Senior Director of Security / Head of Security
Job Description
ROLE OVERVIEW
\n
\n
We are seeking an experienced and strategic Senior Director / Head of Security to lead security for our GPU-as-a-Service (GPUaaS) platform. This role is responsible for protecting GPU infrastructure, cloud platforms, customer workloads, data, APIs, orchestration systems, and corporate environments.
\n
\n
You will build and manage a comprehensive security program across infrastructure, platform, application, cloud, data, identity, compliance, and customer trust, partnering closely with Infrastructure Engineering, Site Reliability Engineering, Product, Legal, Sales, and executive leadership to enable secure growth at scale.
\n
\n
This is a senior leadership role requiring strong expertise in cloud security, Kubernetes, high-performance computing, multi-tenant platforms, incident response, security architecture, and regulatory compliance.
\n
\n
RESPONSIBILITIES
\n
\n
Strategy & Organization
\n
- Define and execute the company's GPUaaS security strategy and roadmap
\n
- Build, lead, and develop a high-performing security organization
\n
- Establish security policies, standards, procedures, and operating models
\n
\n
Infrastructure & Platform Security
\n
- Secure GPU clusters, data centers, cloud environments, and networking infrastructure
\n
- Protect Kubernetes, containers, orchestration platforms, schedulers, and management planes
\n
- Ensure strong isolation between customer tenants, workloads, data, and control planes
\n
- Secure infrastructure provisioning, operating systems, firmware, drivers, and infrastructure-as-code
\n
- Lead vulnerability management across hardware, software, containers, dependencies, and cloud services
\n
\n
Product & Application Security
\n
- Own application and product security for APIs, portals, SDKs, dashboards, and customer integrations
\n
- Implement secure software development lifecycle practices and security testing
\n
- Establish threat modeling, code review, penetration testing, and release security controls
\n
\n
Identity & Data Protection
\n
- Manage identity and access controls, including MFA, privileged access, and least privilege
\n
- Protect customer data, models, datasets, credentials, logs, and operational metadata
\n
- Oversee encryption, key management, data classification, retention, and data-loss prevention
\n
\n
Detection & Incident Response
\n
- Build security monitoring, threat detection, intelligence, and incident response capabilities
\n
- Lead investigations, containment, recovery, communications, and post-incident improvements
\n
\n
Governance, Risk & Customer Trust
\n
- Manage security governance, risk, compliance, audits, certifications, and control documentation
\n
- Oversee third-party risk management, vendor assessments, and supply-chain security
\n
- Support customer security reviews, enterprise sales engagements, RFPs, and due diligence
\n
- Promote security awareness, secure engineering practices, security champions, and a company-wide security culture
\n
\n
QUALIFICATIONS
\n
\n
- 15+ years of experience in cybersecurity, cloud security, infrastructure security, application security, or a related field
\n
- 5+ years of experience in senior security leadership, management, or architecture roles
\n
- Proven experience securing cloud-native, distributed, and multi-tenant environments
\n
- Strong expertise in Kubernetes, containers, Linux, networking, IAM, secrets management, and encryption
\n
- Experience securing large-scale compute, data-center, bare-metal, or high-performance computing environments
\n
- Strong understanding of secure software development lifecycle practices
\n
- Experience with security testing, vulnerability management, monitoring, and incident response
\n
- Experience designing and managing governance, risk, compliance, and audit programs
\n
- Demonstrated ability to lead cross-functional initiatives and influence executive stakeholders
\n
- Excellent written, verbal, and stakeholder communication skills
\n
\n
PREFERRED
\n
\n
- Experience with GPUaaS, cloud platforms, AI/ML infrastructure, or managed technology services
\n
- Experience with workload isolation, confidential computing, zero-trust architecture, and Kubernetes security
\n
- Experience leading SOC 2, ISO 27001, HIPAA, DPA, PCI DSS, or similar compliance programs
\n
- Security certifications such as CISSP, CISM, CCSP, or GIAC, plus experience with enterprise customers and security supply chains
