
Head of Security & Compliance
- SOC2
- GDPR
- ISO 27001
- AI
- Pub/Sub
- HIPAA
- Penetration Testing
- Bug Bounty
- GCP
- Cloud Run
- Firestore
- IAM
- VPC
- Secrets Management
- GitHub
- Incident Response
- OpenTelemetry
- Devops
- CI/CD
- SAST
- DAST
- GitHub Actions
- Snyk
- Dependabot
- SIEM
- LangSmith
- Firebase Auth
- KMS
- TLS
- OAuth
- Threat Modeling
- FastAPI
- OAuth2
- Postman
Role Overview
You will be theguardian of trust at Vibecoderz. Developers will only commit their code, data, and learning journeys into a platform they know issecure, private, and compliant. You’ll build Vibecoderz’end-to-end security posture, ensurecompliance with global frameworks (SOC 2, GDPR, ISO 27001), and proactivelydefend against threats like prompt injection, data poisoning, and model misuse.
This is not just about firewalls and audits. This is about makingsecurity invisible but unbreakable — so users feel flow, while knowing their data and code are safe.
Key Responsibilities
Security Architecture
Define and enforce Vibecoderz’security-first architecture across all layers (frontend, backend, AI, infra).
Design secure patterns forAI agent communication (A2A via Pub/Sub) to prevent leakage or injection attacks.
Compliance & Certifications
Lead Vibecoderz throughSOC 2 Type II, GDPR, ISO 27001, HIPAA (where relevant).
Own documentation, audits, and compliance playbooks.
Application Security
Implementsecure coding standards, static/dynamic analysis pipelines, and dependency scanning.
Run regular penetration testing and bug bounty programs.
Cloud & Infrastructure Security
Secure GCP stack (Cloud Run, Firestore, Pub/Sub, Cloud Tasks, Workflows).
Manage IAM policies, VPC service controls, and secrets management.
AI/LLM Security
Developguardrails for LLMs against prompt injection, malicious payloads, or unsafe content.
Build continuousAI evals for hallucination, bias, and red-team attacks.
Data Privacy & Governance
Ensure secure handling ofdeveloper data, GitHub integrations, and learning graphs.
Definedata retention, anonymization, and encryption-at-rest/in-transit policies.
Monitoring & Incident Response
Build aSecurity Operations Center (SOC) playbook.
Implement observability pipelines (OpenTelemetry + GCP Trace) for security events.
Ownincident response, from detection → containment → resolution.
Cross-Functional Leadership
Partner with CTO/DevOps to embed security into CI/CD.
Partner with CPO/PM to balanceUX speed with security tradeoffs.
Mentor engineers on“security-as-craft” culture.
Success Metrics
90 Days (Probation):
Establishsecure CI/CD pipelines with SAST/DAST checks.
Define and document Vibecoderz’security baseline (policies, access, data handling).
Run the firstred-team simulation against TutorAgent + artifacts.
12 Months:
AchieveSOC 2 Type II certification.
Maintainzero P1/P2 security breaches.
Achieve99.99% uptime without security-related downtime.
Establish acontinuous security monitoring dashboard visible to leadership.
Must-Haves
10+ years in security engineering or compliance leadership inSaaS or developer platforms.
Proven success in achievingSOC 2 / ISO 27001 / GDPR compliance.
Strong background incloud-native security (GCP preferred).
Expertise inapplication security, IAM, VPC, encryption, and key management.
Experience designingsecurity frameworks for AI/LLM products.
Nice-to-Haves
Prior experience indeveloper-first SaaS.
Contributions tosecurity open-source projects or standards.
Experience withfederated identity, SSO, and enterprise compliance.
Background inoffensive security / red-team practices.
Tech Stack Visibility
Infra & Cloud: GCP (Cloud Run, Firestore, Pub/Sub, Cloud Tasks, Workflows)
CI/CD Security: GitHub Actions, Snyk, Dependabot
Observability & Monitoring: OpenTelemetry, GCP Trace, SIEM tools
AI Security: LangSmith/Langfuse evals, custom LLM guardrails
Compliance: SOC 2, ISO 27001, GDPR frameworks
Identity & Access: Firebase Auth, IAM, VPC Service Controls
Encryption: KMS, TLS 1.3, AES-256
Assessment
Objective: Validate ability to designsecure architecture + compliance strategy for Vibecoderz.
Assessment (3-Part):
Security Design (Written)
Draft asecurity architecture doc for Vibecoderz’ core flow:Text → Course → Artifact → Mini-App.
Must include:
Data encryption flow (at rest + in transit).
Access control model (OAuth + Firebase Auth).
AI guardrails (prompt injection, unsafe outputs).
Threat modeling for Firestore + Pub/Sub.
Compliance Playbook
Outline a12-month plan to achieve SOC 2 Type II certification.
List top 5 risks for Vibecoderz’ compliance and your mitigation plan.
Coding Assessment
Implement asecure FastAPI microservice with:
OAuth2 authentication.
Rate limiting (per-user).
Secure logging (PII masked).
Deploy toCloud Run with IAM policies.
Deliver aPostman collection with working requests.
Deliverables:
Written security design doc (3–4 pages).
Compliance roadmap (slide deck or doc).
GitHub repo with code + deployment instructions.
Head of Security & Compliance · Gradientflo Labs