Head of Security
You find the fit. Your agent handles the form.
Choose a role or send your matches to the agent. It uses your original résumé and saved details, applies in the cloud, and keeps every result in one place.
About this role
Employer-provided description, formatted for easier reading.
About F2
F2 is redefining how the financial sector operates by bridging the gap between legacy workflows in institutional finance and the future of AI-driven efficiency. While large financial firms comprise the backbone of the economy, their front and middle-office processes are still manual, spreadsheet-heavy, and fragmented.
F2 is the leading vertical AI platform purpose-built for private markets and commercial banking. We transform dense, unstructured deal materials into auditable, decision-ready insights in minutes. This is not generic AI tooling.
It is core infrastructure embedded directly into underwriting, credit, and portfolio workflows. We are the only fully vertical platform in this space with meaningful, proven revenue and real product–market fit.
The Role
We are hiring our first security engineer. Our customers are private credit funds, commercial banks, and private equity firms, and they trust us with credit agreements, financial models, and deal materials that never leave their four walls otherwise. Security is not a compliance checkbox for us; it is the product.
You will own security at F2 end to end: the multi-tenant platform, the cloud infrastructure, the AI and agent execution paths, our SOC 2 program, and the way the engineering team builds. This is a hands-on, engineer-first role. You will also be the person our customers' security teams talk to.
You will report to the co-founder and CEO and operate with a high degree of independence. There is no security team to inherit; you set the bar and build the function.
WHAT YOU'LL DO
- Own the security of a multi-tenant AI platform. Lead the efforts in hardening tenant isolation across Postgres, object storage, vector search namespaces, and per-tenant sandboxes.
- Secure the AI and agent surface. Threat-model LLM-driven workflows. Design controls that hold up when the agent is the one making requests.
- Own cloud and infrastructure security. IAM and least privilege across vendors; network boundaries; secrets management; logging and detection; backup and recovery.
- Run the SOC 2 program’s technical controls as an engineer. Build the controls into the pipeline and the platform so compliance is a byproduct of how we work.
- Build detection and incident response. Set up alerting on the signals that matter, run tabletop exercises, and lead real incidents end to end, including customer communication and postmortems.
- Answer to customer security teams. Co-own questionnaires with our CRO, penetration test coordination and remediation, architecture reviews, and security addenda for enterprise deals with banks and funds.
- Raise the bar for the engineering team. Set secure-by-default patterns, write the guidance engineers and coding agents actually follow, and teach through review. Hire and lead the security team when the business needs it.
WHAT YOU BRING
- Hands-on security engineering depth. 8+ years in security with a strong software engineering background. You have shipped production code, found real vulnerabilities in real systems, and fixed them. You are comfortable in Python and TypeScript.
- Cloud and application security expertise. Practical, recent experience securing AWS-hosted services and modern web applications: identity and access, secrets, network boundaries, CI/CD, dependency and supply-chain risk, and multi-tenant SaaS data isolation.
- AI/LLM security fluency. Understanding of prompt injection, tool and agent authorization, sandboxing untrusted execution, and the data-handling implications of sending customer content to model providers.
- Compliance as an engineering problem. You have owned or been a primary contributor to SOC 2 Type II (or ISO 27001) from the engineering side and know the difference between controls that work and controls that produce evidence.
- Enterprise customer experience. You have sat across enterprise security teams, handled questionnaires and pen test findings, and closed deals by being credible and direct.
- Independent operator. You are comfortable being the only security person in the building, deciding what matters most, and executing without a mandate handed to you.
- Bias to build. You would rather write the detection rule, the scanner integration, or the migration than write the policy document describing it.
WHY F2
- Security is a core product requirement for our customers, not a cost center. Your work is directly tied to revenue.
- You define the function from scratch, with the founders’ backing and access to the whole codebase.
- Small, senior, high-velocity team where your decisions land in production the same week.
Location
San Francisco
Employment Type: Full time
Location Type: Hybrid
Department: Engineering, Product, Design (EPD)
Compensation: $250K – $400K • Offers Equity
The total rewards package at F2 includes base salary, equity (stock options), and benefits.