Jobs · Information Technology

Director, Corporate Security

A16Z GAMES · United States · Today
RemoteRemoteInformation Technology$237k–$290k/yrFull-time

About the role

The Director of Corporate Security will assess the current state of Komodo’s security environment and drive strategic improvements across the company. This role will focus on protecting employee systems, identity, devices, endpoints, internal networks, business applications, vendor tools, and workforce-related security risk.

Responsibilities

  • Own corporate security strategy and execution across identity and access management, endpoint and device trust, internal SaaS security, data-sharing controls, workforce risk, and incident response for corporate assets.

  • Build and maintain a multi-year corporate security roadmap, prioritized by risk, business context, and resource constraints. Present progress and risk posture clearly to the Komodo Executive Team.

  • Lead security operations across existing tooling: Our existing EDR/MDR, email security, SIEM/monitoring tools, and evolving vendor stack. Own response coordination, remediation tracking, and escalation.

  • Partner with IT to strengthen provisioning and deprovisioning, access reviews, device management, and internal network and application security controls. Hold the line on offboarding.

  • Establish practical guardrails for internal enterprise AI use — approved-tool standards, SSO and domain capture, RBAC, retention, redaction, logging, and usage expectations.

  • Partner with Product Security, Compliance, Procurement, and Legal on vendor security reviews, risk assessments, privacy and security questionnaires, and security requirements for strategic software and AI vendors.

  • Build and lead a high-performing corporate security team. Hire well, develop people, set clear expectations, and hold the team to a high standard of execution and accountability.

  • Represent corporate security in audits, investor diligence, customer security reviews, and regulator inquiries as needed.

Requirements

7+ years of experience operating at the Director level or equivalent in corporate security, IT security, or security operations — with demonstrated accountability for program ownership, team leadership, and executive stakeholder management.

Experience across both mature, compliance-minded environments (public company, regulated industry, or enterprise scale) and high-growth startups where you had to build from scratch.

5+ years of experience leading, managing, or developing high-performing teams.

Proven track record building or significantly maturing a corporate security program at a startup or scale-up, where you owned the roadmap, made prioritization calls with limited resources, and shipped durable results.

Deep fluency in corporate security fundamentals: identity and access management, endpoint security, device trust, internal network security, SaaS security posture, incident response, and access governance.

Hands-on experience with enterprise security tooling — SIEM tools, modern EDR/MDR, modern email security, IAM platforms, and device management.

Experience running a security program in an environment subject to external audits, SOC 2, or similar compliance frameworks. Comfort with auditor-ready documentation, evidence collection, and control testing.

Strong cross-functional leadership. You have worked effectively across IT, Engineering, Compliance, Legal, Procurement, People, and business teams — and you know how to get things done through influence, not just authority.

Clear, confident communicator at the executive level. You can translate technical risk into business language and present a credible security posture to CFOs, boards, and enterprise customers.

Experience in healthcare, life sciences, or other sensitive-data environments handling PHI, PII, or proprietary clinical/commercial data.

Experience communicating risks, gaps, progress, and recommended actions clearly to leaders and stakeholders with different technical backgrounds.

Experience supporting audits, internal investigations, vendor reviews, security questionnaires, and environments that handle sensitive data.

Strong judgment, leadership presence, and execution discipline, with the ability to stay calm under pressure and move work forward consistently.

Expectations of AI Use in This Role: Drive secure enterprise AI adoption by owning governance for approved tools — SSO, domain capture, RBAC, retention controls — that reduce shadow IT without slowing the business. Establish practical, enforceable controls for internal AI use cases: data handling standards, logging, redaction, access review, and a process for evaluating new tools before they proliferate. Use AI in your own workflow to improve IT Security operations, documentation, risk prioritization, and incident triage. Maintain clear human accountability for every decision.

Qualifications

Experience scaling a security program through a Series C–E or pre-IPO stage, with direct exposure to investor diligence, SOC 2 Type II, or early public-company readiness.

Familiarity with Apple device management and mixed-device enterprise environments.

Experience with security automation and tooling that improves team efficiency, detection quality, and response times.

Background in offboarding and access governance at distributed organizations with significant SaaS sprawl.

Experience evaluating, selecting, and managing enterprise security vendors through procurement cycles.

Similar jobs