Head of Security & Infrastructure

Rise Works•,
•$230,000 - $275,000•Remote

About The Position

Rise is a global payments and payroll platform built for the way modern teams actually work - across borders, currencies, and rails. We make it possible for companies to pay full-time employees, contractors, and freelancers anywhere in the world, in either fiat or digital assets, with the compliance, tax, and identity infrastructure handled underneath. Our stack runs on Google Cloud Platform (Cloud Run, BigQuery, Google SecOps), with MySQL, a Node.js / TypeScript application layer, and Cloudflare (including Cloudflare Pages) at the edge. Settlement for stablecoin payments runs on Ethereum and EVM-compatible networks through our own smart contracts and treasury wallets. Because we move money for real people, security and correctness are first-order concerns in everything we ship.

Requirements

  • Applicants must be legally authorized to work in the United States on a full-time basis and reside in the U.S. The company will not sponsor applicants for work visas for this position.
  • Must pass a comprehensive 7-to-10 year background check, including criminal, credit, and employment verification.
  • 10+ years in security engineering and infrastructure, including at least 3 years owning a security program or function end to end, with the judgment to set direction as Rise's first dedicated security leader.
  • Substantial, hands-on GCP experience - IAM, VPC and networking, Cloud Audit Logs and monitoring, Security Command Center, Secret Manager, Cloud Run, BigQuery, and Google SecOps (Chronicle). This is a GCP role; you should already operate GCP in production.
  • You've built and run detection, triage, and response as a day-to-day discipline in a SIEM (Google SecOps / Chronicle preferred), you can turn logs into signal and signal into alerts people act on, and you've been in the room when something was on fire and helped put it out.
  • You manage cloud infrastructure as code in Terraform and are comfortable owning the modules, state, and pipelines that apply it.
  • You have designed and implemented zero trust access (identity-aware proxies, Cloudflare Access / BeyondCorp-style controls, device posture, context-aware policy) for production and internal systems.
  • IAM and least privilege, secrets/key management, network security, cryptography basics, and data protection.
  • Comfort reading and reasoning about code in a Node.js / TypeScript and MySQL environment (you don't need to be a full-time developer).
  • Hands-on experience owning deployment pipelines and embedding security controls into how we build and ship.
  • Willingness to carry production operations and on-call for a set of VMs and a mostly serverless GCP footprint alongside the security work.
  • You already use AI tools (Claude Code, Copilot, or similar) every day to write and review code, investigate incidents, draft documentation, and automate repetitive work - and you can show how it has multiplied your output. This is how work gets done at Rise; it is not optional.
  • You have carried at least one of SOC 2, ISO 27001, or PCI DSS through certification and recurring audits as the control owner, and know what evidence collection actually costs. Experience taking a company from SOC 2 to ISO 27001 or PCI DSS is a strong plus.

Nice To Haves

  • Google Cloud Professional Cloud Security Engineer, plus any of Professional Cloud Architect, Professional Cloud Network Engineer, or Professional Cloud DevOps Engineer.
  • Wallets, keys, and signers; multisig (Safe) administration; and the threat landscape around stablecoin settlement.
  • Experience in fintech, payments, or another regulated, funds-handling environment.
  • Active or previous U.S. Government security clearance.
  • U.S. military experience, particularly in cybersecurity, signals, or intelligence roles.
  • CISSP, GCIH, GCFA, GCDA, CCSP, or similar.
  • WAF rules, Workers, Zero Trust, and Logpush beyond the basics.

Responsibilities

  • Own and run Rise's security operations: detection engineering, alert triage, investigation, and response across GCP, Cloudflare, GitHub, and Google Workspace.
  • Build and tune detections in Google SecOps (Chronicle) over Cloud Audit Logs, load-balancer and Cloud Run request logs, Cloudflare firewall logs, and application telemetry - covering anomalous traffic, abuse, credential misuse, insider risk, and scanning - and keep log ingestion and feed health reliable.
  • Establish and track behavioral baselines so new or escalated activity stands out from normal operations.
  • Own incident response: detection, containment, forensics, remediation, and blameless post-mortems - and build the tooling and runbooks so we respond faster next time.
  • Run tabletop exercises and game days so our response is proven, not assumed.
  • Build AI-driven security automation: agent-based log review, alert triage and enrichment, and scheduled investigation passes over GCP, Cloudflare, and GitHub activity, so a team of one can cover what used to take a SOC shift.
  • Own Rise's security posture across cloud, edge, data, and on-chain surfaces.
  • Design and enforce a zero trust access model: identity-aware access to production and internal tools, device and context-based policy, no implicit trust based on network location.
  • Own secrets management and access governance: least-privilege IAM, separation of duties, network segmentation, and audit logging as enforced defaults across production systems.
  • Harden the GCP footprint (SecOps, Security Command Center, Cloud Run, IAM, VPC, BigQuery, Secret Manager) and Cloudflare edge configuration (WAF, DNS, rate limiting, bot management).
  • Protect sensitive customer, payroll, and identity data - classification, encryption, retention, and access controls.
  • Own the security of Rise's Ethereum and EVM treasury layer: treasury and ramp wallets, multisig (Safe) owners and thresholds, admin roles on our access-control contracts, and signer and key custody. Smart contract development, auditing, and on-chain monitoring are owned by the blockchain team; you partner with them on controls and custody.
  • Secure the relayer and off-chain services that submit transactions, including key management and transaction signing controls.
  • Own Rise's compliance program: maintain our SOC 2 certification and lead the path to ISO 27001 and PCI DSS - control ownership, evidence collection, gap assessment, and audit coordination - and represent security to auditors, partners, and customers.
  • Own security policy, vendor and third-party risk review, and access review cycles.
  • Run security awareness and secure-development enablement for the engineering team.
  • Own data privacy risk - data residency, subject-access and deletion requests, and GDPR / CCPA obligations across the platform.
  • Own the infrastructure operations behind code releases: run and improve the deployment pipelines that ship our fleet of Cloud Run services to production, and be accountable for safe, repeatable releases (rollouts, rollbacks, and release hygiene).
  • Provide day-to-day operational support for our production infrastructure - keeping services healthy and available, responding to operational issues, and doing the maintenance, upgrades, and toil-reduction that keep the platform running.
  • Build and maintain CI/CD and Terraform-managed infrastructure on GCP, with security controls built into the pipeline rather than bolted on.
  • Improve observability - logging, metrics, tracing, and alerting - so we find problems before customers do.
  • Be accountable for reliability - capacity, backups, and on-call - for systems that move money, on a mostly serverless architecture designed to keep operational load and toil low.
  • Operate and continuously improve our disaster recovery capability. Own our RTO/RPO targets, manage database backup and point-in-time recovery for our managed MySQL databases, maintain and refine failover procedures and DR runbooks, and run regular restore drills and game days so recovery stays proven, not assumed.
  • Keep the infrastructure upgraded over time.

Benefits

  • Base salary: $230,000-$275,000, commensurate with experience.
  • Meaningful equity in a growing company.
  • Generous healthcare benefits - medical, dental, and vision coverage for you and your family.
  • Unlimited PTO and a flexible work schedule - we care about outcomes, not hours.
  • 401(k) with a 3% company grant - not a match. Rise contributes 3% of your salary to your 401(k) every pay period whether or not you contribute a dollar yourself. Add your own contributions on top and you keep both.
  • Fully remote within the United States.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service