Head of Security (Cloud, Corporate & Physical)

Studyfetch · Beverly Hills, CA

Verified today

In the employer's feed today

“Verified” means one of three checks: the employer’s own careers page, their job feed, or the employer’s own word. The line above says which one, and when.

About Studyfetch

StudyFetch builds AI-native learning products. StudyFetch serves students, and Honen serves workforce training, from universities to Fortune 500 teams. Millions of learners, a growing list of enterprise customers, and soon government agencies trust us with their data, and we take that seriously.



The role

We're hiring a Head of Security, your job will be protecting learners and the organizations that trust us with their people. You'll own security across our cloud, our company, our physical spaces, and our path into government markets. You'll also build an AI-native security program, where LLM agents continuously audit our code and infrastructure alongside you

This is a builder role. We already have a real foundation: SOC 2 Type II, ongoing third-party penetration testing, managed EDR, email and DNS filtering, Firewalls, network security etc. Now we need someone to own it, raise the bar, lead us through FedRAMP, and scale the program as we grow.

You'll be hands-on from day one, working directly with engineering and leadership. You'll also work with our IT Engineer, who handles day-to-day IT: onboarding, offboarding, devices, and employee support. You set the direction, and together you run corporate security and IT. As the company grows, you'll build and lead a broader security team.

What you'll own

Cloud & product security

  • Own the security posture of our Google Cloud environment, including IAM, org policies, network controls, logging, and threat detection.
  • Work with engineering on secure infrastructure-as-code, secrets management, credential rotation, and secure development practices.
  • Lead our third-party penetration testing program. You'll set scope and cadence, manage vendors, triage findings, and drive fixes to completion.
  • Own vulnerability disclosure intake.
  • Help set guardrails for how we build and use AI safely, covering data handling, prompt injection, and model and vendor risk.

Corporate security & IT

  • Lead and mentor our IT Engineer, and set the priorities, standards, and processes for how we run IT.
  • Own identity and access strategy across Google Workspace and our SaaS stack, including SSO, MFA, and role-based access.
  • Own endpoint security and device management standards for our mostly-Mac fleet, with IT handling rollout and day-to-day support.
  • Design secure onboarding, offboarding, and quarterly access reviews with IT and People Ops, and automate them wherever possible.
  • Build security awareness into the culture without slowing people down.

Physical security

  • Own office security systems, including access control, cameras, alarms, and visitor management.
  • Set policies for guests, deliveries, asset tracking, and after-hours access, and make sure front-of-house staff can run them smoothly.

AI-native security

  • Design and run AI and LLM agent systems that continuously audit our codebases and infrastructure. That includes reviewing pull requests, scanning infrastructure-as-code, finding misconfigurations, and flagging risky changes before they ship.
  • Build agentic workflows that triage alerts, investigate findings, draft fixes, and collect compliance evidence automatically.
  • Secure our own AI systems and agents: permissions and tool access, prompt injection defenses, sandboxing, audit logging, and data handling.
  • Evaluate and adopt AI security tooling, and know when a human needs to stay in the loop.
  • Set guardrails for how the whole company uses AI safely, including approved tools, sensitive data, and model and vendor risk.

Compliance & trust

  • Own our SOC 2 program end to end: evidence, policies, vendor risk, and audits.
  • Build one automated, continuously monitored control set that serves every framework we pursue.
  • Be our security voice with enterprise customers and universities, from answering security questionnaires to joining sales calls and building our trust center.
  • Navigate student-data and privacy requirements such as FERPA, COPPA, and state privacy laws, along with emerging AI regulation.

Government & public sector

  • Lead our FedRAMP program end to end: strategy, certification class, assessor selection, packaging, and continuous monitoring.
  • Own related frameworks as we expand, such as GovRAMP for state and local customers, NIST 800-53 and 800-171, and ISO 27001.
  • Work with sales and leadership on public-sector deals, agency security reviews, and procurement.

Incident response

  • Build and own our incident response plan, runbooks, and tabletop exercises.
  • Be the calm, clear lead when something goes wrong.
What you've done
  • 8+ years in security, with real hands-on time across cloud, corporate IT, and compliance. You've touched all of these areas, not just one.
  • You've been an early security leader at a startup and built programs from scratch as the company grew.
  • You've managed or mentored IT or security staff, and you can grow someone's skills while keeping the work moving.
  • You've led or played a central role in a FedRAMP authorization, either Rev5 or 20x, and you know what it takes to get it and keep it.
  • You know NIST 800-53 deeply and can map its controls onto a modern cloud stack.
  • You have strong cloud security experience, ideally on GCP. Deep AWS or Azure experience also works if you can get up to speed on GCP quickly.
  • You've taken a company through SOC 2 or ISO 27001, and you know the difference between real security and checkbox security.
  • You've run third-party pentest programs and turned the findings into shipped fixes.
  • You've owned or overseen physical security systems such as badge access, cameras, and visitor management.
  • You can explain risk to a CEO, a customer's CISO, a federal agency, and a new hire, each in terms that fit.
Nice to have
  • Hands-on experience with FedRAMP 20x, Key Security Indicators, or automated compliance pipelines
  • Experience selling into government or higher ed, including GovRAMP or state procurement
  • Eligibility to work on federal systems, or an active or past clearance
  • Experience with Vanta, Jamf, Google Cloud, AWS,Cloudflare Zero Trust, and Pulumi or Terraform
Why this role
  • You'll build the security function at a fast-growing AI company, with the scope to shape it your way.
  • You'll lead a FedRAMP program from the start, which is rare, career-defining work.
  • You'll lead from day one, with an IT Engineer reporting to you and room to grow the team as we scale.
  • You'll have a direct line to leadership, real ownership, and budgets.
  • The work matters: you'll protect learners and the organizations that trust us with their people.


Compensation & benefits
  • 170,000–220,000 base salary, plus equity
  • 100% employer-paid Medical, Dental, and Vision; 75% dependent coverage
  • 401(k) with employer matching
  • Daily team dinner provided in-office
  • A small, mission-driven team changing how the world learns

#LI-SF1





Listed under Technology & IT jobs.

Similar openings

Browse all jobs →