Head of Security
Straight from Code Metal’s careers page. Apply on the company site — no recruiter, no middleman.
Head of Security
Department: Technology & Solutions
Location: San Franscisco Hub, Remote , Boston Hub
Employment Type: FullTime
About Code Metal
Code Metal is the leader in automated software engineering you can trust. As AI writes more of the worlds code, the bottleneck in software has shifted from writing code to verifying it works, and AI cannot verify its own work with certainty. Code Metal takes a fundamentally different approach: constrain AI to what it does reliably, verify every step independently of the model using formal methods, and keep engineers in the loop on the decisions that matter. The result isnt code that probably works — its code that is provably correct, with auditable proof. Customers including the U.S. Air Force, L3Harris, RTX, and Toshiba use Code Metal to modernize legacy code, optimize performance on real hardware, and move prototypes to production, fast. Founded in 2023 with offices in Boston and San Francisco, Code Metal is funded by Accel, Salesforce Ventures, B Capital, Smith Point Capital, J2 Ventures, Shield Capital, Overmatch, RTX, and others.
Learn more at codemetal.ai.
About the Role
Code Metal is looking for a Head of Security to lead, mature, and scale our existing security program as the company grows.
This person will own security strategy and technical direction across our products, offerings, infrastructure, corporate systems, and development environments. You will work closely with engineering, IT, legal, compliance, our FSO, and company leadership to ensure our security posture meets the needs of defense, government, and enterprise customers.
This is a senior leadership role for someone who is technically strong, comfortable making risk-based decisions, and able to operate effectively with engineers, executives, customers, and government partners.
Requirements
10+ years of cybersecurity and compliance experience with meaningful security leadership responsibility.
Broad technical depth across product, cloud, infrastructure, and enterprise security.
Experience owning or significantly maturing security programs within highly technical organizations.
Strong understanding of security architecture, risk management, security operations, privacy and compliance requirement and incident response.
Experience working closely with engineering organizations and influencing technical decisions.
Strong judgment and the ability to communicate security risks and priorities to technical and non-technical audiences.
U.S. citizenship and ability to obtain and maintain a U.S. government security clearance.
Nice to Haves
Experience supporting defense, government, or other highly regulated customers.
Experience with CUI, classified systems, SCIFs, or other high-assurance environments.
Experience with moving into new markets and jurisdictions and understanding the compliance requirements for new regions.
Familiarity with relevant government and industry security frameworks, such as NIST 800-171, CMMC, SOC 2, ISO 27001, GDPR or EU AI.
Experience securing modern cloud-native and AI-enabled products.
Active U.S. government security clearance.
Responsibilities
Own and evolve Code Metals cybersecurity strategy, priorities, and roadmap.
Lead security across our products, infrastructure, corporate systems, and development environments.
Partner with engineering teams to establish practical security architecture, standards, and controls.
Oversee core security operations, including identity and access management, vulnerability management, monitoring, and incident response.
Lead product security and ensure security is integrated throughout the software development lifecycle.
Own the security aspects of regulatory, compliance, and customer requirements.
Partner with our FSO and technical teams on cybersecurity requirements for CUI and classified environments.
Partner with Legal, the FSO, and Operations to translate regulatory, contractual, and customer security requirements (CMMC, DFARS/NIST 800-171, and customer flowdowns) into technical controls, and coordinate on compliance obligations for new business initiatives, products, and environments.
Represent Code Metals security posture with leadership, customers, government partners, auditors, and other external stakeholders.
Lead and develop the security organization and its capabilities as Code Metal grows.
Benefits
Pay depends on experience, but we strive to be at the upper end of the salary range
Health care plan with 100% premium coverage, including medical, dental, and vision
401k with 5% matching
Paid Time Off (uncapped vacation, plus sick and public holidays)
Flexible hybrid or remote work arrangement
Relocation assistance for qualifying employees
Wage Transparency - The salary range for this role is not a guarantee of compensation or salary, as the final offer amount may vary based on factors including, but not limited to, individual proficiency, skills, experience, and location.
We are an equal opportunity employer. US Citizenship may be required for certain project assignments involving security clearance.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Similar remote jobs
More like this →


Leidos
Engineering Delivery Manager

Leidos
Post-Quantum Cryptography Engineer (Remote)
Discover More than 100,000 Hidden Remote Jobs Before Everyone Else
Unlock All Remote Jobs Today
Simple pricing. Big savings on Quarterly and Yearly.
Monthly Access
- Instant access to fresh remote jobs from 500+ companies
- New opportunities added hourly, often 3-7 days before anywhere else
- Advanced filtering by role type, stack, pay, and location
- Priority customer support
Yearly Access
- Everything in Monthly
- Save $169 (~74%) vs paying monthly
- Average job search takes ~6 months - get covered for the whole journey
- Less than the cost of one lunch per month for competitive advantage
- Equivalent to just ~$4.92/month