Head of Information Security
About the Role
We're an AI company handling enterprise-grade conversations at global scale, and our customers trust us with data that matters. That trust isn't a nice-to-have—it's a competitive differentiator. Security here means being a partner to the business, not a blocker. It means building systems that scale as fast as we do and understanding that being a 24/7 global platform demands proactive security thinking—not just incident response. We're looking for a practitioner who rolls up their sleeves, builds programs that work well, and earns trust across the engineering org by being someone people want to work with.
This role reports to the CFO. You'll lead a high-functioning, mature, and global team located in the United States and South Korea, with end-to-end accountability for Security, IT, and Compliance, ensuring these functions work in harmony to support our global scale. You'll inherit a world-class program that's already SOC 2, HIPAA, ISO 27001, and ISO 42001 compliant. Your job is to take it further by owning Sendbird's comprehensive information security programs, managing and evolving our compliance frameworks, partnering with engineering, and continuously building a security culture embedded in how we work—not bolted on as an afterthought. You'll also own global IT Operations, managing our IT infrastructure, networks, servers, and data while supporting our expanding use of AI technology across internal systems.
Responsibilities
- Own the program: Maintain and continuously improve Sendbird's information security program—policies, processes, and controls that hold up under scrutiny.
- Drive continuous control monitoring to ensure alignment with audit frameworks (SOC 2, HIPAA, ISO 27001, ISO 42001).
- Translate complex compliance requirements (HIPAA, GDPR, CCPA) into practical, actionable programs.
- Evaluate and adopt AI-powered security tooling to stay ahead of evolving threats.
- Partner with the business: Work directly with the CTO and engineering teams to embed security into the product development lifecycle.
- Raise risk awareness across business stakeholders without creating friction.
- Collaborate with senior leaders to ensure data privacy protocols align with our use of AI tools.
- Lead the team: Manage and develop a global lean security team, ensuring each hire advances the program's goals.
- Act as a player-coach—this isn't a delegator role; you're hands-on in the work.
- Respond and improve: Establish and maintain incident response protocols that are fast, clear, and practiced.
- Continuously strengthen the security posture of a 24/7 global platform.
- Turn every incident into a lesson and every lesson into a control.
- Champion a defense-in-depth philosophy, ensuring a multi-layered approach to security.
- Scale global internal business systems to maintain trust with demanding enterprises.
Requirements
- 10+ years of combined experience across security management, IT operations, compliance, or consulting.
- 3+ years leading or managing a team, including information security planning, scheduling, and resource monitoring.
- Hands-on experience with audit frameworks: ISO 27001, SOC 2, HIPAA, and/or GDPR.
- Background in global B2B technology, SaaS, or cloud-based businesses.
- Proven track record managing security incidents end-to-end.
- Strong understanding of security and compliance challenges unique to AI/LLMs.
- Bachelor's degree in Information Security, Computer Science, MIS, or related field.
Qualifications
You might be this person if you:
- Have built and run security programs at a B2B SaaS or cloud company—not just inherited them.
- Can walk an engineer through a threat model and a CFO through a risk summary—without losing either.
- Are well-versed in compliance frameworks (ISO 27001, SOC 2, HIPAA, GDPR).
- Have managed or mentored a global security team and take pride in developing people.
- Are organized, methodical, and detail-oriented with strong analytical skills.
- Thrive in ambiguity and build structure where none existed.
- Instinctively fix, document, and improve when something goes wrong—not assign blame.
- Treat security as a conversation with the business, not a monologue.
- Have started using AI tools to work faster and are curious about their impact on security programs.
Added value:
- Security certifications: CISM, CISA, CISSP, or equivalent.
- Experience at a global company operating across multiple time zones and regulatory environments.
Benefits
- Medical, dental, and vision coverage: 100% premium coverage for employees and ~80% for dependents.
- Generous time off: 20 days PTO, 13 company holidays, 7 sick days, 2 rest & rejuvenation days, 1 volunteer day, and your birthday off.
- $3,500 annual "Be Your Best Self" boost for growth-related expenses (gym, therapy, courses, etc.).
- Parental leave for all new parents.
- 401(k) with auto-enrollment, flexible contributions, and Vanguard investment access from day one.
- HSA & FSA options for healthcare, dependent care, and commuter expenses.
- Life & disability coverage: 2x salary life insurance and AD&D, plus fully paid short- and long-term disability.
- AI-first environment: Enterprise access to top LLMs (Claude, ChatGPT, Gemini) and coding tools.
Pay
A reasonable estimate of the current salary range for this role is $280,000 – $320,000 (San Francisco Bay market). Final compensation considers skill sets, experience, licensure, certifications, and business needs.
Schedule
Flexible work policy with a minimum requirement of three days per week in the office for collaboration and relationship-building. Some roles may require a more frequent in-office schedule.