About the job
Join Greenboard as the Head of Technical Security
At Greenboard, we are pioneering the future of financial compliance through our AI-driven, unified compliance operating system. Our platform serves a diverse range of clients including RIAs, fintechs, private funds, and hedge funds, effectively replacing outdated systems and automating processes like never before. By consolidating data and workflows, we empower firms to mitigate regulatory risks, streamline their technology stack, modernize compliance operations, and ultimately save costs.
Our team boasts engineers with extensive experience from Amazon, Google, and other leading startups, backed by top-tier investors such as Y Combinator and General Catalyst, with over $20 million raised to date. Trusted by prominent financial institutions, Greenboard is on a rapid growth trajectory.
Role Overview
We are seeking an experienced security engineer to lead and enhance our security strategy as we expand. As the first dedicated security hire on our engineering team, you will play a crucial role in defining our security approach, addressing compliance frameworks, conducting vendor assessments, implementing infrastructure security measures, and promoting secure development practices.
This position offers high impact and autonomy, requiring collaboration with engineering, product, and business teams to ensure we are developing securely, meeting compliance standards expected by our fintech clients, and proactively countering security threats as we grow internationally.
Your Responsibilities
Technical Security Management
Identify, prioritize, and remediate vulnerabilities across all layers , from infrastructure to application and network.
Oversee third-party penetration testing activities and coordinate internal responses to findings.
Embed security measures throughout the development lifecycle, including code reviews, SAST/DAST tools, dependency checks, and developer security training.
Manage credential and secret handling, focusing on rotation policies, vault configurations, and access controls.
Lead infrastructure patching and hardening initiatives while collaborating with engineering teams to maintain current systems without hindering delivery.
Compliance & Framework Leadership
Spearhead our SOC 2 compliance program, including audit preparations, evidence gathering, and tracking remediation efforts.
Enhance and uphold our GDPR compliance, working alongside legal and product teams to ensure data protection standards are met.
Lead efforts towards ISO 42001 certification, developing and maintaining necessary AI management frameworks.
