Tremendous logo

Head of Security

Tremendous
Remote
Remote$250k–$330k· about 2 months ago

Straight from Tremendous’s careers page. Apply on the company site — no recruiter, no middleman.

Head of Security

Department: Engineering

Location: United States, Remote

Compensation: $250K – $330K • Offers Equity

Employment Type: FullTime

Tremendous is the global platform built for businesses to send payouts—gift cards and money—to anyone, anywhere, instantly. Were trusted by 20,000+ organizations, from startups to giants like Atlassian, MIT, and United Way, to reach millions of recipients worldwide.

Were profitable and growing without outside investors. Were fully remote, with a high-documentation, low-meeting culture that leaves more time for the work that matters—and for your life outside it. Our employee NPS sits in the high 80s.

We move billions of dollars through our systems. That makes security existential, and its why were making our first dedicated security hire.

About the role

Youll be our first Head of Security. Theres already a real foundation here—bug bounty, pen tests, automated code and configuration scanning on the production and code side, phishing simulations on the people side. You’ll add to it across access and identity, SecOps and monitoring, incident response, vendor security, employee security practices, and policy. Youll own the whole posture.

This is a player-coach role. Early on, youll do the scoping and the hands-on work yourself; this is not a role where you direct from above. As the work demands it, were fully prepared to build a team here—and were looking to you to define what that team should be and when.

Youll report to the VP of Engineering, Tremendous most senior technical leader. Weve deliberately placed security with Engineering so youre set up to drive real implementation fast—embedded with the people whose work youre securing, not siloed in a compliance function. As the security function matures, well revisit this.

What youll do

  • Own Tremendous security posture end-to-end, partnering with our engineering team on production infrastructure and code security.

  • Assess where we have gaps, prioritize them, and tackle our highest-leverage gaps first. We’ll have opinions, but you own the prioritization and implementation.

  • Treat incident response as core, not afterthought. We may not be able to prevent a breach, but your job is making sure its small, contained, and that we know exactly what to do.

  • Drive security as a cultural shift across the company—introducing controls incrementally, working with teams rather than over them. Yes, and, not no.

  • Lead our AI-security posture. We invest heavily in AI tooling; your job is to manage that risk and enable it, not to ban it.

  • Define when and how to staff up the security function, and hire your own team.

What youll bring

  • Real, hands-on security experience at a company that scaled—ideally as an early security hire who grew with the business through high growth.

  • Deep experience in at least one core security domain—product/production security, security operations, or access/identity and policy—with enough range to reason across the others. You defined the security posture, not just executed someone else’s playbook.

  • An engineers mindset. You reach for code to solve problems and can read our codebase and understand our infrastructure (Ruby on Rails; TypeScript + React; PostgreSQL; Google Cloud). You wont write much day-to-day, but youre not lost in the code.

  • Judgment over checklists. You can explain the actual risk of a given decision, hold a firm line where it matters, and give ground where best practice doesnt apply to us or real business need pulls the other way. You can hold your own in a debate about whether to open up broad data access for AI tooling.

  • Bedside manner. You drive hard change by bringing the team around to your point of view, rather than just telling them no. Engineers and the rest of the company want to work with you.

  • Experience building or co-building a small security team is a plus.

  • Fintech, payments, or regulated-industry experience is a plus.

Whats cool about the role

  • You define the function. First security leader, with the budget for the required tools and team.

  • A real mandate. The push for this hire comes straight from the founders.

  • We invest in your tools. Everyone has a $5k/month budget for AI tools. Use it.

  • Competitive pay and equity. Base salary $250,000–$330,000, plus meaningful equity.

  • Fully remote. Work from anywhere in the Americas.

  • Great culture. Read more about how we work in our public handbook.

Similar remote jobs

More like this →
Valiant Solutions logo

Valiant Solutions

Software Engineer (Remote)

Remote
✓ From careers page· about 23 hours ago
Omada Health logo

Omada Health

Software Engineer, Solutions Engineering (Remote)

Remote
$128k–$184k
✓ From careers page· 1 day ago
Omada Health logo

Omada Health

Senior Software Engineer, Solutions Engineering (Remote)

Remote
$156k–$224k
✓ From careers page· 1 day ago
Omada Health logo

Omada Health

Engineering Manager, Infrastructure

Remote
$156k–$224k
✓ From careers page· 1 day ago

Discover More than 100,000 Hidden Remote Jobs Before Everyone Else

Unlock All Remote Jobs Today

Simple pricing. Big savings on Quarterly and Yearly.

Monthly Access

$19/month
  • Instant access to fresh remote jobs from 500+ companies
  • New opportunities added hourly, often 3-7 days before anywhere else
  • Advanced filtering by role type, stack, pay, and location
  • Priority customer support
Start 7-day trial — $2.95
Most Popular

Yearly Access

$59/year
  • Everything in Monthly
  • Save $169 (~74%) vs paying monthly
  • Average job search takes ~6 months - get covered for the whole journey
  • Less than the cost of one lunch per month for competitive advantage
  • Equivalent to just ~$4.92/month
Start 7-day trial — $2.95