Head of Security & Infrastructure

Posted Yesterday
Be an Early Applicant
Hiring Remotely in United States
Remote
230K-275K Annually
Expert/Leader
Fintech • HR Tech • Payments • Cryptocurrency
The Role
Owns company-wide security operations, cloud and infrastructure security, incident response, zero-trust architecture, blockchain treasury controls, compliance, privacy, production reliability, Terraform, CI/CD, observability, disaster recovery, and on-call operations. This hands-on leadership role reports to the CTO, represents the company to auditors and customers, and builds security automation across GCP, Cloudflare, GitHub, Google Workspace, and Ethereum infrastructure.
Summary Generated by Built In
Head of Security & Infrastructure

Location: Remote - United States only (must reside in the U.S.)

Team: Security & Infrastructure

Reports to: CTO (you'll work directly with the CTO)

About Rise

Rise is a global payments and payroll platform built for the way modern teams actually work - across borders, currencies, and rails. We make it possible for companies to pay full-time employees, contractors, and freelancers anywhere in the world, in either fiat or digital assets, with the compliance, tax, and identity infrastructure handled underneath.

Our stack runs on Google Cloud Platform (Cloud Run, BigQuery, Google SecOps), with MySQL, a Node.js / TypeScript application layer, and Cloudflare (including Cloudflare Pages) at the edge. Settlement for stablecoin payments runs on Ethereum and EVM-compatible networks through our own smart contracts and treasury wallets. Because we move money for real people, security and correctness are first-order concerns in everything we ship.

Our Culture

We're a lean, high-trust, high-ownership team. Because we move real money for real people, we hold a high bar for correctness, security, and accountability - the work is meaningful precisely because the stakes are real. We value:

  • Ownership over hand-offs. You'll own security and infrastructure end to end and have the autonomy that comes with that.

  • Security as a default, not a phase. Handling funds and personal data means security thinking is part of every decision, not a box checked at the end.

  • Directness and low ego. We give and receive candid feedback, write things down, and prefer clarity over politics.

  • AI-first in how work gets done. We use AI agents and assistants as a core part of daily work - writing and reviewing code and Terraform, triaging alerts, investigating logs, drafting runbooks and policies, and automating the toil that would otherwise eat the day. We expect everyone to work this way and to keep getting better at it.

  • Remote-first discipline. We're a globally distributed team spread across time zones around the world, and we communicate asynchronously with a bias toward documentation and reproducibility.

What You'll Do

Working directly with the CTO, you'll own security across Rise's cloud, edge, and on-chain surfaces, and the infrastructure operations that keep production healthy. You are the first dedicated security role at Rise, but you are not starting from zero: you inherit a working program - SOC 2 certification, Google SecOps, Terraform-managed GCP, Cloudflare at the edge, and established on-chain treasury controls - and your job is to own it, harden it, and take it further. Security is the center of gravity for the role, with infrastructure and reliability close behind, on a mostly serverless stack designed to keep operational overhead low.

This is a hands-on leadership role. You will not manage people, but you are the security leader for the company: you set security direction, make the calls on risk, represent Rise to auditors, partners, and customers, and are the person engineering and leadership turn to when a security or infrastructure question needs an answer. It is a builder's seat, not an advisory one - you'll harden what exists, design what's missing, and ship it yourself.

Security operations (SecOps)

  • Own and run Rise's security operations: detection engineering, alert triage, investigation, and response across GCP, Cloudflare, GitHub, and Google Workspace.

  • Build and tune detections in Google SecOps (Chronicle) over Cloud Audit Logs, load-balancer and Cloud Run request logs, Cloudflare firewall logs, and application telemetry - covering anomalous traffic, abuse, credential misuse, insider risk, and scanning - and keep log ingestion and feed health reliable.

  • Establish and track behavioral baselines so new or escalated activity stands out from normal operations.

  • Own incident response: detection, containment, forensics, remediation, and blameless post-mortems - and build the tooling and runbooks so we respond faster next time.

  • Run tabletop exercises and game days so our response is proven, not assumed.

  • Build AI-driven security automation: agent-based log review, alert triage and enrichment, and scheduled investigation passes over GCP, Cloudflare, and GitHub activity, so a team of one can cover what used to take a SOC shift.

Security posture & architecture

  • Own Rise's security posture across cloud, edge, data, and on-chain surfaces.

  • Design and enforce a zero trust access model: identity-aware access to production and internal tools, device and context-based policy, no implicit trust based on network location.

  • Own secrets management and access governance: least-privilege IAM, separation of duties, network segmentation, and audit logging as enforced defaults across production systems.

  • Harden the GCP footprint (SecOps, Security Command Center, Cloud Run, IAM, VPC, BigQuery, Secret Manager) and Cloudflare edge configuration (WAF, DNS, rate limiting, bot management).

  • Protect sensitive customer, payroll, and identity data - classification, encryption, retention, and access controls.

Blockchain & treasury security

  • Own the security of Rise's Ethereum and EVM treasury layer: treasury and ramp wallets, multisig (Safe) owners and thresholds, admin roles on our access-control contracts, and signer and key custody. Smart contract development, auditing, and on-chain monitoring are owned by the blockchain team; you partner with them on controls and custody.

  • Secure the relayer and off-chain services that submit transactions, including key management and transaction signing controls.

Governance, risk & compliance

  • Own Rise's compliance program: maintain our SOC 2 certification and lead the path to ISO 27001 and PCI DSS - control ownership, evidence collection, gap assessment, and audit coordination - and represent security to auditors, partners, and customers.

  • Own security policy, vendor and third-party risk review, and access review cycles.

  • Run security awareness and secure-development enablement for the engineering team.

  • Own data privacy risk - data residency, subject-access and deletion requests, and GDPR / CCPA obligations across the platform.

Infrastructure operations & platform reliability

  • Own the infrastructure operations behind code releases: run and improve the deployment pipelines that ship our fleet of Cloud Run services to production, and be accountable for safe, repeatable releases (rollouts, rollbacks, and release hygiene).

  • Provide day-to-day operational support for our production infrastructure - keeping services healthy and available, responding to operational issues, and doing the maintenance, upgrades, and toil-reduction that keep the platform running.

  • Build and maintain CI/CD and Terraform-managed infrastructure on GCP, with security controls built into the pipeline rather than bolted on.

  • Improve observability - logging, metrics, tracing, and alerting - so we find problems before customers do.

  • Be accountable for reliability - capacity, backups, and on-call - for systems that move money, on a mostly serverless architecture designed to keep operational load and toil low.

  • Operate and continuously improve our disaster recovery capability. Own our RTO/RPO targets, manage database backup and point-in-time recovery for our managed MySQL databases, maintain and refine failover procedures and DR runbooks, and run regular restore drills and game days so recovery stays proven, not assumed.

  • Keep the infrastructure upgraded over time.

What We're Looking For

Required

  • Work authorization. Applicants must be legally authorized to work in the United States on a full-time basis and reside in the U.S. The company will not sponsor applicants for work visas for this position.

  • Background check. Must pass a comprehensive 7-to-10 year background check, including criminal, credit, and employment verification.

  • Experience. 10+ years in security engineering and infrastructure, including at least 3 years owning a security program or function end to end, with the judgment to set direction as Rise's first dedicated security leader.

  • Google Cloud Platform. Substantial, hands-on GCP experience - IAM, VPC and networking, Cloud Audit Logs and monitoring, Security Command Center, Secret Manager, Cloud Run, BigQuery, and Google SecOps (Chronicle). This is a GCP role; you should already operate GCP in production.

  • Security operations and incident response. You've built and run detection, triage, and response as a day-to-day discipline in a SIEM (Google SecOps / Chronicle preferred), you can turn logs into signal and signal into alerts people act on, and you've been in the room when something was on fire and helped put it out.

  • Terraform. You manage cloud infrastructure as code in Terraform and are comfortable owning the modules, state, and pipelines that apply it.

  • Zero trust. You have designed and implemented zero trust access (identity-aware proxies, Cloudflare Access / BeyondCorp-style controls, device posture, context-aware policy) for production and internal systems.

  • Security fundamentals. IAM and least privilege, secrets/key management, network security, cryptography basics, and data protection.

  • Code literacy. Comfort reading and reasoning about code in a Node.js / TypeScript and MySQL environment (you don't need to be a full-time developer).

  • CI/CD. Hands-on experience owning deployment pipelines and embedding security controls into how we build and ship.

  • Production operations. Willingness to carry production operations and on-call for a small set of VMs and a mostly serverless GCP footprint alongside the security work.

  • AI-first workflow. You already use AI tools (Claude Code, Copilot, or similar) every day to write and review code, investigate incidents, draft documentation, and automate repetitive work - and you can show how it has multiplied your output. This is how work gets done at Rise; it is not optional.

  • Compliance. You have carried at least one of SOC 2, ISO 27001, or PCI DSS through certification and recurring audits as the control owner, and know what evidence collection actually costs. Experience taking a company from SOC 2 to ISO 27001 or PCI DSS is a strong plus.

Preferred

  • Google Cloud certifications. Google Cloud Professional Cloud Security Engineer, plus any of Professional Cloud Architect, Professional Cloud Network Engineer, or Professional Cloud DevOps Engineer.

  • Ethereum / EVM security. Wallets, keys, and signers; multisig (Safe) administration; and the threat landscape around stablecoin settlement.

  • Regulated industry. Experience in fintech, payments, or another regulated, funds-handling environment.

Nice to have

  • Security clearance. Active or previous U.S. Government security clearance.

  • Military service. U.S. military experience, particularly in cybersecurity, signals, or intelligence roles.

  • Additional certifications. CISSP, GCIH, GCFA, GCDA, CCSP, or similar.

  • Cloudflare depth. WAF rules, Workers, Zero Trust, and Logpush beyond the basics.

Compensation & Benefits
  • Base salary: $230,000-$275,000, commensurate with experience.

  • Meaningful equity in a growing company.

  • Generous healthcare benefits - medical, dental, and vision coverage for you and your family.

  • Unlimited PTO and a flexible work schedule - we care about outcomes, not hours.

  • 401(k) with a 3% company grant - not a match. Rise contributes 3% of your salary to your 401(k) every pay period whether or not you contribute a dollar yourself. Add your own contributions on top and you keep both.

  • Fully remote within the United States.

Why Rise

You'll be the person who owns security operations and reliability for a platform that moves real money across borders and on-chain. It's a role with genuine scope, genuine autonomy, and genuine stakes - GCP security, SecOps, blockchain treasury security, compliance, and production ownership, all in one seat, with a direct line to the CTO.

You'll be the first dedicated security leader at Rise, inheriting a real program and the full authority to shape where it goes next.

Skills Required

  • Legally authorized to work full-time in the United States and reside in the U.S.
  • Pass a comprehensive 7-to-10 year background check, including criminal, credit, and employment verification.
  • 10+ years of experience in security engineering and infrastructure.
  • At least 3 years owning a security program or function end to end.
  • Substantial hands-on production experience with Google Cloud Platform, including IAM, VPC and networking, Cloud Audit Logs, monitoring, Security Command Center, Secret Manager, Cloud Run, BigQuery, and Google SecOps.
  • Experience building and operating security detection, triage, incident response, and SIEM processes; Google SecOps or Chronicle preferred.
  • Hands-on Terraform experience, including modules, state, and deployment pipelines.
  • Experience designing and implementing zero-trust access controls, identity-aware proxies, device posture, and context-aware policies.
  • Strong security fundamentals in IAM, least privilege, secrets and key management, network security, cryptography, and data protection.
  • Comfort reading and reasoning about Node.js, TypeScript, and MySQL code.
  • Hands-on experience owning CI/CD pipelines and embedding security controls into software delivery.
  • Willingness to support production operations and on-call for VMs and serverless GCP infrastructure.
  • Daily use of AI tools such as Claude Code or Copilot for coding, incident investigation, documentation, and automation.
  • Experience carrying SOC 2, ISO 27001, or PCI DSS through certification and recurring audits as a control owner.
  • Google Cloud Professional Cloud Security Engineer certification.
  • Additional Google Cloud certification such as Professional Cloud Architect, Professional Cloud Network Engineer, or Professional Cloud DevOps Engineer.
  • Experience with Ethereum or EVM security, wallets, keys, signers, Safe multisig administration, and stablecoin settlement threats.
  • Experience in fintech, payments, or another regulated, funds-handling environment.
  • Active or previous U.S. Government security clearance.
  • U.S. military experience, particularly in cybersecurity, signals, or intelligence.
  • CISSP, GCIH, GCFA, GCDA, CCSP, or similar certification.
  • Advanced Cloudflare experience with WAF rules, Workers, Zero Trust, and Logpush.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
101 Employees
Year Founded: 2019

What We Do

Rise (Rise Works, Inc.) is a global payroll and compliance SaaS platform that helps companies hire, onboard, and pay international contractors and full-time employees across 190+ countries. It supports flexible fiat and cryptocurrency payouts, automated identity verification (KYC/AML), tax and legal documentation, and provides EOR/AOR services and on-chain RiseID for secure, compliant workforce management.

Similar Jobs

NVIDIA Logo NVIDIA

Head of Infrastructure Security Engineering - EDA Clusters

Artificial Intelligence • Computer Vision • Hardware • Robotics • Metaverse
In-Office or Remote
5 Locations
21960 Employees
272K-489K Annually

T-Mobile Logo T-Mobile

Account Executive

Other • Utilities
Remote
Massachusetts, USA
89016 Employees
43K-78K Annually
In-Office or Remote
Miami Beach, FL, United States
90K-150K Annually

Liberty Mutual Insurance Logo Liberty Mutual Insurance

Senior Underwriting Manager, Liberty Mutual Mobility Solutions

Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Remote or Hybrid
5 Locations
40000 Employees
98K-359K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account