Togal AI - Director of Security
Requirements
• Must-haves: • Experience running a SOC 2 or similar compliance program end-to-end, including audit management and tooling (Vanta or equivalent). • Comfortable being the primary voice in customer-facing security conversations — you can sit across from a customer's CISO and hold your own. • Solid grounding in cloud security fundamentals (IAM, configuration management, logging) rather than just general cloud familiarity. • Enough hands-on technical depth to lead an incident when one occurs — you don't need to be a forensics specialist, but you should be credible investigating and coordinating a response. • Comfortable operating independently at an early-stage company, building the function as you go rather than stepping into an existing team or playbook. • Nice-to-haves: • Experience standing up a security/trust function from scratch at a startup or scale-up. • Background in construction tech or B2B SaaS. • Familiarity with email authentication and phishing/account-compromise forensics (DKIM/SPF/DMARC). • Experience evaluating or managing an MDR/IR retainer relationship. • You'd be Togal's first dedicated security hire, with the mandate to build the function the way you think it should work rather than inherit someone else's backlog. You'll be the person enterprise customers trust when security becomes a deal-maker or deal-breaker, work closely with the CTO and CEO, and have a direct hand in the deals where security is the deciding factor.
Responsibilities
• Own Togal's SOC 2 Type II program end-to-end — evidence collection, audit management, and control ownership in Vanta — so it's audit-ready year-round, not just before an audit. • Turn around customer security questionnaires and vendor security reviews quickly and accurately. • Be Togal's front-line security contact for customers and prospects, including calls with customer-side CISOs and security teams during deal cycles and MSA negotiations. • Design a written incident-response and notification policy — clear triggers, timelines, escalation paths, and roles — that's actually followed, replacing today's ad hoc handling by the CTO and CEO. • Lead incident response when something does happen: containment, investigation, and coordinating any outside help needed (e.g., an MDR/IR retainer for surge capacity) — this is "own it when it happens," not the day-to-day center of the role. • Evaluate whether to buy, outsource, or build additional security monitoring — assess managed detection/SIEM options against what we actually need before committing engineering time to standing anything up ourselves. • Assess and tighten cloud security posture (IAM, configuration, logging) alongside the CTO and engineering team. • Partner with Legal and the CEO on breach determination and external communication, as a defined process rather than a one-off scramble.
Apply in one click
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT