Hiring.Camp

Head of Security & Compliance

Casca

·

Jun 26, 2026

Location
San Francisco, US
Type
Full-time
Department
Legal
Experience
2+ years
Source
Y Combinator

Description

Why Casca?

Casca is building AGI for banking. We’re replacing decades-old legacy systems with AI-native technology that automates 90% of the manual work humans once had to do.

What you'll do:

  • Build security tooling & processes that engineers actually use. Create internal mechanisms for appsec, identity and access management, and threat detection that naturally integrate into how the team ships.

  • Manage, mentor, and grow our team of application security engineers. Mature our Secure SDLC, threat modeling, and vulnerability management processes to ensure our security posture matches our growing responsibility..

  • Secure the agent execution surface. Partner with Engineering and Product to establish robust security architecture for our AI-driven workflows, ensuring strict data privacy, mitigating AI-specific vulnerabilities, and maintaining safe agentic identity.

  • Drive customer trust. Partner with go-to-market and legal teams to support compliance and customer-driven initiatives. Own and expand our compliance roadmap (SOC 2, SOC 1, ISO 27001), while keeping guardrails pragmatic for a fast-paced startup.

  • Lead incident response and detection. Build the detection pipeline, act as the primary commander, and turn every event into systemic improvements.

What you'll bring:

  • 5+ years in progressive security roles, with at least 2+ years at a B2B tech, fintech, or highly regulated SaaS company.

  • Strong fundamentals in secure SDLC, cloud security (AWS/GCP), Web security, and DevSecOps practices.

  • Ability to develop lightweight, durable security policies, access controls, and data governance frameworks. A track record of building "practical security, not checkbox theater."

  • Nice to have: Experience securing LLM usage for both coding and in product use cases, and mitigating risks specific to agentic systems (e.g., unauthorized actions taken by autonomous agents, prompt injection, and data poisoning)

  • Proven track record of owning SOC 2 Type II and/or ISO 27001 compliance.

  • You can review a penetration test, debate architecture with a lead engineer, and present to a bank's CISO…all in the same day

  • You’re comfortable with incident response - calm, methodical, and effective under pressure; experience leading incidents end to end & driving the fixes that follow.

  • You thrive in ambiguity, know how to ruthlessly prioritize fixes to eliminate the highest risks first, and understand the balance between security and business velocity.

  • Experience in fintech or banking

What you'll get:

  • Impact & Ownership : A unique opportunity to shape the future of banking through AI, owning end-to-end product initiatives.

  • Collaborative Environment : Work alongside a talented and passionate team that values continuous improvement and knowledge sharing.

  • Competitive Compensation : Includes salary, benefits, and potential equity in a fast-growing startup.

  • Professional Growth : Access to resources and mentorship to expand your skill set, influence strategy, and accelerate your career.

  • Culture of Innovation : We encourage risk-taking, learning from failures, and pushing the boundaries of what’s possible in fintech.

As an early-stage company building at the frontier of AI, we work with high intensity and commitment. While schedules can vary by role/team, many weeks will demand extra focus, flexibility and time particularly during major launches and high impact sprints. We're seeking those who are aligned to and able to commit to that expectation.

Skills

AWSGCPSOCComplianceSOC 2ISO 27001

Similar Jobs

30

Head of Security

Snorkel AI·San Francisco, CA +1·Hybrid

3w ago

Head of Security

Exa·San Francisco, California·Onsite

1mo ago

Head of Security

Verse Medical·New York City·Hybrid

1mo ago

Head of Security

Tremendous·US +1·Remote

2mo ago

Head of Security

Profound·New York·Onsite

2mo ago

Head of Security

Kontigo·San Francisco, California·Remote

2mo ago

Head of Security

Tatari·San Francisco, California +2

4mo ago

Head of Security

Tatari·New York, US +2

4mo ago

Head of Security

Tatari·Los Angeles, California +2

4mo ago

Head of Security

Fresha·London·Onsite

5mo ago

Head of Security

Protege·Remote·Remote

5mo ago

Group Head of Security

Culina Group·Warrington, UK

1d ago

Head Of Security - Base44

Wix.com·Tel Aviv, Israel

3d ago

Head of Security Team -NEW

Deutsche Telekom IT Solutions·Budapest, Hungary·Hybrid

1w ago

Head of Security Operations Mexico

Ericsson·México D.F., MX

1w ago

CSIS Head of Security: Asia South & Japan, Asia North and Australia (JANA) Clusters

citibank·Sydney, NSW

1w ago

CSIS Head of Security: Asia South & Japan, Asia North and Australia (JANA) Clusters

Citi Bank·2 PARK STREET SYDNEY, Australia·Hybrid

1w ago

Head of Security Incident Management

Wpp·London

2w ago

Head of Security (f/m/d)

1KOMMA5˚·De +1·Remote

4w ago

Head of Security (f/m/d)

1KOMMA5°·Hamburg +2

4w ago

Sr Director, IT Head of Security Operations

Gilead·US - CA - Foster City, US·Onsite

1mo ago

Sr Director, IT Head of Security Operations

Gilead Sciences·US - CA - Foster City, US·Onsite

1mo ago

Head of Security Operations & Engineering - Flutter Functions, Hybrid

Flutterbe·London, UK +2·Hybrid

1mo ago

Head of Security Engineering (DevSecOps & CISO)

Smarkets·London·Hybrid

1mo ago

Global Head of Security Detection and Response

Ing·Madrid

2mo ago

Head of Security GRC

DriveWealth·AMER-US-Remote, Austin·Remote

2mo ago

Head of Security Engineering

January·New York City·Hybrid

2mo ago

Head of Security & AI Governance

Flip·Los Angeles +1·Onsite

2mo ago

Head of Security & Compliance

Aerospike·Mountain View, CA +1·Remote, Hybrid

3mo ago

SVP, Head of Security Technology

Berkley·Wilmington, DE

3mo ago
Head of Security & Compliance at Casca | Hiring.Camp