Skip to content

Open nowPosted 9 days ago

Head of Information Security

athenago6 open roles

Where
Los Angeles
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowHead of Information Securityathenago · Los Angeles
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on athenago's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.3% of postings close within 7 days. Measured by our own scanner across the market. athenago postings stay open a median of 3 days.

Share of postings closed within
  1. 1.9%1 day
  2. 3.9%3 days
  3. 8.3%7 days
  4. 15.3%14 days
  5. 34.1%30 days
This job: posted 9 days ago

athenago median: 3 days open

The posting

About Athena

Athena (athena.com) pairs world-class leaders with elite executive assistants. It’s where some of the most powerful partnerships in the world get built.

Our clients are founders, executives, and leaders whose ambition exceeds their time. Athena is the first company to build a human-in-the-loop executive support system, combining trained Executive Assistants with market-leading AI to help them stay organized, follow through on priorities, and operate at their highest level.

Athena is one of the largest companies in this category, with 3,000+ clients and over $100M in annual run rate. Our clients include Uber, Shopify, and Goldman Sachs.

We are fully global, working across time zones and cultures. Joining Athena means creating something that fundamentally changes how people live and work and brings extraordinary achievement within reach.

Who We’re Looking For

We’re looking for people who take their work seriously and want to get better at it.

You should be thoughtful in how you approach problems, willing to take ownership, and able to follow through without constant direction. You ask questions when something doesn’t make sense, and you care about getting the details right.

You should be comfortable working with people who have high expectations and limited time. That means being clear, responsive, and reliable.

We’re also looking for people who are interested in how this role is changing. The way work gets done is in flux between people, systems, and AI. We want people who are curious about that and willing to adapt as technology evolves.

You don’t need to know everything on day one, but you should be able to learn quickly and apply what you learn.

Role Overview

We are looking for a Head of InfoSec Operations to lead the day-to-day execution of our cybersecurity operations, security monitoring, incident response, threat detection, vulnerability management, and client-facing security assurance.

This role will bridge the gap between security strategy and tactical execution. The ideal candidate is hands-on, operationally strong, calm under pressure, and able to work cross-functionally with IT, Engineering, DevOps, Product, Legal, Compliance, Sales, and Customer Success.

In addition to leading internal security operations, this person will serve as a key point of contact for client security questions, customer due diligence, security questionnaires, vendor risk reviews, and enterprise security discussions.

Key Responsibilities

Security Operations & Incident Response

  • Lead and continuously improve the company’s security operations function, including monitoring, detection, investigation, response, and remediation.
  • Serve as incident commander for major cybersecurity incidents, leading triage, containment, eradication, recovery, and post-incident reviews.
  • Own the operational incident response process, including playbooks, escalation paths, communication procedures, and readiness exercises.
  • Ensure proper logging, monitoring, alerting, and security visibility across cloud, SaaS, endpoint, network, and application environments.
  • Oversee threat detection, threat hunting, security investigations, malware analysis, and forensic response activities.
  • Establish and track security operations metrics such as mean time to detect, mean time to respond, alert quality, incident volume, and remediation timelines.
  • Conduct tabletop exercises, simulations, and regular readiness reviews to improve incident response maturity.

Vulnerability Management & Risk Reduction

  • Own the vulnerability management program, including scanning, prioritization, remediation tracking, and reporting.
  • Coordinate penetration testing, external assessments, and remediation follow-up with Engineering, DevOps, IT, and Product teams.
  • Partner with technical teams to identify, assess, and reduce security risks across infrastructure, applications, cloud services, endpoints, and third-party tools.
  • Monitor emerging threats, adversary tactics, and relevant attack trends, and translate them into practical defensive improvements.
  • Drive remediation of risks that exceed the company’s acceptable risk thresholds.

Security Tooling & Architecture

  • Evaluate, implement, manage, and optimize security tools such as SIEM, EDR, SOAR, XDR, vulnerability scanners, cloud security monitoring, identity security tools, and logging platforms.
  • Tune detection rules, reduce false positives, and improve the quality and actionability of security alerts.
  • Ensure security tooling is properly integrated with IT, DevOps, cloud, identity, and engineering systems.
  • Participate in or lead security reviews for new products, services, infrastructure changes, and vendor technologies.
  • Maintain consolidated visibility across security data sources and ensure the company has an effective daily security watch function.

Client Security Assurance & External Trust

  • Serve as the primary point of contact for client security inquiries, security questionnaires, due diligence requests, and customer security reviews.
  • Participate in client security calls, vendor risk assessments, procurement reviews, and enterprise customer security discussions.
  • Partner with Sales, Customer Success, Legal, Compliance, Product, Engineering, and IT to address client security concerns accurately and efficiently.
  • Translate technical security controls, risks, and remediation plans into clear, client-appropriate explanations.
  • Maintain reusable, approved responses and documentation for common client security topics, including data protection, encryption, access control, incident response, vulnerability management, business continuity, cloud security, and compliance.
  • Support customer-facing security communications during major incidents, material security events, audits, or significant security posture changes.
  • Identify recurring client security concerns and translate them into improvements in controls, processes, documentation, and internal security maturity.

Compliance, Reporting & Governance Support

  • Support compliance audits, risk assessments, and security reporting requirements, including SOC 2, ISO 27001, NIST, HIPAA, or other relevant frameworks.
  • Provide security evidence, operational metrics, and control documentation for audits and customer reviews.
  • Develop clear executive reporting on security posture, incidents, operational performance, key risks, and remediation progress.
  • Help define and maintain security policies, standards, procedures, and operational playbooks.
  • Work with leadership to ensure security operations align with business goals, regulatory expectations, and customer commitments.

Team Leadership & Cross-Functional Collaboration

  • Lead, mentor, and scale a high-performing team of security engineers, analysts, and external security partners.
  • Set clear priorities, operating rhythms, performance expectations, and development plans for the security operations team.
  • Partner closely with IT, DevOps, Engineering, Product, Legal, Compliance, Sales, and Customer Success to manage risk without slowing down the business unnecessarily.
  • Build a culture of accountability, responsiveness, continuous improvement, and practical security execution.
  • Act as a trusted advisor to internal teams on security operations, incident response, client security expectations, and operational risk.

Required Qualifications

  • 8+ years of total experience across cybersecurity, information security, security operations, IT, infrastructure, or related technical fields.
  • 3-5+ years of experience in a dedicated security operations leadership, incident response leadership, or security management role.
  • Strong hands-on experience with incident response, security monitoring, threat detection, threat intelligence, vulnerability management, and security investigations.
  • Experience managing or operating SIEM, EDR, SOAR, XDR, vulnerability management, cloud security monitoring, identity security, or related security platforms.
  • Experience securing cloud environments such as AWS, Azure, or GCP.
  • Strong understanding of modern attack vectors, adversary tactics, techniques, and procedures, including frameworks such as MITRE ATT&CK.
  • Familiarity with security and compliance frameworks such as NIST, ISO 27001, SOC 2, CIS Controls, OWASP, SANS, SSAE, ITIL, or similar standards.
  • Experience creating security operations metrics, dashboards, executive reports, and remediation tracking processes.
  • Strong written and verbal communication skills, with the ability to explain technical security issues to executive, technical, and non-technical audiences.
  • Ability to remain calm, structured, and decisive during high-pressure security events.

Client-Facing Security Requirements

  • Experience responding to enterprise security questionnaires, vendor risk assessments, customer audits, and client due diligence requests.
  • Ability to represent the security function in customer-facing meetings, procurement discussions, and executive-level security reviews.
  • Strong judgment in balancing transparency with confidentiality when discussing security controls, incidents, vulnerabilities, and internal processes with external parties.
  • Familiarity with common customer security review topics, including data privacy, encryption, access management, incident response, vulnerability management, cloud security, business continuity, SOC 2, and ISO 27001.
  • Ability to create clear, accurate, reusable security documentation and approved responses for client-facing use.

Preferred Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related field, or equivalent practical experience.
  • Security certifications such as CISSP, CISM, GCIH, GCIA, CRISC, ISSAP, OSCP, or similar.
  • Experience leading or working with a 24/7 SOC or managed security service provider.
  • Experience in a SaaS, cloud-native, enterprise software, fintech, healthcare, AI, or regulated technology environment.
  • Experience supporting SOC 2, ISO 27001, HIPAA, PCI, or other customer-driven compliance programs.
  • Experience building security operations programs from an early or scaling stage.
  • Experience partnering with Sales or Customer Success on enterprise customer security reviews.
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against athenago's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on athenago's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    athenago's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.