Job Closed
This listing is no longer active.
Building people software for high growth companies.
Head of Security
Location
California + 2 moreAll locations: California | New York | Washington
Posted
157 days ago
Salary
$250K - $320K / year
Seniority
Lead
Job Description
Head of Security
Ashby
• I’m seeking a knowledgeable, collaborative, and creative leader to scale our security program and build out our security team. • This leader will report directly to me. • You’ll inherit a competent security program and scale this program through our next phase of high growth. • This includes building the Security team from scratch (which means you’ll be a hands-on security generalist to start). • By the end of the year, you’ll have defined our security strategy and roadmap, and added people (1-3 individuals), processes, and automation to scale yourself out of routine work. • Collaborate with other departments to solve interesting security challenges concerning sensitive information and PII. • Lead and grow a culture of security awareness among over 250 people today and more than 500 people by the end of the year.
Job Requirements
- Most importantly, I’m looking for someone who is collaborative and approaches security from a first-principles perspective.
- In past companies, we’ve worked with security teams that blindly follow industry norms and standards, or view their job as reducing risk to zero, both at the expense of velocity and innovation in other departments.
- Instead, you view Security’s goal as identifying risk and collaborating with other departments to determine when it makes sense to mitigate and when it makes sense to compromise.
- You don’t throw problems over the fence; instead, you help steer departments toward the right decision for the business.
- Secondly, I am looking for someone who is capable of building high-quality, scalable processes.
- You should be able to zoom out from hands-on work to realize when you need to shift to building a process or playbook.
- You should also be technically proficient enough to identify opportunities for automation rather than always relying on people to solve the problem.
- Finally, I’m looking for someone who is an excellent communicator.
Benefits
- Competitive salary and equity.
- 10-year exercise window for stock options. You shouldn’t feel pressure to purchase stock options if you leave Ashby —do it when you feel financially comfortable.
- Unlimited PTO.
- A minimum of 12 weeks of fully paid parental leave, covered by Ashby. For folks outside the US, it may be longer to be in line with regional requirements.
- Generous equipment, software, and office furniture budget. Get what you need to be happy and productive!
- $100/month education budget with more expensive items (like conferences) covered with manager approval.
- If you’re in the US, we offer top-tier health insurance for you and your dependents, with 100% of premiums covered by Ashby. In other countries, we provide high-quality supplemental health insurance for you and your dependents, also fully covered by us.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Cloud Security Engineer
UnqorkUsing CaaS (Codeless-as-a-Service) to accelerate time-to-market & eliminate legacy code for the enterprise 🚀
• Multi-Cloud Governance: Monitor and triage security findings across AWS, GCP, and Azure, prioritizing high-risk vulnerabilities and misconfigurations. • Security Automation: Architect and maintain security automation workflows using Python. • Posture Management (CSPM): Identify and remediate insecure cloud configurations (e.g., exposed buckets, overly permissive IAM roles, unencrypted data). • Edge Security: Manage and fine-tune AWS WAF (Web Application Firewall) rules using Terraform (Infrastructure as Code). • Consultative Partnership: Collaborate with Cloud Architects and Developers during the design phase to prevent security debt and ensure "Secure by Design" principles.
Lead Security Architect
Protective LifeWe are on a mission to help more people achieve the sense of protection and security they deserve.
• Define and drive enterprise security architecture across hybrid and cloud environments. • Lead the design, governance, and evolution of secure architectures. • Collaborate with leadership, technology teams, and stakeholders to embed security into IT strategy. • Champion secure-by-design principles through automation and innovation. • Develop and execute the security architecture roadmap aligned with organizational goals. • Create and maintain security documentation, standards, patterns, and reference architectures. • Drive secure-by-design initiatives and develop security standards. • Define, track, and report security metrics to demonstrate security maturity, program effectiveness, and compliance with standards. • Design and oversee implementation of security architecture topologies for systems and enterprise enablement. • Drive DevSecOps adoption and secure CI/CD integration. • Apply strong business acumen to align security initiatives with organizational goals. • Lead threat modeling, risk assessments, and incident response planning for Azure and hybrid systems. • Provide expert guidance on identity and access management (IAM), network segmentation, encryption, and cloud security. • Evaluate, recommend, and select security products and vendors. • Build and maintain strong relationships with technology teams, suppliers, and business units. • Mentor architects and engineers; foster a secure-by-design culture. • Deliver security awareness training and guidance to business and IT teams. • Stay current with emerging threats, technologies, and regulatory changes; recommend innovative solutions.
• Complete technical collections projects including acquisition, monitoring, and analysis of deep and dark web data. • Collect and ingest data from websites by developing scrapers and scripts to work with APIs and databases. • Build, deploy, and maintain tools and services with Docker, Git, and automated pipelines. • Investigate logs to identify and fix code issues, ensuring collection tools can adapt and keep up with an evolving criminal ecosystem. • Employ secure operational tradecraft methods and practices. • Conduct proactive research into underground cybercriminal economies and how threat actors are exploiting or abusing emerging technologies. • Collaborate closely with multiple and various stakeholders of CrowdStrike’s global Counter Adversary Operations team.
• Deploy, manage, and maintain security tools • Develop, monitor, and improve KPIs for security program • Collaborate with cross-functional teams for optimal functionality • Ensure seamless integration of security tools




