Head of Security; Cloud, Corporate & Physical
Listed on 2026-09-27
-
IT/Tech
Cybersecurity
Head of Security (Cloud, Corporate & Physical)
Studyfetch Beverly Hills, California, United States
About this positionAbout Studyfetch
Study Fetch builds AI-native learning products. Study Fetch serves students, and Honen serves workforce training, from universities to Fortune 500 teams. Millions of learners, a growing list of enterprise customers, and soon government agencies trust us with their data, and we take that seriously.
The roleWe're hiring a Head of Security, your job will be protecting learners and the organizations that trust us with their people. You'll own security across our cloud, our company, our physical spaces, and our path into government markets. You'll also build an AI-native security program, where LLM agents continuously audit our code and infrastructure alongside you
This is a builder role. We already have a real foundation: SOC 2 Type II, ongoing third-party penetration testing, managed EDR, email and DNS filtering, Firewalls, network security etc. Now we need someone to own it, raise the bar, lead us through FedRAMP, and scale the program as we grow.
You'll be hands-on from day one, working directly with engineering and leadership. You'll also work with our IT Engineer, who handles day-to-day IT: onboarding, offboarding, devices, and employee support. You set the direction, and together you run corporate security and IT. As the company grows, you'll build and lead a broader security team.
What you'll ownCloud & product security
- Own the security posture of our Google Cloud environment, including IAM, org policies, network controls, logging, and threat detection.
- Work with engineering on secure infrastructure-as-code, secrets management, credential rotation, and secure development practices.
- Lead our third-party penetration testing program. You'll set scope and cadence, manage vendors, triage findings, and drive fixes to completion.
- Own vulnerability disclosure intake.
- Help set guardrails for how we build and use AI safely, covering data handling, prompt injection, and model and vendor risk.
Corporate security & IT
- Lead and mentor our IT Engineer, and set the priorities, standards, and processes for how we run IT.
- Own identity and access strategy across Google Workspace and our SaaS stack, including SSO, MFA, and role-based access.
- Own endpoint security and device management standards for our mostly-Mac fleet, with IT handling rollout and day-to-day support.
- Design secure onboarding, offboarding, and quarterly access reviews with IT and People Ops, and automate them wherever possible.
- Build security awareness into the culture without slowing people down.
Physical security
- Own office security systems, including access control, cameras, alarms, and visitor management.
- Set policies for guests, deliveries, asset tracking, and after-hours access, and make sure front-of-house staff can run them smoothly.
AI-native security
- Design and run AI and LLM agent systems that continuously audit our codebases and infrastructure. That includes reviewing pull requests, scanning infrastructure-as-code, finding misconfigurations, and flagging risky changes before they ship.
- Build agentic workflows that triage alerts, investigate findings, draft fixes, and collect compliance evidence automatically.
- Secure our own AI systems and agents: permissions and tool access, prompt injection defenses, sandboxing, audit logging, and data handling.
- Evaluate and adopt AI security tooling, and know when a human needs to stay in the loop.
- Set guardrails for how the whole company uses AI safely, including approved tools, sensitive data, and model and vendor risk.
Compliance & trust
- Own our SOC 2 program end to end: evidence, policies, vendor risk, and audits.
- Build one automated, continuously monitored control set that…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).