Athenago logo

Head of Information Security

Hiring from
United States
Work type
Remote
Posted
Sep 30, 2026
Is this job info correct?

About Athena

Athena (athena.com) pairs world-class leaders with elite executive assistants. It’s where some of the most powerful partnerships in the world get built.

Our clients are founders, executives, and leaders whose ambition exceeds their time. Athena is the first company to build a human-in-the-loop executive support system, combining trained Executive Assistants with market-leading AI to help them stay organized, follow through on priorities, and operate at their highest level.

Athena is one of the largest companies in this category, with 3,000+ clients and over $100M in annual run rate. Our clients include Uber, Shopify, and Goldman Sachs.

We are fully global, working across time zones and cultures. Joining Athena means creating something that fundamentally changes how people live and work and brings extraordinary achievement within reach.


Who We’re Looking For

We’re looking for people who take their work seriously and want to get better at it.

You should be thoughtful in how you approach problems, willing to take ownership, and able to follow through without constant direction. You ask questions when something doesn’t make sense, and you care about getting the details right.

You should be comfortable working with people who have high expectations and limited time. That means being clear, responsive, and reliable.

We’re also looking for people who are interested in how this role is changing. The way work gets done is in flux between people, systems, and AI. We want people who are curious about that and willing to adapt as technology evolves.

You don’t need to know everything on day one, but you should be able to learn quickly and apply what you learn.


Role Overview

We are looking for a Head of InfoSec Operations to lead the day-to-day execution of our cybersecurity operations, security monitoring, incident response, threat detection, vulnerability management, and client-facing security assurance.

This role will bridge the gap between security strategy and tactical execution. The ideal candidate is hands-on, operationally strong, calm under pressure, and able to work cross-functionally with IT, Engineering, DevOps, Product, Legal, Compliance, Sales, and Customer Success.

In addition to leading internal security operations, this person will serve as a key point of contact for client security questions, customer due diligence, security questionnaires, vendor risk reviews, and enterprise security discussions.


Key Responsibilities

Security Operations & Incident Response

  • Lead and continuously improve the company’s security operations function, including monitoring, detection, investigation, response, and remediation.
  • Serve as incident commander for major cybersecurity incidents, leading triage, containment, eradication, recovery, and post-incident reviews.
  • Own the operational incident response process, including playbooks, escalation paths, communication procedures, and readiness exercises.
  • Ensure proper logging, monitoring, alerting, and security visibility across cloud, SaaS, endpoint, network, and application environments.
  • Oversee threat detection, threat hunting, security investigations, malware analysis, and forensic response activities.
  • Establish and track security operations metrics such as mean time to detect, mean time to respond, alert quality, incident volume, and remediation timelines.
  • Conduct tabletop exercises, simulations, and regular readiness reviews to improve incident response maturity.

Vulnerability Management & Risk Reduction

  • Own the vulnerability management program, including scanning, prioritization, remediation tracking, and reporting.
  • Coordinate penetration testing, external assessments, and remediation follow-up with Engineering, DevOps, IT, and Product teams.
  • Partner with technical teams to identify, assess, and reduce security risks across infrastructure, applications, cloud services, endpoints, and third-party tools.
  • Monitor emerging threats, adversary tactics, and relevant attack trends, and translate them into practical defensive improvements.
  • Drive remediation of risks that exceed the company’s acceptable risk thresholds.

Security Tooling & Architecture

  • Evaluate, implement, manage, and optimize security tools such as SIEM, EDR, SOAR, XDR, vulnerability scanners, cloud security monitoring, identity security tools, and logging platforms.
  • Tune detection rules, reduce false positives, and improve the quality and actionability of security alerts.
  • Ensure security tooling is properly integrated with IT, DevOps, cloud, identity, and engineering systems.
  • Participate in or lead security reviews for new products, services, infrastructure changes, and vendor technologies.
  • Maintain consolidated visibility across security data sources and ensure the company has an effective daily security watch function.

Client Security Assurance & External Trust

  • Serve as the primary point of contact for client security inquiries, security questionnaires, due diligence requests, and customer security reviews.
  • Participate in client security calls, vendor risk assessments, procurement reviews, and enterprise customer security discussions.
  • Partner with Sales, Customer Success, Legal, Compliance, Product, Engineering, and IT to address client security concerns accurately and efficiently.
  • Translate technical security controls, risks, and remediation plans into clear, client-appropriate explanations.
  • Maintain reusable, approved responses and documentation for common client security topics, including data protection, encryption, access control, incident response, vulnerability management, business continuity, cloud security, and compliance.
  • Support customer-facing security communications during major incidents, material security events, audits, or significant security posture changes.
  • Identify recurring client security concerns and translate them into improvements in controls, processes, documentation, and internal security maturity.

Compliance, Reporting & Governance Support

  • Support compliance audits, risk assessments, and security reporting requirements, including SOC 2, ISO 27001, NIST, HIPAA, or other relevant frameworks.
  • Provide security evidence, operational metrics, and control documentation for audits and customer reviews.
  • Develop clear executive reporting on security posture, incidents, operational performance, key risks, and remediation progress.
  • Help define and maintain security policies, standards, procedures, and operational playbooks.
  • Work with leadership to ensure security operations align with business goals, regulatory expectations, and customer commitments.

Team Leadership & Cross-Functional Collaboration

  • Lead, mentor, and scale a high-performing team of security engineers, analysts, and external security partners.
  • Set clear priorities, operating rhythms, performance expectations, and development plans for the security operations team.
  • Partner closely with IT, DevOps, Engineering, Product, Legal, Compliance, Sales, and Customer Success to manage risk without slowing down the business unnecessarily.
  • Build a culture of accountability, responsiveness, continuous improvement, and practical security execution.
  • Act as a trusted advisor to internal teams on security operations, incident response, client security expectations, and operational risk.


Required Qualifications

  • 8+ years of total experience across cybersecurity, information security, security operations, IT, infrastructure, or related technical fields.
  • 3-5+ years of experience in a dedicated security operations leadership, incident response leadership, or security management role.
  • Strong hands-on experience with incident response, security monitoring, threat detection, threat intelligence, vulnerability management, and security investigations.
  • Experience managing or operating SIEM, EDR, SOAR, XDR, vulnerability management, cloud security monitoring, identity security, or related security platforms.
  • Experience securing cloud environments such as AWS, Azure, or GCP.
  • Strong understanding of modern attack vectors, adversary tactics, techniques, and procedures, including frameworks such as MITRE ATT&CK.
  • Familiarity with security and compliance frameworks such as NIST, ISO 27001, SOC 2, CIS Controls, OWASP, SANS, SSAE, ITIL, or similar standards.
  • Experience creating security operations metrics, dashboards, executive reports, and remediation tracking processes.
  • Strong written and verbal communication skills, with the ability to explain technical security issues to executive, technical, and non-technical audiences.
  • Ability to remain calm, structured, and decisive during high-pressure security events.

Client-Facing Security Requirements

  • Experience responding to enterprise security questionnaires, vendor risk assessments, customer audits, and client due diligence requests.
  • Ability to represent the security function in customer-facing meetings, procurement discussions, and executive-level security reviews.
  • Strong judgment in balancing transparency with confidentiality when discussing security controls, incidents, vulnerabilities, and internal processes with external parties.
  • Familiarity with common customer security review topics, including data privacy, encryption, access management, incident response, vulnerability management, cloud security, business continuity, SOC 2, and ISO 27001.
  • Ability to create clear, accurate, reusable security documentation and approved responses for client-facing use.

Preferred Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related field, or equivalent practical experience.
  • Security certifications such as CISSP, CISM, GCIH, GCIA, CRISC, ISSAP, OSCP, or similar.
  • Experience leading or working with a 24/7 SOC or managed security service provider.
  • Experience in a SaaS, cloud-native, enterprise software, fintech, healthcare, AI, or regulated technology environment.
  • Experience supporting SOC 2, ISO 27001, HIPAA, PCI, or other customer-driven compliance programs.
  • Experience building security operations programs from an early or scaling stage.
  • Experience partnering with Sales or Customer Success on enterprise customer security reviews.

Why work here?

At Athena, work actually works for you. Weekly pay, comprehensive benefits that fit your life (yes, even pet perks), and real growth opportunities with global reach.

You'll work on an international stage with world-class leaders where your ideas matter. This isn't about ticking boxes or following scripts—you're here to make a meaningful impact while building skills that transform your career trajectory. Greatness is contagious, and you'll be surrounded by curious, ambitious people who challenge the norm and grow together.

Athena is a community of unconventional thinkers where success is mutual. From day one, you’ll be supported through intensive onboarding, hands-on mentorship, and targeted development programs designed to accelerate your growth. Our high-performance culture is fueled by collaboration, feedback, and a shared commitment to excellence, and we invest deeply in your development.

Similar jobs

Apply for this job