Nous Research
Head of Security
Remote work allowed only within certain countries or regions.
North America
Employer listed it 6 weeks ago · Added 5 days ago
Been open since 6 weeks ago, still being checked, but it has been live a while.
Salary
Not stated
Location
North America
Timezone
US East
Contract
Full-time
Experience
Lead
Category
Software
This employer didn't state pay. Jobs like this usually pay around $200k–$275k a year, a typical range taken from 597 lead-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Region Restricted
Remote work is allowed, but only for candidates based in North America.
What the employer says
- Source listing states candidate location: "Americas (US time zones), Remote"
What Nomaders makes of it
- Applications outside the listed area are usually rejected
- Timezone overlap with the listed area is often expected
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
The Role
As the first Security hire at Nous Research, you'll build and own security end-to-end across our infrastructure, products, and enterprise deployments. Nous builds open-source AI language models and agents, including Hermes Agent, which is used by consumers and Fortune 500 enterprises across multi-tenant SaaS, dedicated VPC, self-hosted, and air-gapped environments.
This is a hands-on-keyboard role for someone who wants to harden multi-cloud infrastructure, secure a novel agentic AI platform, and build the security foundation regulated enterprise customers demand. You'll be the person focused full-time on protecting the company while helping the rest of the team continue shipping quickly.
Responsibilities
Own production security across a multi-cloud footprint spanning AWS, GCP, Azure, and Vercel.
Secure multi-tenant SaaS, dedicated VPC, self-hosted Kubernetes, and air-gapped deployments.
Secure the Hermes Agent platform across sandboxing, kernel-level file system and network isolation, agent identity, credential controls, egress controls, and trace integrity.
Own SOC 2 technical controls, evidence collection, remediation, and ongoing readiness.
Harden identity and access management, including SSO and SAML consolidation, least-privilege access reviews, 2FA, and BYOD policies.
Lead vulnerability management, penetration testing, incident response, and cloud-native security monitoring.
Strengthen the secure software development lifecycle through practical controls, including peer-review requirements, while maintaining high development velocity.
Support enterprise deals by completing security questionnaires, leading architecture reviews, and addressing penetration-testing requirements.
Partner across engineering, infrastructure, product, FDE, and operations to identify and address security risks.
Qualifications
8+ years of security engineering experience, with deep hands-on expertise in infrastructure and multi-cloud security.
Track record securing production SaaS environments and owning security end-to-end at a fast-growing technology company.
Strong Kubernetes, identity, and IAM fundamentals, including familiarity with enterprise SSO, SAML, and SCIM.
Experience implementing compliance-driven engineering programs such as SOC 2 or ISO 27001 without allowing them to become checkbox exercises.
Strong understanding of vulnerability management, incident response, access controls, penetration testing, and secure software development practices.
Interest in securing agentic AI systems and addressing emerging risks across agent identity, tool permissions, prompt injection, and data provenance.
Ability to work effectively in a high-velocity, open-source-native engineering culture.
Security-minded by default and pragmatic in practice, with strong judgment around balancing protection and development speed.
Nice-to-Have
Experience supporting regulated customers, financial services organizations, or air-gapped deployments.
Requirements
- ·8+ years of security engineering experience, with deep hands-on expertise in infrastructure and multi-cloud security.
- ·Track record securing production SaaS environments and owning security end-to-end at a fast-growing technology company.
- ·Strong Kubernetes, identity, and IAM fundamentals, including familiarity with enterprise SSO, SAML, and SCIM.
- ·Experience implementing compliance-driven engineering programs such as SOC 2 or ISO 27001 without allowing them to become checkbox exercises.
- ·Strong understanding of vulnerability management, incident response, access controls, penetration testing, and secure software development practices.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, region restricted, matches where you plan to live and work.
- 2Tailor your CV to the role at Nous Research, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $200k to $275k per year · You'll be taken to the employer's careers page.