Match your resume skills with our AI powered skill match!
Questions interviewers often ask for this role, with sample answers.
Upload your resume and we draft a letter for this exact role, tailored to what it asks for.
You will serve as the dedicated security lead, managing the day-to-day security and compliance program including SOC 2 and ISO certifications. You will also oversee AWS remediation, vulnerability management, and shape the security strategy for AI-native systems.
UserGems is the AI Command Center for outbound and ABM. Think of us as the ‘brain’ behind your go-to-market. We capture account & contact data and buying signals to help companies know who to target, when, and why. Then, take the next actions via humans or AI agents to run personalized outbound and ABM at scale.
UserGems has generated billions in pipeline and revenue for hundreds of start-ups and public companies. Companies like Hubspot, Workday, Crowdstrike, Mimecast, UserTesting, SAP, Outreach see more than 15X ROI in closed-won revenue from UserGems.
Operate UserGems' security and compliance program day-to-day, partnered with the Sr. Director on direction and strategy.
UserGems is an AI platform helping sales and marketing teams double pipeline impact. Our AI agent Gem-E turns signals from CRMs, buying intent, and public data into precise outreach - generating $4B in pipeline and $950M in revenue for customers like CrowdStrike, UserTesting, and SAP LeanIX (15X+ ROI).
UserGems is a ~70-person company with around 25 engineers across Europe and 45 team members in sales and marketing based in the U.S. Several of our customers are top-tier security companies themselves (e.g. CrowdStrike), so our own security posture directly influences how fast revenue can move.
You will be UserGems' single dedicated security person, taking over the operational majority of the security work the Sr. Director currently owns. This is a compliance-led role with hands-on operational components - heavy on SOC 2 / ISO ownership, customer security reviews, day-to-day program operations, and Drata-driven remediation in AWS. Compliance is the primary focus and over time you'll own the full technical scope described below as well. The Sr. Director approves direction; you propose, shape, and execute the program. Cadence is a bi-weekly 1:1 with the Sr. Director plus a weekly work discussion, same as every UserGems employee.
UserGems' security program is in great shape - no fires to put out. SOC 2 Type II is in place for years already, all compliance monitoring is centralized in Drata, scanner findings auto-flow into Linear and are auto-triaged by an in-house automation, and CrowdStrike Complete (managed MDR) handles runtime protection. There's no on-call rotation at UserGems - incident response is a whole-team effort, and the Sr. Director continues to cover during your time off.
The Sr. Director currently runs the whole program in roughly 25% of one person's time, so a dedicated owner has real headroom. Expect your time to split roughly 2–3 days per week on baseline operations and the remainder on new initiatives. The biggest near-term programs are ISO 27001 and likely ISO 42001 (AI management) - both held back today because no one has the dedicated capacity to drive them. That's the gap you fill.
UserGems is an AI company, and AI risk shows up in nearly every customer security review. A meaningful portion of this role is shaping how a modern, AI-native company secures both its product and its own internal AI usage - not just answering questionnaires about it.
We're already EU AI Act compliant - so you're extending a working baseline, not starting from zero.
You'll own:
Non-negotiable:
Strongly preferred - you'll likely grow into the gaps:
We're a lean team where everyone owns their work end-to-end. We trust people to manage their own time, and we expect real output plus the basic async hygiene that makes it work: flag blockers early, surface progress, don't go dark.
This is a high-commitment role, not a standard 9-to-5. If you're looking to coast, this isn't the right fit.
Target annual compensation range for the role is €80k €100k.Final seniority leveling and compensation package will be determined based on commensurate experience, qualifications, and demonstrated ability to perform in the senior level role.
Why you should join:
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Featuring 220,015+ Jobs in Security Engineer
Answer easy questions
220,015+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”