Head of Security

Nous Research

Remote · USFull-timePosted 1mo agoStill listed today

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
Remote · US
Schedule
Full-time
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Job overview

As Nous Research’s first Security hire, the Head of Security will build and own security across infrastructure, products, and enterprise deployments. The role focuses on hardening multi-cloud infrastructure, securing the Hermes Agent platform, and establishing a security foundation for regulated enterprise customers. It partners across engineering and operations while helping the team maintain development velocity.

Skills & qualifications

RequiredNice to have

Skills

Infrastructure SecurityMulti-Cloud SecuritySaaS SecurityKubernetesIdentity and IAMEnterprise SSOSAMLSCIMCompliance EngineeringSOC 2ISO 27001Vulnerability ManagementIncident ResponseAccess ControlsPenetration TestingSecure Software DevelopmentAgentic AI SecurityAgent IdentityTool PermissionsPrompt InjectionData ProvenanceRegulated Customer SecurityFinancial Services SecurityAir-Gapped SecurityAI SecurityMachine Learning SecurityOpen-Source SecurityCloud-Native DetectionCloud-Native ResponseKernel-Level SandboxingNetwork IsolationAgent SecuritySecurity ReviewsArchitecture AssessmentsSecurity JudgmentPragmatismCross-Functional Collaboration

Qualifications

8+ Years Security Engineering ExperienceProduction SaaS Security Track RecordEnd-to-End Security OwnershipFast-Growing Technology Company Experience

Full job description

The Role As the first Security hire at Nous Research, you'll build and own security end-to-end across our infrastructure, products, and enterprise deployments. Nous builds open-source AI language models and agents, including Hermes Agent, which is used by consumers and Fortune 500 enterprises across multi-tenant SaaS, dedicated VPC, self-hosted, and air-gapped environments. This is a hands-on-keyboard role for someone who wants to harden multi-cloud infrastructure, secure a novel agentic AI platform, and build the security foundation regulated enterprise customers demand. You'll be the person focused full-time on protecting the company while helping the rest of the team continue shipping quickly. Responsibilities

  • Own production security across a multi-cloud footprint spanning AWS, GCP, Azure, and Vercel.

  • Secure multi-tenant SaaS, dedicated VPC, self-hosted Kubernetes, and air-gapped deployments.

  • Secure the Hermes Agent platform across sandboxing, kernel-level file system and network isolation, agent identity, credential controls, egress controls, and trace integrity.

  • Own SOC 2 technical controls, evidence collection, remediation, and ongoing readiness.

  • Harden identity and access management, including SSO and SAML consolidation, least-privilege access reviews, 2FA, and BYOD policies.

  • Lead vulnerability management, penetration testing, incident response, and cloud-native security monitoring.

  • Strengthen the secure software development lifecycle through practical controls, including peer-review requirements, while maintaining high development velocity.

  • Support enterprise deals by completing security questionnaires, leading architecture reviews, and addressing penetration-testing requirements.

  • Partner across engineering, infrastructure, product, FDE, and operations to identify and address security risks.

Qualifications

  • 8+ years of security engineering experience, with deep hands-on expertise in infrastructure and multi-cloud security.

  • Track record securing production SaaS environments and owning security end-to-end at a fast-growing technology company.

  • Strong Kubernetes, identity, and IAM fundamentals, including familiarity with enterprise SSO, SAML, and SCIM.

  • Experience implementing compliance-driven engineering programs such as SOC 2 or ISO 27001 without allowing them to become checkbox exercises.

  • Strong understanding of vulnerability management, incident response, access controls, penetration testing, and secure software development practices.

  • Interest in securing agentic AI systems and addressing emerging risks across agent identity, tool permissions, prompt injection, and data provenance.

  • Ability to work effectively in a high-velocity, open-source-native engineering culture.

  • Security-minded by default and pragmatic in practice, with strong judgment around balancing protection and development speed.

Nice-to-Have

  • Experience supporting regulated customers, financial services organizations, or air-gapped deployments.

  • Prior experience securing AI, machine learning, or open-source systems.

  • Experience with detection and response tooling in cloud-native environments.

  • Familiarity with kernel-level sandboxing, network isolation, and agent security.

  • Experience supporting Fortune 500 security reviews, architecture assessments, and penetration-testing requirements.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.