[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![Tremendous logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/01/c2bd8be5-221.jpeg)](https://jobicy.com/company/tremendous.md)Remote opportunity at[Tremendous](https://jobicy.com/company/tremendous.md)

# Head of Security

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/tremendous.md)Share9 Sep 2026Published48Listing views1Application actions9 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryTremendous is hiring its first dedicated Head of Security to own the company’s security posture for a global payments platform. This hands-on player-coach leader will prioritize and implement security improvements across product and infrastructure security, identity and access, SecOps, incident response, vendor risk, employee practices, and AI-security governance. The role partners closely with Engineering, reports to the VP of Engineering, and will define the future security team and hiring plan. Success requires practical security leadership at a scaling organization, technical fluency with cloud and application stacks, strong risk judgment, and the ability to drive adoption through collaboration.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a first security-leader role at a high-growth payments company moving billions of dollars, with broad ownership and substantial operational risk. The hire must personally execute early priorities while establishing a scalable program, influencing engineering and company-wide behavior, and preparing to build a team.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive$290,000US market range$250k–$330k0$363k

AI insightThe disclosed US yearly base-salary range is $250,000 to $330,000, with a midpoint of $290,000. This is consistent with the seniority, first-security-leader scope, fintech/payment risk profile, and broad technical and organizational ownership of a Head of Security role; equity is additional and not included in the cash figures.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Security leadership](https://jobicy.com/jobs?search_keywords=Security%20leadership.md)[Application security](https://jobicy.com/jobs?search_keywords=Application%20security.md)[Cloud security](https://jobicy.com/jobs?search_keywords=Cloud%20security.md)[Google Cloud Platform](https://jobicy.com/jobs?search_keywords=Google%20Cloud%20Platform.md)[Incident response](https://jobicy.com/jobs?search_keywords=Incident%20response.md)[Identity and access management](https://jobicy.com/jobs?search_keywords=Identity%20and%20access%20management.md)[Security operations](https://jobicy.com/jobs?search_keywords=Security%20operations.md)[Vendor risk management](https://jobicy.com/jobs?search_keywords=Vendor%20risk%20management.md)[AI security governance](https://jobicy.com/jobs?search_keywords=AI%20security%20governance.md)[Fintech security](https://jobicy.com/jobs?search_keywords=Fintech%20security.md)

Sample interview questionsHow would you approach your first 90 days as Tremendous’s first Head of Security?I would first establish a fact-based view of the current posture by reviewing architecture, access patterns, production controls, incident processes, vulnerability-management outputs, vendor dependencies, and existing testing results. I would then publish a prioritized risk roadmap that balances exploitability, business impact, engineering effort, and regulatory or customer commitments. Early delivery would focus on a small number of high-confidence controls and an exercised incident-response process, while creating a longer-term staffing and tooling plan.

How do you balance security requirements with the need for engineering teams to ship quickly?

I frame security as risk management rather than checklist enforcement. I work with teams to understand the product and delivery constraint, propose the least-friction control that meaningfully reduces risk, and clearly document any accepted risk and its owner. This builds trust while preserving firm escalation boundaries for material risks such as privileged-access exposure, sensitive-data leakage, or inadequate incident containment.

Describe how you would strengthen incident response for a payments platform.

I would define severity levels, ownership, escalation paths, communications templates, evidence-handling practices, and recovery decision criteria. I would validate that telemetry, alerting, access logs, and critical system runbooks support fast investigation and containment. Finally, I would run tabletop exercises and targeted technical simulations, then convert findings into tracked engineering and operational improvements.

What is your approach to AI-security governance without blocking useful tooling?

I would inventory approved AI use cases, identify what data may be shared, assess vendors and model configurations, and establish proportional guardrails for sensitive information, access, logging, and human review. The goal is to give employees approved paths for productive use rather than drive usage into unmanaged tools. Governance should be iterated with Engineering, Legal, and business teams as both the technology and risks evolve.

How would you decide when to hire additional security team members?

I would use the security roadmap, operational load, risk concentration, and required depth of expertise to identify where a single leader is becoming a bottleneck. Initial hires should address the highest-leverage persistent need, such as product security, security engineering, or detection and response, rather than mirror a generic organizational chart. I would define clear outcomes, ownership boundaries, and a hiring sequence tied to business growth and measurable risk reduction.

Tremendous is the global platform built for businesses to send payouts—gift cards and money—to anyone, anywhere, instantly. We’re trusted by 20,000+ organizations, from startups to giants like Atlassian, MIT, and United Way, to reach millions of recipients worldwide.

We’re profitable and growing without outside investors. We’re fully remote, with a high-documentation, low-meeting culture that leaves more time for the work that matters—and for your life outside it. Our employee NPS sits in the high 80s.

We move billions of dollars through our systems. That makes security existential, and it’s why we’re making our first dedicated security hire.

### About the role

You’ll be our first Head of Security. There’s already a real foundation here—bug bounty, pen tests, automated code and configuration scanning on the production and code side, phishing simulations on the people side. You’ll add to it across access and identity, SecOps and monitoring, incident response, vendor security, employee security practices, and policy. You’ll own the whole posture.

This is a player-coach role. Early on, you’ll do the scoping and the hands-on work yourself; this is not a role where you direct from above. As the work demands it, we’re fully prepared to build a team here—and we’re looking to you to define what that team should be and when.

You’ll report to [the VP of Engineering](https://www.linkedin.com/in/magnusvk/), Tremendous’ most senior technical leader. We’ve deliberately placed security with Engineering so you’re set up to drive real implementation fast—embedded with the people whose work you’re securing, not siloed in a compliance function. As the security function matures, we’ll revisit this.

### What you’ll do

*

Own Tremendous’ security posture end-to-end, partnering with our engineering team on production infrastructure and code security.

*

Assess where we have gaps, prioritize them, and tackle our highest-leverage gaps first. We’ll have opinions, but you own the prioritization and implementation.

*

Treat incident response as core, not afterthought. We may not be able to prevent a breach, but your job is making sure it’s small, contained, and that we know exactly what to do.

*

Drive security as a cultural shift across the company—introducing controls incrementally, working with teams rather than over them. “Yes, and,” not “no.”

*

Lead our AI-security posture. We invest heavily in AI tooling; your job is to manage that risk and enable it, not to ban it.

*

Define when and how to staff up the security function, and hire your own team.

### What you’ll bring

*

Real, hands-on security experience at a company that scaled—ideally as an early security hire who grew with the business through high growth.

*

Deep experience in at least one core security domain—product/production security, security operations, or access/identity and policy—with enough range to reason across the others. You defined the security posture, not just executed someone else’s playbook.

*

An engineer’s mindset. You reach for code to solve problems and can read our codebase and understand our infrastructure (Ruby on Rails; TypeScript + React; PostgreSQL; Google Cloud). You won’t write much day-to-day, but you’re not lost in the code.

*

Judgment over checklists. You can explain the actual risk of a given decision, hold a firm line where it matters, and give ground where “best practice” doesn’t apply to us or real business need pulls the other way. You can hold your own in a debate about whether to open up broad data access for AI tooling.

*

Bedside manner. You drive hard change by bringing the team around to your point of view, rather than just telling them no. Engineers and the rest of the company want to work with you.

*

Experience building or co-building a small security team is a plus.

*

Fintech, payments, or regulated-industry experience is a plus.

### What’s cool about the role

*

You define the function. First security leader, with the budget for the required tools and team.

*

A real mandate. The push for this hire comes straight from the founders.

*

We invest in your tools. Everyone has a $5k/month budget for AI tools. Use it.

*

Competitive pay and equity. Base salary $250,000–$330,000, plus meaningful equity.

*

Fully remote. Work from anywhere in the Americas.

*

Great culture. Read more about how we work in [our public handbook](https://handbook.tremendous.com/).

Show more

[Apply now >](https://jobicy.com/jobs/152862-head-of-security.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Nebius logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/d90c0566-221.webp)
Nebius  Sep 9

### [Detection Engineering & Response Lead](https://jobicy.com/jobs/148918-detection-engineering-response-lead.md)

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from…

*
![Databricks logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/12/4e3f864ba9cf3c62d471e1c62414d098.jpg)
Databricks  Sep 7

### [Cyber Security GTM Leader](https://jobicy.com/jobs/152703-cyber-security-gtm-leader.md)

SLSQ327R408 As the Cybersecurity Go-to-market (GTM) Leader, you will drive the global GTM strategy and execution of the Cybersecurity business at Databricks. You will play a pivotal role in accelerating…

*
![Tenable logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/01879e02-221.jpg)
Tenable  Sep 6

### [Senior Security Consultant](https://jobicy.com/jobs/152673-senior-security-consultant.md)

Who is Tenable? Tenable® is the Exposure Management company. Over 40,000 organizations around the globe rely on Tenable to understand and reduce cyber risk. Our global employees support 65 percent…

*
![Tenable logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/01879e02-221.jpg)
Tenable  Sep 6

### [Security Sales Engineer – SLED/Public Sector](https://jobicy.com/jobs/152668-security-sales-engineer-sled-public-sector.md)

Who is Tenable? Tenable® is the Exposure Management company. Over 40,000 organizations around the globe rely on Tenable to understand and reduce cyber risk. Our global employees support 65 percent…

*
![Tenable logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/01879e02-221.jpg)
Tenable  Sep 6

### [Principal Solutions Architect (AWS Technical Alliances)](https://jobicy.com/jobs/152664-principal-solutions-architect-aws-technical-alliances.md)

Who is Tenable? Tenable® is the Exposure Management company. Over 40,000 organizations around the globe rely on Tenable to understand and reduce cyber risk. Our global employees support 65 percent…

*
![Upside logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/06e64944-221.png)
Upside  Sep 6

### [Staff Application Security Engineer](https://jobicy.com/jobs/152657-staff-application-security-engineer.md)

Meet Upside: We created Upside to transform brick-and-mortar commerce. Our technology uses the sophistication of online retail—profit measurement, attribution, and incrementality—to provide users with more value on their everyday purchases…

*
![Smartsheet logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8b6103bd-221.jpg)
Smartsheet  Sep 6

### [Senior Security Engineer I, Customer Trust EMEA (Remote Eligible in the UK)](https://jobicy.com/jobs/150221-senior-security-engineer-i-customer-trust-emea-remote-eligible-in-the-uk.md)

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI…

*
![HackerOne logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8937d355-221.png)
HackerOne  Sep 4

### [Senior Director, Community](https://jobicy.com/jobs/152527-senior-director-community.md)

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to…

*
![HackerOne logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8937d355-221.png)
HackerOne  Sep 4

### [Product Security Analyst](https://jobicy.com/jobs/152523-product-security-analyst.md)

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to…

*
![HackerOne logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8937d355-221.png)
HackerOne  Sep 4

### [Senior Security Engineer, Detection and Response](https://jobicy.com/jobs/152514-senior-security-engineer-detection-and-response.md)

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to…