Head of Security (Cloud, Corporate & Physical)

StudyFetch•Beverly Hills, CA
•Onsite

About The Position

We're hiring a Head of Security to protect learners and the organizations that trust us with their people. This role involves owning security across our cloud, company, physical spaces, and government market entry. A key aspect is building an AI-native security program, utilizing LLM agents for continuous auditing of code and infrastructure. This is a builder role, starting with an existing foundation of SOC 2 Type II, third-party penetration testing, managed EDR, email and DNS filtering, and firewalls. The Head of Security will own and elevate this foundation, lead the company through FedRAMP certification, and scale the security program. The role requires hands-on work with engineering and leadership, and collaboration with the IT Engineer who manages day-to-day IT operations. As the company grows, the Head of Security will build and lead a broader security team.

Requirements

  • 8+ years in security, with hands-on experience across cloud, corporate IT, and compliance.
  • Experience as an early security leader at a startup, building programs from scratch.
  • Experience managing or mentoring IT or security staff.
  • Experience leading or playing a central role in a FedRAMP authorization (Rev5 or 20x).
  • Deep knowledge of NIST 800-53 and ability to map controls to a modern cloud stack.
  • Strong cloud security experience, ideally on GCP (AWS or Azure experience is acceptable if able to quickly learn GCP).
  • Experience taking a company through SOC 2 or ISO 27001.
  • Experience running third-party pentest programs and implementing fixes.
  • Experience owning or overseeing physical security systems (badge access, cameras, visitor management).
  • Ability to explain risk to diverse audiences (CEO, CISO, federal agency, new hire).

Nice To Haves

  • Hands-on experience with FedRAMP 20x, Key Security Indicators, or automated compliance pipelines.
  • Experience selling into government or higher education, including GovRAMP or state procurement.
  • Eligibility to work on federal systems, or an active or past clearance.
  • Experience with Vanta, Jamf, Google Cloud, AWS, Cloudflare Zero Trust, and Pulumi or Terraform.

Responsibilities

  • Own the security posture of our Google Cloud environment, including IAM, org policies, network controls, logging, and threat detection.
  • Work with engineering on secure infrastructure-as-code, secrets management, credential rotation, and secure development practices.
  • Lead our third-party penetration testing program, including setting scope and cadence, managing vendors, triaging findings, and driving fixes.
  • Own vulnerability disclosure intake.
  • Help set guardrails for safe AI development and usage, covering data handling, prompt injection, and model/vendor risk.
  • Lead and mentor the IT Engineer, setting priorities, standards, and processes for IT operations.
  • Own identity and access strategy across Google Workspace and our SaaS stack, including SSO, MFA, and role-based access.
  • Own endpoint security and device management standards for our Mac fleet.
  • Design and automate secure onboarding, offboarding, and quarterly access reviews with IT and People Ops.
  • Build security awareness into the company culture.
  • Own office security systems, including access control, cameras, alarms, and visitor management.
  • Set policies for guests, deliveries, asset tracking, and after-hours access.
  • Design and run AI and LLM agent systems for continuous auditing of codebases and infrastructure.
  • Build agentic workflows for alert triage, investigation, fix drafting, and compliance evidence collection.
  • Secure our own AI systems and agents: permissions, tool access, prompt injection defenses, sandboxing, audit logging, and data handling.
  • Evaluate and adopt AI security tooling.
  • Set company-wide guardrails for safe AI usage.
  • Own our SOC 2 program end-to-end: evidence, policies, vendor risk, and audits.
  • Build an automated, continuously monitored control set for compliance frameworks.
  • Serve as the security representative for enterprise customers and universities.
  • Navigate student data and privacy requirements (FERPA, COPPA, state privacy laws) and emerging AI regulation.
  • Lead our FedRAMP program end-to-end: strategy, certification class, assessor selection, packaging, and continuous monitoring.
  • Own related frameworks like GovRAMP, NIST 800-53, NIST 800-171, and ISO 27001.
  • Work with sales and leadership on public-sector deals, agency security reviews, and procurement.
  • Build and own our incident response plan, runbooks, and tabletop exercises.
  • Lead incident response efforts.

Benefits

  • 100% employer-paid Medical, Dental, and Vision; 75% dependent coverage
  • 401(k) with employer matching
  • Daily team dinner provided in-office
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service