Head of Security
Tremendous
New York, New York, New York, United States · Remote · Full Time
Posted
Job description
Tremendous is the global platform built for businesses to send payoutsâgift cards and moneyâto anyone, anywhere, instantly. We're trusted by 20,000+ organizations, from startups to giants like Atlassian, MIT, and United Way, to reach millions of recipients worldwide. We're profitable and growing without outside investors. We're fully remote, with a high-documentation, low-meeting culture that leaves more time for the work that mattersâand for your life outside it. Our employee NPS sits in the high 80s. We move billions of dollars through our systems. That makes security existential, and it's why we're making our first dedicated security hire. About The Role You'll be our first Head of Security. There's already a real foundation hereâbug bounty, pen tests, automated code and configuration scanning on the production and code side, phishing simulations on the people side. Youâll add to it across access and identity, SecOps and monitoring, incident response, vendor security, employee security practices, and policy. You'll own the whole posture. This is a player-coach role. Early on, you'll do the scoping and the hands-on work yourself; this is not a role where you direct from above. As the work demands it, we're fully prepared to build a team hereâand we're looking to you to define what that team should be and when. You'll report to the VP of Engineering , Tremendous' most senior technical leader. We've deliberately placed security with Engineering so you're set up to drive real implementation fastâembedded with the people whose work you're securing, not siloed in a compliance function. As the security function matures, we'll revisit this. What You'll Do Own Tremendous' security posture end-to-end, partnering with our engineering team on production infrastructure and code security. Assess where we have gaps, prioritize them, and tackle our highest-leverage gaps first. Weâll have opinions, but you own the prioritization and implementation. Treat incident response as core, not afterthought. We may not be able to prevent a breach, but your job is making sure it's small, contained, and that we know exactly what to do. Drive security as a cultural shift across the companyâintroducing controls incrementally, working with teams rather than over them. "Yes, and," not "no." Lead our AI-security posture. We invest heavily in AI tooling; your job is to m…