Please mention DailyRemote when applying
See how much of this job your resume covers, and what’s missing.
Want a recruiter to go through it line by line?
Get professional reviewUpload your resume and we draft a letter for this exact role, tailored to what it asks for.
You will own the end-to-end security and infrastructure operations, including detection engineering, incident response, and cloud architecture hardening. You will also lead compliance efforts and manage the security of the company's blockchain treasury layer while working directly with the CTO.
Location: Remote - United States only (must reside in the U.S.)
Team: Security & Infrastructure
Reports to: CTO (you'll work directly with the CTO)
Rise is a global payments and payroll platform built for the way modern teams actually work - across borders, currencies, and rails. We make it possible for companies to pay full-time employees, contractors, and freelancers anywhere in the world, in either fiat or digital assets, with the compliance, tax, and identity infrastructure handled underneath.
Our stack runs on Google Cloud Platform (Cloud Run, BigQuery, Google SecOps), with MySQL, a Node.js / TypeScript application layer, and Cloudflare (including Cloudflare Pages) at the edge. Settlement for stablecoin payments runs on Ethereum and EVM-compatible networks through our own smart contracts and treasury wallets. Because we move money for real people, security and correctness are first-order concerns in everything we ship.
We're a lean, high-trust, high-ownership team. Because we move real money for real people, we hold a high bar for correctness, security, and accountability - the work is meaningful precisely because the stakes are real. We value:
Ownership over hand-offs. You'll own security and infrastructure end to end and have the autonomy that comes with that.
Security as a default, not a phase. Handling funds and personal data means security thinking is part of every decision, not a box checked at the end.
Directness and low ego. We give and receive candid feedback, write things down, and prefer clarity over politics.
AI-first in how work gets done. We use AI agents and assistants as a core part of daily work - writing and reviewing code and Terraform, triaging alerts, investigating logs, drafting runbooks and policies, and automating the toil that would otherwise eat the day. We expect everyone to work this way and to keep getting better at it.
Remote-first discipline. We're a globally distributed team spread across time zones around the world, and we communicate asynchronously with a bias toward documentation and reproducibility.
Working directly with the CTO, you'll own security across Rise's cloud, edge, and on-chain surfaces, and the infrastructure operations that keep production healthy. You are the first dedicated security role at Rise, but you are not starting from zero: you inherit a working program - SOC 2 certification, Google SecOps, Terraform-managed GCP, Cloudflare at the edge, and established on-chain treasury controls - and your job is to own it, harden it, and take it further. Security is the center of gravity for the role, with infrastructure and reliability close behind, on a mostly serverless stack designed to keep operational overhead low.
This is a hands-on leadership role. You will not manage people, but you are the security leader for the company: you set security direction, make the calls on risk, represent Rise to auditors, partners, and customers, and are the person engineering and leadership turn to when a security or infrastructure question needs an answer. It is a builder's seat, not an advisory one - you'll harden what exists, design what's missing, and ship it yourself.
Security operations (SecOps)
Own and run Rise's security operations: detection engineering, alert triage, investigation, and response across GCP, Cloudflare, GitHub, and Google Workspace.
Build and tune detections in Google SecOps (Chronicle) over Cloud Audit Logs, load-balancer and Cloud Run request logs, Cloudflare firewall logs, and application telemetry - covering anomalous traffic, abuse, credential misuse, insider risk, and scanning - and keep log ingestion and feed health reliable.
Establish and track behavioral baselines so new or escalated activity stands out from normal operations.
Own incident response: detection, containment, forensics, remediation, and blameless post-mortems - and build the tooling and runbooks so we respond faster next time.
Run tabletop exercises and game days so our response is proven, not assumed.
Build AI-driven security automation: agent-based log review, alert triage and enrichment, and scheduled investigation passes over GCP, Cloudflare, and GitHub activity, so a team of one can cover what used to take a SOC shift.
Security posture & architecture
Own Rise's security posture across cloud, edge, data, and on-chain surfaces.
Design and enforce a zero trust access model: identity-aware access to production and internal tools, device and context-based policy, no implicit trust based on network location.
Own secrets management and access governance: least-privilege IAM, separation of duties, network segmentation, and audit logging as enforced defaults across production systems.
Harden the GCP footprint (SecOps, Security Command Center, Cloud Run, IAM, VPC, BigQuery, Secret Manager) and Cloudflare edge configuration (WAF, DNS, rate limiting, bot management).
Protect sensitive customer, payroll, and identity data - classification, encryption, retention, and access controls.
Blockchain & treasury security
Own the security of Rise's Ethereum and EVM treasury layer: treasury and ramp wallets, multisig (Safe) owners and thresholds, admin roles on our access-control contracts, and signer and key custody. Smart contract development, auditing, and on-chain monitoring are owned by the blockchain team; you partner with them on controls and custody.
Secure the relayer and off-chain services that submit transactions, including key management and transaction signing controls.
Governance, risk & compliance
Own Rise's compliance program: maintain our SOC 2 certification and lead the path to ISO 27001 and PCI DSS - control ownership, evidence collection, gap assessment, and audit coordination - and represent security to auditors, partners, and customers.
Own security policy, vendor and third-party risk review, and access review cycles.
Run security awareness and secure-development enablement for the engineering team.
Own data privacy risk - data residency, subject-access and deletion requests, and GDPR / CCPA obligations across the platform.
Infrastructure operations & platform reliability
Own the infrastructure operations behind code releases: run and improve the deployment pipelines that ship our fleet of Cloud Run services to production, and be accountable for safe, repeatable releases (rollouts, rollbacks, and release hygiene).
Provide day-to-day operational support for our production infrastructure - keeping services healthy and available, responding to operational issues, and doing the maintenance, upgrades, and toil-reduction that keep the platform running.
Build and maintain CI/CD and Terraform-managed infrastructure on GCP, with security controls built into the pipeline rather than bolted on.
Improve observability - logging, metrics, tracing, and alerting - so we find problems before customers do.
Be accountable for reliability - capacity, backups, and on-call - for systems that move money, on a mostly serverless architecture designed to keep operational load and toil low.
Operate and continuously improve our disaster recovery capability. Own our RTO/RPO targets, manage database backup and point-in-time recovery for our managed MySQL databases, maintain and refine failover procedures and DR runbooks, and run regular restore drills and game days so recovery stays proven, not assumed.
Keep the infrastructure upgraded over time.
Required
Work authorization. Applicants must be legally authorized to work in the United States on a full-time basis and reside in the U.S. The company will not sponsor applicants for work visas for this position.
Background check. Must pass a comprehensive 7-to-10 year background check, including criminal, credit, and employment verification.
Experience. 10+ years in security engineering and infrastructure, including at least 3 years owning a security program or function end to end, with the judgment to set direction as Rise's first dedicated security leader.
Google Cloud Platform. Substantial, hands-on GCP experience - IAM, VPC and networking, Cloud Audit Logs and monitoring, Security Command Center, Secret Manager, Cloud Run, BigQuery, and Google SecOps (Chronicle). This is a GCP role; you should already operate GCP in production.
Security operations and incident response. You've built and run detection, triage, and response as a day-to-day discipline in a SIEM (Google SecOps / Chronicle preferred), you can turn logs into signal and signal into alerts people act on, and you've been in the room when something was on fire and helped put it out.
Terraform. You manage cloud infrastructure as code in Terraform and are comfortable owning the modules, state, and pipelines that apply it.
Zero trust. You have designed and implemented zero trust access (identity-aware proxies, Cloudflare Access / BeyondCorp-style controls, device posture, context-aware policy) for production and internal systems.
Security fundamentals. IAM and least privilege, secrets/key management, network security, cryptography basics, and data protection.
Code literacy. Comfort reading and reasoning about code in a Node.js / TypeScript and MySQL environment (you don't need to be a full-time developer).
CI/CD. Hands-on experience owning deployment pipelines and embedding security controls into how we build and ship.
Production operations. Willingness to carry production operations and on-call for a small set of VMs and a mostly serverless GCP footprint alongside the security work.
AI-first workflow. You already use AI tools (Claude Code, Copilot, or similar) every day to write and review code, investigate incidents, draft documentation, and automate repetitive work - and you can show how it has multiplied your output. This is how work gets done at Rise; it is not optional.
Compliance. You have carried at least one of SOC 2, ISO 27001, or PCI DSS through certification and recurring audits as the control owner, and know what evidence collection actually costs. Experience taking a company from SOC 2 to ISO 27001 or PCI DSS is a strong plus.
Preferred
Google Cloud certifications. Google Cloud Professional Cloud Security Engineer, plus any of Professional Cloud Architect, Professional Cloud Network Engineer, or Professional Cloud DevOps Engineer.
Ethereum / EVM security. Wallets, keys, and signers; multisig (Safe) administration; and the threat landscape around stablecoin settlement.
Regulated industry. Experience in fintech, payments, or another regulated, funds-handling environment.
Nice to have
Security clearance. Active or previous U.S. Government security clearance.
Military service. U.S. military experience, particularly in cybersecurity, signals, or intelligence roles.
Additional certifications. CISSP, GCIH, GCFA, GCDA, CCSP, or similar.
Cloudflare depth. WAF rules, Workers, Zero Trust, and Logpush beyond the basics.
Base salary: $230,000-$275,000, commensurate with experience.
Meaningful equity in a growing company.
Generous healthcare benefits - medical, dental, and vision coverage for you and your family.
Unlimited PTO and a flexible work schedule - we care about outcomes, not hours.
401(k) with a 3% company grant - not a match. Rise contributes 3% of your salary to your 401(k) every pay period whether or not you contribute a dollar yourself. Add your own contributions on top and you keep both.
Fully remote within the United States.
You'll be the person who owns security operations and reliability for a platform that moves real money across borders and on-chain. It's a role with genuine scope, genuine autonomy, and genuine stakes - GCP security, SecOps, blockchain treasury security, compliance, and production ownership, all in one seat, with a direct line to the CTO.
You'll be the first dedicated security leader at Rise, inheriting a real program and the full authority to shape where it goes next.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Featuring 212,266+ Jobs in Software Development
Answer easy questions
212,266+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”