Close

Security & Trust Lead (USA Only - 100% Remote)

United StatesRemoteFull timeLeadPosted 17 days ago
Apply on Close →

Sign into see who you know at Close.

ABOUT US

Since 2013, we’ve been building a CRM that gets out of your way and helps your team sell more, faster. Now we’re building AI into every part of it, so Close does the busywork and your team does the selling. No manual data entry, no 10-click workflows. Just communication-first, AI-powered sales software designed to help you succeed and scale.

We're bootstrapped and profitable, which means we answer to our customers and play by our own rules. We're proud of our 120-person, 100% remote team, focused on building Close so that no small, scaling business fails because it can't figure out sales.

ABOUT THE ROLE

We have 11k+ customers, which means we have a lot of data in our care. Earning and keeping their trust — rigorous security and privacy practices, plus the compliance and audit work that verifies it to customers — has so far been spread across engineering leadership, our founders, and our ops team. It's high time this had a real owner.

You'll be the first person at Close whose full-time job is protecting our customers' data and our company: GRC (security governance, risk, and compliance), internal security (identity, devices, access, vendors), incidents, and the customer-facing resources that prove we do this well. Your mandate is to build this like an engineer — automate the evidence, codify the processes, use AI aggressively. We recommend giving grc.engineering http://grc.engineering a read; this is the mentality we're hiring for.

YOU ARE

- A hands-on operator, with 5+ years of building Security & Trust programs. You've personally run security and compliance programs, ideally at a 50–300 person company. You’ve been the one configuring SSO, running access reviews, answering the SOC 2 auditor's questions.

- Technical enough to know how our systems work. You can reason about SSO/IAM configuration details, trace how customer data flows through third-party tools, and dig through logs (e.g., in Loki) to run down an incident yourself.

- Automa...