SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 300,000 - 375,000 / annual
Profound is a marketing platform built for the AI search era, helping brands understand and win in a world where AI models like ChatGPT and Perplexia are primary customer touchpoints. The company has achieved $1B valuation in 18 months with 100x revenue growth, serving 15% of Fortune 500 companies including Walmart, Wayfair, and U.S. Bank, backed by top-tier VCs including Sequoia and Kleiner Perkins.
As Head of Security, you will build and lead Profound's security program as it scales into a trusted enterprise platform. This is a foundational, high-impact role combining strategic leadership with hands-on technical work. You'll own security strategy end-to-end while working alongside an existing Security Engineer to mature the program from foundational to enterprise-grade. The role also encompasses IT operations, making it a comprehensive security and systems leadership position.
Key responsibilities include: developing and executing overall security strategy and roadmap; building and growing the security team; serving as executive-level security owner in customer conversations, RFPs, and enterprise security reviews; embedding security into the SDLC and product roadmap; maturing compliance posture (SOC 2 Type II, ISO 27001, GDPR); owning incident response programs; providing technical direction on application security, cloud security (AWS/GCP), and infrastructure hardening; and managing IT operations including identity/access management, endpoint security, and employee onboarding/offboarding.
You should have 8+ years in security with progressively increasing scope, including experience owning a security program. Prior experience as a first or early security hire at a high-growth SaaS startup is strongly preferred. This is a player-coach role requiring both strategic thinking and hands-on technical depth in application security, cloud security, and incident response. You'll need direct experience with SOC 2 Type II compliance, ability to lead and develop a small team, comfort being the face of security to enterprise customers, and excellent communication skills translating technical risk into business terms.