Head of Security
San Francisco, CAFull-time$250–350K/yrPosted 1w agoStill listed 1w ago
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near San Francisco, CA, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Job overview
Exa is an applied AI lab building a massive‑scale search engine, developing infrastructure to crawl the web, train embedding models, and create high‑performance vector databases, serving products like Cursor and HubSpot while seeking a leader to define and execute its company‑wide security strategy.
Skills & qualifications
Skills
Benefits
Full job description
About Exa
Exa is an applied AI lab building a search engine unlike the world has ever seen. We build massive-scale infra to crawl the entire web, train state-of-the-art embedding models to process it, and design super high performant vector databases to retrieve over it. We now power search for Cursor, Cognition, HubSpot, and over 400,000 developers and have raised $350m from Lightspeed, Benchmark, and a16z. Our ultimate goal is to build perfect search over all the world's information, far beyond Google. If you want to build massive-scale ML systems that will define the way the new AI world consumes information, this is the place for you.
What You’ll Own
-
Define Exa’s company-wide security strategy, operating model, risk framework, and multiyear roadmap.
-
Establish Exa’s security posture and risk appetite in partnership with the founders and executive team.
-
Provide leadership with clear, decision-ready assessments of material risks, incidents, investments, and tradeoffs.
-
Own security architecture and engineering across Exa’s products, APIs, web-scale data pipelines, cloud environments, Kubernetes clusters, model-training systems, GPU infrastructure, and internal platforms.
-
Protect customer data, proprietary models, training data, source code, credentials, and other high-value assets from external attacks, insider threats, supply-chain compromise, and misuse.
-
Build security into the product-development lifecycle through threat modeling, architecture reviews, secure defaults, automated controls, vulnerability management, offensive testing, and engineering education.
-
Establish identity, access, secrets, key, certificate, and service-trust systems across human users, workloads, training jobs, and AI agents.
-
Build Exa’s detection, investigation, incident response, crisis management, and recovery capabilities; serve as the accountable leader during significant security incidents.
-
Own corporate security, including endpoints, SaaS applications, employee access, security awareness, insider risk, physical-security interfaces, and third-party risk.
-
Lead security governance, regulatory readiness, compliance, and customer assurance, including programs such as SOC 2 and ISO 27001.
-
Represent Exa’s security program in strategic customer conversations, enterprise reviews, audits, and other high-trust settings.
-
Define the security organization’s structure, budget, technology strategy, external partnerships, and hiring plan.
-
Recruit, develop, and lead an exceptional security team while creating a culture in which every team shares responsibility for security.
-
Establish meaningful security metrics and regularly communicate Exa’s posture, priorities, and progress to company leadership.
What We’re Looking For
-
You have built or led security at a technically ambitious, rapidly growing infrastructure, AI, developer-platform, cloud, or enterprise-software company.
-
You have operated with company-wide accountability for security—not merely responsibility for an individual security discipline.
-
You combine executive judgment with deep technical credibility. You can move comfortably between company strategy, business risk, system architecture, incident investigation, and implementation details.
-
You approach unfamiliar problems with the mindset of both a builder and an attacker, and you are energized by security challenges for which no established playbook exists.
This is an in-person opportunity in San Francisco. We’re happy to sponsor international candidates (e.g., STEM OPT, OPT, H1B, O1, E3). In addition to premium healthcare benefits (medical, dental, vision), we also offer fertility benefits and a monthly wellness stipend to all of our employees.
Exa is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, creed, color, religion, sex, sexual orientation, gender identity or expression, national origin, disability, age, veteran status, marital status, pregnancy or related conditions, criminal histories consistent with applicable law, or any other basis protected by applicable law.
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Senior Cloud Security EngineerAnyscale · San Francisco, CA (Hybrid) · $200–240K/yrPosted 2w agoPosted 2w ago
Senior Product Security EngineerAnyscale · San Francisco, CA, India · $180–210K/yrPosted 2w agoPosted 2w ago
Security GRC AnalystPinterest · San Francisco, CA (Hybrid) · $124–255K/yrPosted 1w agoPosted 1w ago
Customer Trust SpecialistAnthropic · San Francisco, CA (Hybrid) · $255–270K/yrPosted todayPosted today
Head of Marketing Technology (MarTech)OpenAI · San Francisco, CA (Hybrid) · $326–362K/yrPosted 3w agoPosted 3w ago
You've read the whole posting — now see how you match it.