
Head of Information Security
Job description
About the role
Security at most companies is reactive. A checkbox for auditors. A speed bump for engineers. A department that says no. That is not what we are building. The role reports to the CFO and you will lead a high-functioning, mature, and global team located in the United States and South Korea, with end-to-end accountability for Security, IT, and Compliance. You will own Sendbird's comprehensive information security programs, manage and evolve our compliance frameworks, partner with engineering, and continuously build a security culture that is embedded in how we work, not bolted on as an afterthought. You will inherit a world-class program that is already SOC 2, HIPAA, ISO 27001, and ISO 42001 compliant, and your job is to take it further. You will champion defense-in-depth philosophy, ensuring a multi-layered approach to security that protects our customers, our data, and our reputation. You will also own global IT Operations, managing our IT infrastructure, networks, servers, and data, while supporting our expanding use of AI technology across internal systems. This is a hands-on builder role, not a talking-head role, and you will lead the team to own how we secure our infrastructure, respond to incidents, and hold our position against an increasingly complex threat landscape.
Key facts
What you'll do
Define and own the end-to-end information security and compliance strategy aligned with Sendbird's AI-first product vision and global enterprise customer needs.
Partner closely with engineering, product, and executive leadership to integrate security into the full product lifecycle, from design through deployment and operations.
Establish and evolve security policies, standards, and controls that reflect industry best practices and regulatory expectations.
Drive implementation of defense-in-depth protections for our communications platform, including identity, access management, network security, data protection, and secure AI system integration.
Lead incident response planning and execution, ensuring timely detection, containment, communication, and continuous improvement across global operations.
Own and advance our compliance programs, including SOC 2, HIPAA, ISO 27001, and ISO 42001, maintaining current certifications and readiness for audits.
Champion security culture and enablement, building training, tooling, and processes that make secure behavior the default for engineers and operators.
Oversee global IT infrastructure, networks, servers, and data management, ensuring resilience, performance, and alignment with AI-driven internal systems.
Monitor evolving threat landscapes and adversary techniques, translating insights into proactive controls, detection rules, and architectural improvements.
Act as the primary security and IT executive accountable for safeguarding AI innovation, protecting customer trust, and supporting enterprise sales and deployments.
Define and manage risk frameworks, ensuring clear communication of security posture and trade-offs to both technical and executive stakeholders.
Lead investigations and root cause analyses for security and IT incidents, driving corrective actions and accountability across cross-functional teams.
Establish metrics and reporting mechanisms to track security performance, compliance status, and operational health of critical systems.
Collaborate with procurement, legal, and vendor management to assess third-party risks and ensure security requirements are reflected in contracts and SLAs.
Requirements
You have built and run security programs at a B2B SaaS or cloud company, not just inherited them, with demonstrable experience managing compliance frameworks.
You can walk an engineer through a threat model and walk a CFO through a risk summary without losing either of them, translating technical risk into business impact.
You hold deep expertise in identity and access management, network security, data protection, and security architecture for distributed, cloud-native systems.
You understand how to build and operate security tooling and processes that scale globally, supporting rapid growth and multi-region deployments.
You have hands-on experience with incident response, forensics, and post-incident remediation in complex, production environments.
You are fluent in security standards and regulations relevant to enterprise communications and AI systems, including but not limited to SOC 2, HIPAA, ISO 27001, and ISO 42001.
You demonstrate a track record of influencing without authority, building trusted relationships with engineering, product, legal, and executive teams.
You bring a builder mindset, showing examples of security programs you have created, improved, or scaled from design through measurable outcomes.
Nice to have
Experience with AI systems security, including model risk, data privacy for training data, and secure prompt engineering workflows.
Background in highly regulated industries such as financial services or healthcare, with applicable lessons applied to communications platforms.
Practical notes
This is a full-time position based in San Mateo, California, United States.
The role involves global collaboration with teams in the United States and South Korea, requiring occasional travel and flexibility across time zones.
Employment eligibility to work in the United States is required, and sponsorship information will be discussed during the hiring process.
Applications will be reviewed on a rolling basis until the position is filled.