Head of Security & Compliance
WHY CASCA?
Casca is building AGI for banking. We’re replacing decades-old legacy systems with AI-native technology that automates 90% of the manual work humans once had to do.
WHAT YOU'LL DO:
- Build security tooling & processes that engineers actually use. Create internal mechanisms for appsec, identity and access management, and threat detection that naturally integrate into how the team ships.
- Manage, mentor, and grow our team of application security engineers. Mature our Secure SDLC, threat modeling, and vulnerability management processes to ensure our security posture matches our growing responsibility..
- Secure the agent execution surface. Partner with Engineering and Product to establish robust security architecture for our AI-driven workflows, ensuring strict data privacy, mitigating AI-specific vulnerabilities, and maintaining safe agentic identity.
- Drive customer trust. Partner with go-to-market and legal teams to support compliance and customer-driven initiatives. Own and expand our compliance roadmap (SOC 2, SOC 1, ISO 27001), while keeping guardrails pragmatic for a fast-paced startup.
- Lead incident response and detection. Build the detection pipeline, act as the primary commander, and turn every event into systemic improvements.
WHAT YOU'LL BRING:
- 5+ years in progressive security roles, with at least 2+ years at a B2B tech, fintech, or highly regulated SaaS company.
- Strong fundamentals in secure SDLC, cloud security (AWS/GCP), Web security, and DevSecOps practices.
- Ability to develop lightweight, durable security policies, access controls, and data governance frameworks. A track record of building "practical security, not checkbox theater."
- Nice to have: Experience securing LLM usage for both coding and in product use cases, and mitigating risks specific to agentic systems (e.g., unauthorized actions taken by autonomous agents, prompt injection, and data poisoning)
- Proven track record of owning SOC 2 Type II...