
Head of Privacy & Security
Posted Jul 16

Posted Jul 16
This is a fully remote position, open to applicants in United States.
• Oversee our security and privacy initiatives to safeguard the students, educators, and partners utilizing the platform.
• Propel the security engineering, compliance, and privacy programs with comprehensive accountability for risk management and customer assurance.
• Foster effective and thoughtful decision-making to minimize uncertainty and enhance organizational efficiency.
• Establish SIEM and detection engineering pipelines to promptly alert and investigate anomalies before they escalate into incidents.
• Standardize and enforce Role-Based Access Control (RBAC) on critical systems, encompassing non-human and AI agent identities.
• Implement LLM-assisted and highly contextual code analysis for security-sensitive pull requests, addressing tenant isolation and prompt injection vulnerabilities.
• Develop data de-identification and isolation strategies for privacy-by-design scenarios.
• Maintain an updated risk register and security roadmap, ensuring clear communication through regular updates.
• Assist the engineering team with secure design reviews that offer actionable and informed tradeoff recommendations.
• Provide customer-facing teams with high-quality trust center materials, including security knowledge bases and customer assurance resources.
• Oversee SOC 2 compliance operations and audits to minimize the burden on engineering and support teams.
• Direct the incident response function to guarantee swift recovery capabilities.
• Collaborate with Trust and Safety on child safety and responsible AI implementations.
• Work collaboratively across functions to forge partnerships rather than obstacles.
• 7+ years of experience in security roles, including a minimum of 3 years in leadership positions.
• Proven track record in implementing security controls within fast-paced engineering organizations, demonstrating the ability to balance security with speed.
• Documented experience in projects addressing AppSec challenges and integrating with software development (DevSecOps).
• Expertise in securing container-based cloud environments (Playlab operates on AWS EKS), including Identity and Access Management (IAM), virtual network security, and logging and auditing functions.
• Experience in leading GDPR compliance and SOC 2 audits.
• Exceptional writing and communication skills, capable of distilling complex problems into actionable consensus.
• Bonus Points For...
• Experience in education data privacy (e.g., FERPA, COPPA).
• Background in defending systems against AI threats (e.g., prompt injection).
• Experience working in nonprofit or mission-driven organizations.
• Flexible work arrangements.
• Competitive salary and benefits.
• Comprehensive package including salary, healthcare, retirement, generous paid time off, and opportunities for professional development.
GuidePoint Security
Redpanda Data
CyberSheath
Akamai Technologies
Get handpicked remote jobs straight to your inbox weekly.