Head of Security

Tremendous

Northern (KY)

Hybrid

USD 250,000 - 330,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

AI tools budget
Equity
Remote work
Competitive compensation

Job summary

Tremendous is seeking its first Head of Security to own the company’s security posture end‑to‑end. You will work closely with engineering on production infrastructure, code security, and incident response, while shaping policy and vendor security.

This is a hands-on leadership role with scope to build the team as needed. You’ll report to the VP of Engineering, partnering across the org to drive security as a core enabler of Tremendous’ growth.

Qualifications

  • Experience leading security at a high-growth tech company.
  • Ability to own and scale security posture end-to-end.
  • Strong judgment on risk vs. best practice in a fast-paced environment.

Responsibilities

  • Own Tremendous’ security posture end-to-end with engineering.
  • Identify gaps, prioritize, and implement high‑leverage security controls.
  • Corral incident response into a repeatable process and drive improvements.
  • Lead a cultural shift toward secure-by-default practices across the company.
  • Define staffing and hire the initial security team as needed.
  • Oversee AI-security posture and tooling while enabling innovation.

Skills

Security leadership
Hands-on security
Incident response
AI security
Risk assessment
Team building

Tools

Ruby on Rails
TypeScript
React
PostgreSQL
Google Cloud

Job description

Tremendous is the global platform built for businesses to send payouts—gift cards and money to anyone, anywhere, instantly. We're trusted by 20,000+ organizations, from startups to giants like Atlassian, MIT, and United Way, to reach millions of recipients worldwide.

We're profitable and growing without outside investors. We're fully remote, with a high-documentation, low-meeting culture that leaves more time for the work that matters—and for your life outside it. Our employee NPS sits in the high 80s.

We move billions of dollars through our systems. That makes security existential, and it's why we're making our first dedicated security hire.

About the role

You’ll be our first Head of Security. There's already a real foundation here—bug bounty, pen tests, automated code and configuration scanning on the production and code side, phishing simulations on the people side. You’ll add to it across access and identity, SecOps and monitoring, incident response, vendor security, employee security practices, and policy. You’ll own the whole posture.

This is a player-coach role. Early on, you’ll do the scoping and the hands‑on work yourself; this is not a role where you direct from above. As the work demands it, we’re fully prepared to build a team here—and we’re looking to you to define what that team should be and when.

You’ll report to the VP of Engineering, Tremendous' most senior technical leader. We've deliberately placed security with Engineering so you're set up to drive real implementation fast—embedded with the people whose work you're securing, not siloed in a compliance function. As the security function matures, we'll revisit this.

What you’ll do
  • Own Tremendous’ security posture end-to-end, partnering with our engineering team on production infrastructure and code security.

  • Assess where we have gaps, prioritize them, and tackle our highest‑leverage gaps first. We'll have opinions, but you own the prioritization and implementation.

  • Treat incident response as core, not afterthought. We may not be able to prevent a breach, but your job is making sure it’s small, contained, and that we know exactly what to do.

  • Drive security as a cultural shift across the company—introducing controls incrementally, working with teams rather than over them. “Yes, and,” not “no.”

  • Lead our AI‑security posture. We invest heavily in AI tooling; your job is to manage that risk and enable it, not to ban it.

  • Define when and how to staff up the security function, and hire your own team.

What you’ll bring
  • Real, hands‑on security experience at a company that scaled—ideally as an early security hire who grew with the business through high growth.

  • Deep experience in at least one core security domain—product/production security, security operations, or access/identity and policy—with enough range to reason across the others. You defined the security posture, not just executed someone else’s playbook.

  • An engineer’s mindset. You reach for code to solve problems and can read our codebase and understand our infrastructure (Ruby on Rails; TypeScript + React; PostgreSQL; Google Cloud). You won’t write much day‑to‑day, but you're not lost in the code.

  • Judgment over checklists. You can explain the actual risk of a given decision, hold a firm line where it matters, and give ground where “best practice” doesn’t apply to us or real business need pulls the other way. You can hold your own in a debate about whether to open up broad data access for AI tooling.

  • Bedside manner. You drive hard change by bringing the team around to your point of view, rather than just telling them no. Engineers and the rest of the company want to work with you.

  • Experience building or co‑building a small security team is a plus.

  • Fintech, payments, or regulated‑industry experience is a plus.

What’s cool about the role
  • You define the function. First security leader, with the budget for the required tools and team.

  • A real mandate. The push for this hire comes straight from the founders.

  • We invest in your tools. Everyone has a $5k/month budget for AI tools. Use it.

  • Competitive pay and equity. Base salary $250,000–$330,000, plus meaningful equity.

  • Fully remote. Work from anywhere in the Americas.

  • Great culture. Read more about how we work in our public handbook.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

First Head of Security - Remote, Fintech & AI Risk
First Head of Security - Remote, Fintech & AI Risk

Tremendous • Northern (KY)

Hybrid
USD 250,000 - 330,000
AI tools budget
Equity
Remote work
+1
Head of Security
Head of Security

Profound • New York (NY)

On-site
USD 300,000 - 375,000
Engineering Manager
Engineering Manager

Tremendous, Inc. • United States

On-site
USD 250,000 - 300,000
Remote work
AI tools budget of $5k/month
Competitive pay and equity
Member of Technical Staff, Head of Security
Member of Technical Staff, Head of Security

Slope • New York (NY)

On-site
USD 300,000 - 375,000
Senior Software Engineer, Security
Senior Software Engineer, Security

Flex • United States

Remote
USD 170,000 - 230,000
Senior Software Engineer, Security
Senior Software Engineer, Security

Flex • Northern (KY)

Hybrid
USD 170,000 - 230,000
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Cogent-Security • United States

On-site
USD 100,000 - 300,000
First Head of Security — Remote, Equity, AI Tools Budget
First Head of Security — Remote, Equity, AI Tools Budget

Tremendous • New York (NY)

On-site
USD 250,000 - 330,000
Budget for tools and team
AI tools budget $5k/month
Equity participation
+1
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Cogent Security • San Francisco (CA)

On-site
USD 100,000 - 300,000
Senior Security Engineer, Platforms & AI
Senior Security Engineer, Platforms & AI

Spinwheel Solutions Inc. • Oakland (CA)

On-site
USD 140,000 - 190,000
Remote-First
Salary & Equity
Unlimited PTO
+2