Head of Security

Ashby•San Francisco, CA
1d

About The Position

Hi 👋🏾, I’m Abhik , Ashby’s Co-Founder and VP of Engineering. I’m seeking a knowledgeable, collaborative, and creative leader to scale our security program and build out our security team. Hopefully, you fit the bill! As our Head of Security, you won’t have to build from scratch. You’ll inherit a reasonably competent security program that I developed, and then our former Head of Security & IT improved. Instead, you’ll scale this program and team through our next phase of high growth. I think it’s important to share a bit about the broader company as context for this role. Ashby builds powerful and easy-to-use recruiting software that replaces several venture-backed companies' worth of products (often with a better experience). We have notable customers like Notion, Linear, Shopify, and Snowflake. Our growth and retention metrics are best-in-class among our peers: we have tens of millions in ARR, thousands of customers (including Enterprise customers), growing >120% year over year, very low churn, and many years of runway. As a result, Ashby manages a significant amount of sensitive information and PII on behalf of candidates and customers (from candidate addresses to offer details to company calendars), and the volume and types of sensitive data are only increasing as we expand the product. This presents interesting security challenges that you’ll lead and collaborate with other departments to solve. Your first challenge will be building out our security team and scaling our security program. There’s no team today, but we’ve added many automations (e.g., one-click offboarding) and services (e.g., SecurityPal) to help. We also collaborate with other departments (e.g., Support triages security@) to manage a good portion of routine Security work. That being said, you’ll still need to be a hands-on security generalist to start. By the end of the year, you’ll have added people (1-3 individuals), processes, and automation to scale yourself out of more of the routine work. Some other examples of challenges you’ll work on: LLMs and AI products are powerful technologies, and new startups today have an advantage in utilizing these technologies because they have higher risk tolerance. Despite our scale, we must continue to adopt new technologies at a similar pace, but with the right security and privacy controls in place to match our maturity. You’ll help us navigate that with our IT and leadership teams by building policies, processes, and systems for departments to adopt at startup speed. LLMs and AI also pose challenges for the recruiting industry, including mass bot applications and fraudulent candidates. You’ll lend your expertise to our Product teams to help them build counters in our product (example here ). You’ll also work with our customers and the broader industry to help them build strategies in their own processes (example here ). As we move into people workflows and capture more sensitive data, we’ll need to address the additional risk that brings, but, at the same time, not hinder our ability to provide excellent support to our customers. You’ll partner with Engineering, IT, and Customer Support to develop tools, integrations, and safeguards that enable us to practice least privilege through smart automations rather than slow, manual approvals.

Requirements

  • Most importantly, I’m looking for someone who is collaborative and approaches security from a first-principles perspective. In past companies, we’ve worked with security teams that blindly follow industry norms and standards, or view their job as reducing risk to zero, both at the expense of velocity and innovation in other departments. Instead, you view Security’s goal as identifying risk and collaborating with other departments to determine when it makes sense to mitigate and when it makes sense to compromise. You help us make the right decision for the business – even if that means sometimes taking a risk that might be initially uncomfortable for you.
  • Secondly, I am looking for someone who builds high-quality, scalable processes. You should be able to zoom out from hands-on work to realize when you need to shift to building a process or playbook. You should also be technically proficient enough to identify opportunities for automation, rather than always relying on people to solve problems, and either build these automations yourself or with our IT and Engineering teams.
  • Finally, I’m looking for someone who is an excellent communicator both externally and internally. Customers need to feel confident that their data is secure with Ashby. You achieve this not just by keeping Ashby secure, but also by addressing common concerns and questions through empathetic and thorough documentation , and, for our larger customers, one-on-one meetings with their Security team. Internally, the policies, processes, and influence you have within the organization affect over 250 people today and more than 500 people by the end of the year. Your words matter, and you use them effectively to navigate opinions and situations, communicate Security priorities, and build a strong security awareness within the team.
  • The types of background we're looking for include candidates who have been the Head of Security at a startup, built a security program from the ground up, and overseen a security program at scale.

Nice To Haves

  • An exceptional candidate would be someone with a background in Engineering, but it’s not required for the role.

Benefits

  • Competitive salary and equity.
  • 10-year exercise window for stock options.
  • Unlimited PTO.
  • A minimum of 12 weeks of fully paid parental leave, covered by Ashby. For folks outside the US, it may be longer to be in line with regional requirements.
  • Generous equipment, software, and office furniture budget. Get what you need to be happy and productive!
  • $100/month education budget with more expensive items (like conferences) covered with manager approval.
  • If you’re in the US, we offer top-tier health insurance for you and your dependents, with 100% of premiums covered by Ashby. In other countries, we provide high-quality supplemental health insurance for you and your dependents, also fully covered by us.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service