What that looks like day to day
We built a new security team from scratch this year. We’re now three people, and we’re looking for our final two. We’re generalists at heart, but for these roles we want people who can primarily focus on Governance, Risk and Compliance (GRC) or cloud security.
The work is greenfield and you’ll be deciding how security gets done at incident from first principles, not inheriting someone else’s process. There’s very little process here today which means you can move quickly rather than fight your way through approval chains. You’ll have real autonomy over how you approach the work.
The engineers you’ll be working with are excellent, and they’ve already dealt with the easy problems. What’s left for you is the genuinely hard stuff, the kind of work that’s interesting precisely because it hasn’t been solved yet. The role is a bit of a security buffet, but we want generalists who can primarily focus on either GRC or cloud security.
We think of security as something that helps the business move, not something that slows it down. That means saying yes wherever we genuinely can, while still having the authority to block a release when something matters enough.
We’re heavy adopters of AI, and this role sits right in the middle of that. You’ll have an unlimited Claude token budget to speed up your own work, review, testing, threat modelling, and you’ll also be responsible for securing the AI features and AI driven workflows we’re shipping into the product.