- Own the security function's day-to-day execution.
- Reduce the company's exposure to high-blast-radius security risk, AI agent architecture, and application security.
- Build a mature, auditable, and scalable security program (policy, controls, evidence, reporting) ahead of compliance and customer-trust demands.
- Lead and grow a Security team, providing the people management the function has lacked.
- Serve as the primary technical authority and incident commander for security events.
- Represent Information Security credibly to executives, auditors, customers, and partners.
- Own the AppSec and vulnerability management program (Snyk and adjacent tooling), including pack ownership, CI/CD security gating, and repository risk classification processes.
- Drive vulnerability remediation SLAs and hold engineering accountable to them.
- Continuously mature the program from reactive scanning toward proactive, gated prevention.
- Act as an incident commander for security incidents, including coordinating cross-functional response, containment, and communication.
- Own the bug bounty and continuous penetration testing disclosure program: triage, validation, remediation tracking, and researcher communication.
- Facilitate post-incident reviews and root-cause analysis, with particular attention to recurring architectural risk patterns.
- Ensure remediation of systemic issues, not just point fixes and elevate platform-level fixes when the same root cause recurs across incidents.
- Own security architecture review for new systems, platforms, and AI agent deployments, including AI agent identity and access patterns (eg, cross-app access, delegated identity).
- Maintain security standards for cloud infrastructure, endpoint protection, and network/edge security.
- Partner with IT Operations on identity-related risk (entitlement sprawl, contractor and non-employee access, and access governance) providing the security requirements and risk lens that IT Operations executes against.
- Own the security policy library, risk register, and control framework; keep them current and audit-ready.
- Lead internal and external audits and assessments, coordinating evidence collection across IT, Engineering, and Legal.
- Report program maturity, open risk, and remediation progress to executive leadership on a regular cadence.
- Oversee processes to update and maintain the Enterprise Security Risk Register.
- Partner with the Chief AI Officer on the security dimensions of AI governance, including enforcement of AI acceptable-use policy and identification of security risk in new AI tooling and agent deployments.
- Provide the security review and risk sign-off for new AI platforms, agents, and integrations prior to broad rollout.
- Own vendor and third-party security risk assessment for new tools, integrations, and contractors.
- Maintain a defensible, repeatable process for evaluating vendor security posture before onboarding.
- Own company-wide security awareness programming, phishing simulation, and targeted training following incidents or audit findings.
- Build blameless, clear communications that raise the organization's security literacy without creating fear or confusion.
- Hire, coach, and develop the Security Engineering team.
- Set team priorities, run performance management, and build a growth path for security engineers.
- Establish team operating rhythm: on-call/incident rotation, backlog grooming, and technical review standards.
- Own the security content in recurring executive reporting.
- Represent Information Security in cross-functional forums (Legal, AI governance, IT Operations, Engineering leadership).
- Escalate material risk, resourcing gaps, or unresolved cross-functional blockers promptly and clearly.
Required Qualifications
- 7+ years in information security, including meaningful experience in application security, incident response, and security architecture.
- Demonstrated experience running vulnerability management programs at scale (eg, Snyk or comparable tooling).
- Direct incident command experience, including coordinating cross-functional response to significant security events.
- People management experience, ideally building or scaling a security engineering team.
- Working knowledge of cloud security, identity and access management concepts, and modern AI/agent architecture risk.
- Strong written and verbal communication skills, including comfort presenting to executive audiences.
- Experience with bug bounty/responsible disclosure program management.
- Experience building or maturing a GRC program, including audit and compliance framework experience (SOC 2, ISO 27001).
- Familiarity with AI agent security risk, including MCP-style tool/agent architectures and identity delegation patterns.
- Experience partnering with AI governance or data governance functions.
- Relevant certifications (CISSP, CISM, or equivalent).
- Incident command and crisis leadership
- Security architecture and risk assessment
- Program and process maturity building
- People leadership and coaching
- Executive communication
- Cross-functional influence without direct authority over partner teams
- Judgment under ambiguity and time pressure
- Equity: We offer full-time employees equity in Fetch, so that everyone can benefit from Fetch’s growth.
- 401k Match: Dollar-for-dollar match up to 4%.
- Benefits for humans and pets: We offer comprehensive medical, dental and vision plans for everyone including your pets.
- Continuing Education: Fetch provides ten thousand per year in education reimbursement.
- Employee Resource Groups: Take part in employee-led groups that are centered around fostering a diverse and inclusive workplace through events, dialogue and advocacy. The ERGs participate in our Inclusion Council with members of executive leadership.
- Paid Time Off: On top of our flexible PTO, Fetch observes 9 paid holidays, as well as our year-end week-long break.
- Robust Leave Policies: 20 weeks of paid parental leave for primary caregivers, 14 weeks for secondary caregivers, and a flexible return to work schedule.
- Calvin Care Cash: Employees who are welcoming new family members will also receive a one time $2,000 incentive to assist employees with covering the cost of childcare, clothing, diapers and much more!
- Flexible Work Environment: Collaborate with your team in one of our stunning offices, or you can work fully remotely from anywhere in the US. We’ll ensure you are equally equipped with the hardware and software you need to get your job done in the comfort of your home. (applicable for most roles)
Skills Required
- 7+ years of experience in information security
- Meaningful experience in application security, incident response, and security architecture
- Experience running vulnerability management programs at scale using Snyk or comparable tooling
- Direct incident command experience coordinating cross-functional response to significant security events
- People management experience, ideally building or scaling a security engineering team
- Working knowledge of cloud security, identity and access management, and modern AI or agent architecture risk
- Strong written and verbal communication skills, including executive presentations
- Bug bounty or responsible disclosure program management experience
- Experience building or maturing a GRC program, including SOC 2 or ISO 27001 audit and compliance experience
- Familiarity with AI agent security risk, MCP-style tool or agent architectures, and identity delegation patterns
- Experience partnering with AI governance or data governance functions
- CISSP, CISM, or equivalent certification
Fetch Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Fetch and has not been reviewed or approved by Fetch.
-
Healthcare Strength — Benefits information points to comprehensive medical, dental, vision, and life insurance coverage. Feedback suggests employees value the strong health offerings alongside mental-health support.
-
Leave & Time Off Breadth — Policies include flexible or unlimited PTO, paid holidays and sick days, bereavement (including pet) and natural-disaster leave. Feedback suggests time-off breadth is a standout element of the package.
-
Wellbeing & Lifestyle Benefits — Wellness programs, 1:1 coaching, Gympass, team workouts, and nutrition counseling are provided. Office and remote perks such as home-office stipends, snacks, and pet-friendly spaces further enhance lifestyle support.
Fetch Insights
What We Do
Fetch Rewards is a mobile app that connects and rewards everyday shoppers for buying the brands they love. Fetch gives users the easiest way to save on their purchases by simply scanning any grocery receipt, from any store. For our brand partners, Fetch helps them build long-term loyalty, and understand a true 360 degree view of purchase behavior.
Why Work With Us
We put people first - both in our culture, and in our product. Our culture is built on transparency, empowerment and accountability. Our product is built on putting our customers first in everything we do - from design, to privacy and security, to new features. The result is the rapid growth we all dream of being a part of. Come join the team!
Gallery








