Head of Security (Cloud, Corporate & Physical)

StudyFetch•Beverly Hills, CA
•$170,000 - $220,000•Onsite

About The Position

We're hiring a Head of Security to protect learners and the organizations that trust us with their people. This role will own security across our cloud, company, physical spaces, and our path into government markets. The Head of Security will also build an AI-native security program, where LLM agents continuously audit code and infrastructure. This is a builder role with a strong foundation already in place, including SOC 2 Type II, ongoing third-party penetration testing, managed EDR, email and DNS filtering, and firewalls. The ideal candidate will own and elevate the security program, lead the company through FedRAMP, and scale the program as the company grows. The role is hands-on, working directly with engineering and leadership. The Head of Security will also collaborate with the IT Engineer, who handles day-to-day IT operations. The Head of Security will set the direction for corporate security and IT, and as the company grows, will build and lead a broader security team.

Requirements

  • 8+ years in security, with hands-on experience across cloud, corporate IT, and compliance.
  • Experience as an early security leader at a startup, building programs from scratch.
  • Experience managing or mentoring IT or security staff.
  • Experience leading or playing a central role in a FedRAMP authorization (Rev5 or 20x).
  • Deep knowledge of NIST 800-53 and ability to map its controls onto a modern cloud stack.
  • Strong cloud security experience, ideally on GCP (AWS or Azure experience is acceptable if able to quickly learn GCP).
  • Experience taking a company through SOC 2 or ISO 27001.
  • Experience running third-party pentest programs and implementing fixes.
  • Experience owning or overseeing physical security systems (badge access, cameras, visitor management).
  • Ability to explain risk to various stakeholders (CEO, customer CISO, federal agency, new hire).

Nice To Haves

  • Hands-on experience with FedRAMP 20x, Key Security Indicators, or automated compliance pipelines.
  • Experience selling into government or higher ed, including GovRAMP or state procurement.
  • Eligibility to work on federal systems, or an active or past clearance.
  • Experience with Vanta, Jamf, Google Cloud, AWS, Cloudflare Zero Trust, and Pulumi or Terraform.

Responsibilities

  • Own the security posture of our Google Cloud environment, including IAM, org policies, network controls, logging, and threat detection.
  • Work with engineering on secure infrastructure-as-code, secrets management, credential rotation, and secure development practices.
  • Lead our third-party penetration testing program, including setting scope and cadence, managing vendors, triaging findings, and driving fixes.
  • Own vulnerability disclosure intake.
  • Help set guardrails for safe AI development and usage, covering data handling, prompt injection, and model and vendor risk.
  • Lead and mentor our IT Engineer, setting priorities, standards, and processes for IT operations.
  • Own identity and access strategy across Google Workspace and our SaaS stack, including SSO, MFA, and role-based access.
  • Own endpoint security and device management standards for our mostly-Mac fleet.
  • Design secure onboarding, offboarding, and quarterly access reviews with IT and People Ops, and automate them where possible.
  • Build security awareness into the company culture.
  • Own office security systems, including access control, cameras, alarms, and visitor management.
  • Set policies for guests, deliveries, asset tracking, and after-hours access.
  • Design and run AI and LLM agent systems for continuous auditing of codebases and infrastructure.
  • Build agentic workflows for triaging alerts, investigating findings, drafting fixes, and collecting compliance evidence.
  • Secure our own AI systems and agents, including permissions, tool access, prompt injection defenses, sandboxing, audit logging, and data handling.
  • Evaluate and adopt AI security tooling.
  • Set guardrails for company-wide AI usage, including approved tools, sensitive data, and model and vendor risk.
  • Own our SOC 2 program end to end, including evidence, policies, vendor risk, and audits.
  • Build one automated, continuously monitored control set for all frameworks.
  • Serve as the security representative with enterprise customers and universities, answering questionnaires and joining sales calls.
  • Navigate student-data and privacy requirements such as FERPA, COPPA, and state privacy laws, along with emerging AI regulation.
  • Lead our FedRAMP program end to end, including strategy, certification class, assessor selection, packaging, and continuous monitoring.
  • Own related frameworks as we expand, such as GovRAMP, NIST 800-53 and 800-171, and ISO 27001.
  • Work with sales and leadership on public-sector deals, agency security reviews, and procurement.
  • Build and own our incident response plan, runbooks, and tabletop exercises.
  • Lead incident response efforts when security incidents occur.

Benefits

  • 170,000–220,000 base salary, plus equity
  • 100% employer-paid Medical, Dental, and Vision
  • 75% dependent coverage for Medical, Dental, and Vision
  • 401(k) with employer matching
  • Daily team dinner provided in-office
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service