance (GRC). You'll own the security function end-to-end - strategy, team, and execution - and operate as the primary security voice with customers, auditors, and the exec team. You'll report to the CTO.
This is a builder's role: you'll take security from its current state to a mature, right-sized function as Snorkel scales, hiring and developing the team as needs grow.
Key ResponsibilitiesSecurity Leadership & Team Building- Define Snorkel's overall security strategy, goals, and roadmap across infrastructure, application, and compliance domains
- Build, hire, and lead a high-performing security organization - starting lean and scaling deliberately as the company and its risk surface grow
- Establish the operating cadence for security (metrics, reporting, incident response, risk register) and represent security posture to the executive team and board
Infrastructure & Cloud Security- Own cloud security architecture and posture across AWS (and other cloud providers as adopted) - IAM, network segmentation, encryption, landing zone design
- Direct detection & response capabilities, threat modeling, and vulnerability management programs
- Set standards for secure infrastructure-as-code, CI/CD, and secrets management
Application Security- Embed security into the product development lifecycle - secure design reviews, threat modeling for new features, and AI/ML-specific risks (data protection, model/prompt security, training pipeline integrity)
- Partner with Engineering and Product leadership to build security into the SDLC without blocking velocity
- Own application security tooling and practices (SAST/DAST/SCA, pen testing, bug bounty)
- Design identity, access, and activity-monitoring controls that correctly handle Snorkel's non-employee marketplace workforce - external contractor (1099 or similar) experts accessing the platform. This population isn't in scope for standard employee compliance obligations, but provisioning, deprovisioning, access boundaries, and monitoring still need to work correctly for them
Governance, Risk & Compliance (GRC)- Build and run Snorkel's compliance program (e.g., SOC 2, ISO 27001, and customer-driven frameworks) - own audits end-to-end
- Establish enterprise risk management practices: risk register, third-party/vendor risk, policy framework
- Serve as the primary security point of contact for customer security reviews and questionnaires
Executive & Cross-Functional Partnership- Act as a trusted advisor to the CTO and executive team on security risk and investment tradeoffs
- Partner cross-functionally with Legal, Sales, Operations, and Engineering to unblock enterprise deals and support customer trust requirements
- Communicate security posture, incidents, and roadmap clearly to both technical and non-technical audiences
Who You AreExperience & Leadership- 10+ years in technology security, including significant leadership experience; you've held director-level or above scope
- Track record building and scaling a security function from a founding stage (team of ~1) through a mature org (10-30+), ideally at a high-growth technology company
- Experience owning security budget, vendor selection, and board/exec-level reporting
Technical Depth- Deep expertise across infrastructure/cloud security (AWS, IAM, network security, encryption) and application security (SDLC integration, threat modeling, AppSec tooling)
- Hands-on familiarity with modern security tooling: SIEM, EDR, CSPM, vulnerability management
- Experience working with AI/ML-specific security risks (model security, data pipeline protection, prompt injection)
Governance & Compliance- Proven experience building and running compliance programs (SOC 2, ISO 27001, or equivalent) from the ground up
- Comfortable as the face of security to customers during security reviews/audits, and to auditors during certification cycles
General- Bachelor's degree in Computer Science, Information Technology, or related field; advanced degree a plus
- Excellent written and verbal communication; able to flex between board-level summary and engineering-level depth
Why This RoleYou'll have meaningful ownership over the infrastructure that determines how quickly Snorkel can experiment with, evaluate, and productionize new AI systems. This isn't a role focused on training a single model or maintaining traditional ML pipelines - you'll build the platform that makes large-scale AI experimentation possible.
You'll work on some of the hardest emerging infrastructure problems in AI: operating non-deterministic systems reliably, reproducing agent behavior across environments, evaluating long-running trajectories, scaling simulations and experiments, and turning rapidly evolving research workflows into robust production systems.
The architecture decisions made by this team will define how Snorkel builds and operates AI systems for years to come.
Actual compensation will be determined based on factors including skills, qualifications, experience, and geographic location.
Salary range(s) for this role
$252,000-$370,000 USD