Tremendous
Head of Security
Remote role where the employee must remain based in a particular country.
United States only
Employer listed it 7 weeks ago · Added 4 days ago
Been open since 7 weeks ago. Long-running listings are sometimes left up after the role is filled.
Salary
$250,000–$330,000
Location
United States only
Timezone
US East
Contract
Full-time
Experience
Lead
Category
Software
Published by the employer
Remote flexibility
Work from home
This is a remote role, but the employee must be based in United States. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "United States, Remote"
- Job description states: "Work from anywhere in the Americas."
What Nomaders makes of it
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Tremendous is the global platform built for businesses to send payouts—gift cards and money—to anyone, anywhere, instantly. We're trusted by 20,000+ organizations, from startups to giants like Atlassian, MIT, and United Way, to reach millions of recipients worldwide.
We're profitable and growing without outside investors. We're fully remote, with a high-documentation, low-meeting culture that leaves more time for the work that matters—and for your life outside it. Our employee NPS sits in the high 80s.
We move billions of dollars through our systems. That makes security existential, and it's why we're making our first dedicated security hire.
About the role
You'll be our first Head of Security. There's already a real foundation here—bug bounty, pen tests, automated code and configuration scanning on the production and code side, phishing simulations on the people side. You’ll add to it across access and identity, SecOps and monitoring, incident response, vendor security, employee security practices, and policy. You'll own the whole posture.
This is a player-coach role. Early on, you'll do the scoping and the hands-on work yourself; this is not a role where you direct from above. As the work demands it, we're fully prepared to build a team here—and we're looking to you to define what that team should be and when.
You'll report to the VP of Engineering , Tremendous' most senior technical leader. We've deliberately placed security with Engineering so you're set up to drive real implementation fast—embedded with the people whose work you're securing, not siloed in a compliance function. As the security function matures, we'll revisit this.
What you'll do
Own Tremendous' security posture end-to-end, partnering with our engineering team on production infrastructure and code security.
Assess where we have gaps, prioritize them, and tackle our highest-leverage gaps first. We’ll have opinions, but you own the prioritization and implementation.
Treat incident response as core, not afterthought. We may not be able to prevent a breach, but your job is making sure it's small, contained, and that we know exactly what to do.
Drive security as a cultural shift across the company—introducing controls incrementally, working with teams rather than over them. "Yes, and," not "no."
Lead our AI-security posture. We invest heavily in AI tooling; your job is to manage that risk and enable it, not to ban it.
Define when and how to staff up the security function, and hire your own team.
What you'll bring
Real, hands-on security experience at a company that scaled—ideally as an early security hire who grew with the business through high growth.
Deep experience in at least one core security domain—product/production security, security operations, or access/identity and policy—with enough range to reason across the others. You defined the security posture, not just executed someone else’s playbook.
An engineer's mindset. You reach for code to solve problems and can read our codebase and understand our infrastructure (Ruby on Rails; TypeScript + React; PostgreSQL; Google Cloud). You won't write much day-to-day, but you're not lost in the code.
Judgment over checklists. You can explain the actual risk of a given decision, hold a firm line where it matters, and give ground where "best practice" doesn't apply to us or real business need pulls the other way. You can hold your own in a debate about whether to open up broad data access for AI tooling.
Bedside manner. You drive hard change by bringing the team around to your point of view, rather than just telling them no. Engineers and the rest of the company want to work with you.
Experience building or co-building a small security team is a plus.
Fintech, payments, or regulated-industry experience is a plus.
What's cool about the role
You define the function. First security leader, with the budget for the required tools and team.
Requirements
- ·Real, hands-on security experience at a company that scaled—ideally as an early security hire who grew with the business through high growth.
- ·Bedside manner. You drive hard change by bringing the team around to your point of view, rather than just telling them no. Engineers and the rest of the company want to work with you.
- ·Experience building or co-building a small security team is a plus.
- ·Fintech, payments, or regulated-industry experience is a plus.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Tremendous, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 5d ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$250,000–$330,000 · You'll be taken to the employer's careers page.