Director of Information Security
Summary
Leads Fetch’s end-to-end security program: AppSec, incident response, compliance, and AI governance while building a scalable, auditable security framework and managing a security engineering team.
Position Summary
The Director of Information Security owns Fetch's security function end to end: vulnerability management and AppSec, incident response and forensics, security architecture, GRC/compliance, third-party risk, and security awareness. This role is the senior full-time security leader for the company, taking day-to-day ownership of the security program.
The Director of Information Security is the dedicated, always-on owner of the security posture; someone who can run point on a critical incident, drive a vulnerability program to completion, and build the compliance backbone the company needs as it scales.
Role Purpose
- Own the security function's day-to-day execution.
- Reduce the company's exposure to high-blast-radius security risk, AI agent architecture, and application security.
- Build a mature, auditable, and scalable security program (policy, controls, evidence, reporting) ahead of compliance and customer-trust demands.
- Lead and grow a Security team, providing the people management the function has lacked.
- Serve as the primary technical authority and incident commander for security events.
- Represent Information Security credibly to executives, auditors, customers, and partners.
Key Responsibilities
1. Security Engineering & Vulnerability Management
- Own the AppSec and vulnerability management program (Snyk and adjacent tooling), including pack ownership, CI/CD security gating, and repository risk classification processes.
- Drive vulnerability remediation SLAs and hold engineering accountable to them.
- Continuously mature the program from reactive scanning toward proactive, gated prevention.
2. Incident Response & Forensics
- Act as an incident commander for security incidents, including coordinating cross-functional response, containment, and communication.
- Own the bug bounty and continuous penetration testing disclosure program: triage, validation, remediation tracking, and researcher communication.
- Facilitate post-incident reviews and root-cause analysis, with particular attention to recurring architectural risk patterns.
- Ensure remediation of systemic issues, not just point fixes and elevate platform-level fixes when the same root cause recurs across incidents.
3. Security Architecture & Emerging Risk
- Own security architecture review for new systems, platforms, and AI agent deployments, including AI agent identity and access patterns (eg, cross-app access, delegated identity).
- Maintain security standards for cloud infrastructure, endpoint protection, and network/edge security.
- Partner with IT Operations on identity-related risk (entitlement sprawl, contractor and non-employee access, and access governance) providing the security requirements and risk lens that IT Operations executes against.
4. GRC, Policy & Compliance
- Own the security policy library, risk register, and control framework; keep them current and audit-ready.
- Lead internal and external audits and assessments, coordinating evidence collection across IT, Engineering, and Legal.
- Report program maturity, open risk, and remediation progress to executive leadership on a regular cadence.
- Oversee processes to update and maintain the Enterprise Security Risk Register.
5. AI Governance & Emerging Technology Risk
- Partner with the Chief AI Officer on the security dimensions of AI governance, including enforcement of AI acceptable-use policy and identification of security risk in new AI tooling and agent deployments.
- Provide the security review and risk sign-off for new AI platforms, agents, and integrations prior to broad rollout.
6. Third-Party & Vendor Risk
- Own vendor and third-party security risk assessment for new tools, integrations, and contractors.
- Maintain a defensible, repeatable process for evaluating vendor security posture before onboarding.
7. Security Awareness & Culture
- Own company-wide security awareness programming, phishing simulation, and targeted training following incidents or audit findings.
- Build blameless, clear communications that raise the organization's security literacy without creating fear or confusion.
8. Team Leadership & People Management
- Hire, coach, and develop the Security Engineering team.
- Set team priorities, run performance management, and build a growth path for security engineers.
- Establish team operating rhythm: on-call/incident rotation, backlog grooming, and technical review standards.
9. Executive & Cross-Functional Communication
- Own the security content in recurring executive reporting.
- Represent Information Security in cross-functional forums (Legal, AI governance, IT Operations, Engineering leadership).
- Escalate material risk, resourcing gaps, or unresolved cross-functional blockers promptly and clearly.
Required Qualifications
- 7+ years in information security, including meaningful experience in application security, incident response, and security architecture.
- Demonstrated experience running vulnerability management programs at scale (eg, Snyk or comparable tooling).
- Direct incident command experience, including coordinating cross-functional response to significant security events.
- People management experience, ideally building or scaling a security engineering team.
- Working knowledge of cloud security, identity and access management concepts, and modern AI/agent architecture risk.
- Strong written and verbal communication skills, including comfort presenting to executive audiences.
Preferred Qualifications
- Experience with bug bounty/responsible disclosure program management.
- Experience building or maturing a GRC program, including audit and compliance framework experience (SOC 2, ISO 27001).
- Familiarity with AI agent security risk, including MCP-style tool/agent architectures and identity delegation patterns.
- Experience partnering with AI governance or data governance functions.
- Relevant certifications (CISSP, CISM, or equivalent).
Core Competencies
- Incident command and crisis leadership
- Security architecture and risk assessment
- Program and process maturity building
- People leadership and coaching
- Executive communication
- Cross-functional influence without direct authority over partner teams
- Judgment under ambiguity and time pressure
Y Combinator