SlipstreamJobsFresh Startup & VC-Backed Jobs

Head of Security

Snorkel AI - San Francisco, CA, United States - Hybrid - posted 2026-09-15

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 252,000 - 370,000 / annual

Snorkel AI is hiring a Head of Security to build and lead the security function end-to-end across infrastructure security, application security, and governance, risk & compliance (GRC). You will own the security strategy, team, and execution, serving as the primary security voice with customers, auditors, and the executive team. You will report to the CTO. This is a builder's role: you will take security from its current state to a mature, right-sized function as Snorkel scales, hiring and developing the team as needs grow. Key Responsibilities: Security Leadership & Team Building: Define Snorkel's overall security strategy, goals, and roadmap across infrastructure, application, and compliance domains. Build, hire, and lead a high-performing security organization—starting lean and scaling deliberately as the company and its risk surface grow. Establish the operating cadence for security (metrics, reporting, incident response, risk register) and represent security posture to the executive team and board. Infrastructure & Cloud Security: Own cloud security architecture and posture across AWS and other cloud providers—IAM, network segmentation, encryption, landing zone design. Direct detection & response capabilities, threat modeling, and vulnerability management programs. Set standards for secure infrastructure-as-code, CI/CD, and secrets management. Application Security: Embed security into the product development lifecycle—secure design reviews, threat modeling for new features, and AI/ML-specific risks (data protection, model/prompt security, training pipeline integrity). Partner with Engineering and Product leadership to build security into the SDLC without blocking velocity. Own application security tooling and practices (SAST/DAST/SCA, pen testing, bug bounty). Design identity, access, and activity-monitoring controls that correctly handle Snorkel's non-employee marketplace workforce—external contractor experts accessing the platform. Governance, Risk & Compliance (GRC): Build and run Snorkel's compliance program (SOC 2, ISO 27001, and customer-driven frameworks)—own audits end-to-end. Establish enterprise risk management practices: risk register, third-party/vendor risk, policy framework. Serve as the primary security point of contact for customer security reviews and questionnaires. Executive & Cross-Functional Partnership: Act as a trusted advisor to the CTO and executive team on security risk and investment tradeoffs. Partner cross-functionally with Legal, Sales, Operations, and Engineering to unblock enterprise deals and support customer trust requirements. Communicate security posture, incidents, and roadmap clearly to both technical and non-technical audiences. About Snorkel: Snorkel AI is the frontier AI data lab, helping teams build the data and environments behind high-performing frontier and agentic AI. Founded out of the Stanford AI Lab in 2019, Snorkel works with leading AI labs and enterprises to move from better data to better outcomes. Requirements: - 10+ years in technology security, including significant leadership experience; director-level or above scope - Track record building and scaling a security function from founding stage (team of ~1) through mature org (10–30+), ideally at a high-growth technology company - Experience owning security budget, vendor selection, and board/exec-level reporting - Deep expertise across infrastructure/cloud security (AWS, IAM, network security, encryption) and application security (SDLC integration, threat modeling, AppSec tooling) - Hands-on familiarity with modern security tooling: SIEM, EDR, CSPM, vulnerability management - Experience working with AI/ML-specific security risks (model security, data pipeline protection, prompt injection) - Proven experience building and running compliance programs (SOC 2, ISO 27001, or equivalent) from the ground up - Comfortable as the face of security to customers during security reviews/audits, and to auditors during certification cycles - Bachelor's degree in Computer Science, Information Technology, or related field; advanced degree a plus - Excellent written and verbal communication; able to flex between board-level summary and engineering-level depth

Similar roles