Director of Security & Compliance
Summary
Lead security and compliance for a Palo Alto-based AI cybersecurity startup, owning customer trust reviews, SOC 2/ISO 27001 compliance, and internal security programs while managing a small team.
About us
Anvilogic is a Palo Alto-based AI cybersecurity startup founded in 2019 by security veterans and data scientists from Fortune 500 companies.
Our mission is to democratize threat detection and hunting for today’s SOC teams to easily be done across hybrid, multi-clouds and security data lakes without needing to centralize data or rip and replace tools. Further, with our investments in AI-powered automation of detection-as-code to create, test, tune and deploy detections, SOC users can implement high-efficacy detection and hunting techniques without writing a single line of code nor manually wrangling data.
Anvilogic raised $45M Series C funding in April 2024 and is backed by top-tier VC firms and prominent industry executives. Anvilogic’s AI-powered Multi-Data Platform SIEM is used by many of the industry’s most advanced security teams.
Learn about our customers:
About the role
Anvilogic is looking for a Director of Security & Compliance to own how we earn and keep our customers' trust. As a security company, our customers hold us to the standard we help them meet — and this role is the person who answers to that standard, both in the room with customers and inside our own environment.
This is a customer-facing leadership role first. You'll partner directly with prospects and customers on their security and compliance requirements: leading trust and security reviews, responding to questionnaires and audit requests, and translating our security posture into terms that satisfy enterprise security teams. Behind that, you'll own and mature Anvilogic's internal security program, maintain our SOC 2 Type II and ISO 27001 compliance, lead a small team spanning security engineering and compliance, and oversee IT.
Key responsibilities
- Serve as Anvilogic's security point of contact for prospects and customers, leading trust and security reviews across the sales cycle and customer lifecycle.
- Own security questionnaires, RFP security sections, and audit-support requests, turning them around quickly and credibly for enterprise security teams.
- Own and mature Anvilogic's internal security program across cloud infrastructure, applications, corporate systems, and data, including vulnerability management, monitoring, and incident response.
- Maintain SOC 2 Type II and ISO 27001 compliance: manage the control environment, coordinate audits, and keep evidence collection continuous.
- Lead and grow a small team spanning security engineering and compliance, and own the security roadmap and priorities.
- Oversee IT operations (identity and access, endpoint management, SaaS administration) in a way that reinforces the security posture.
Requirements
Required qualifications
- 10+ years in security or security engineering, with 3+ years in a customer-facing or GRC capacity (trust reviews, questionnaires, audits).
- 2+ years managing security engineers or a comparable technical team.
- Strong grounding in cloud security (AWS preferred), including infrastructure, identity and access, and application security.
- Proven ability to represent a security posture credibly to enterprise security teams, CISOs, and auditors, and to translate technical controls into clear assurances.
- Sound judgment on prioritizing security work against real risk at a fast-moving company.
Preferred qualifications
- Experience at a security vendor or in a company selling to enterprise security teams.
- Familiarity with security operations tooling (SIEM, detection engineering, threat detection) and how modern SOC teams work.
- Experience owning or overseeing IT in a growing company.
- Background scaling a security program from an early or mid stage.
Benefits
- US Salary Transparency: Final compensation will depend on experience, qualifications, and location.
- Competitive salary with equity in the company
- Comprehensive medical, dental, and vision insurance
- Unlimited paid time off policy for work life balance
- 401(k) retirement plan with company match
- Monthly stipend for home internet and cell phone expenses
As published by workable
First name, Last name, Email, Headline, Phone, Address, Photo, Education, Experience, Summary, Resume, Cover letter
- Are you authorized to work in the United States? yes / no
- Will you now, or in the future, require sponsorship (e.g., H-1B, TN, O-1, or other work visas) to work within the United States? yes / no
- Do you have at least 10 years experience in security or security engineering with 3+ years in a customer-facing or GRC capacity (trust reviews, questionnaires, audits)? yes / no
- Do you have at least 2+ years managing security engineers or a comparable technical team? yes / no
- Tell us about about a time you presented a security posture credibly to enterprise security teams, CISOs, and/or auditors, and how you translated technical controls into clear assurances. written answer
- Please list any security operations tools (SIEM, detection engineering, threat detection) you have used and how you utilized them to lead a modern SOC team written answer
- Briefly describe your experience scaling a security program from an early or mid stage written answer