Head of Security & Compliance Location: Remote Reports to: Chief Operating Officer Type: Full-time, exempt About Finch AI Finch AI is a growing GovTech software company building research-security and intelligence products for federal agencies and universities. We operate with a lean, highly technical team where security and compliance are essential to our ability to serve customers and grow. The role We are seeking a hands-on Head of Security & Compliance to own and operate our company-wide compliance program. This is an executive-facing operating role—not a policy-only or advisory position. You will administer our Microsoft 365 and Entra environment, maintain audit-ready evidence, respond to customer security reviews, and brief leadership on compliance posture and risk. What you’ll own Sustain CMMC Level 2 and maintain accurate SSP, POA&M, and SPRS documentation. Administer Microsoft 365, Entra ID, Purview, Defender, Exchange Online, SharePoint, and Teams security controls. Govern source-code access, branch protection, secrets, CI/CD pipelines, build integrity, and software supply-chain evidence. Define and maintain CUI, personnel-access, and segregated-development boundaries. Build and operate security awareness, insider-threat, and incident-response programs. Own customer security assessments and DFARS 252.204-7012 obligations. Establish a practical AI governance and assurance program. Assess AWS security controls and evidence without serving as the AWS operator. Help shape future FedRAMP or GovRAMP authorization efforts as customer demand develops. Brief executives, the board, customers, and external assessors. Required qualifications 7+ years in federal or defense-industrial security, compliance, governance, or ISSM-type roles. Direct experience implementing and sustaining NIST SP 800-171, CMMC, an ATO, FedRAMP continuous monitoring, or a comparable authorization. Hands-on authorship and maintenance of SSPs, POA&Ms, and audit evidence. Working knowledge of DFARS, CUI handling, and DoD incident-reporting requirements. Production administration experience with Microsoft 365 and Entra ID. Experience applying security controls to source control, CI/CD pipelines, secrets, and software-development environments. Ability to evaluate technical cloud controls and determine whether the documented posture matches reality. Strong executive communication and defensible technical writing skills. Experience with FedRAMP or GovRAMP, export controls, insider-threat programs, AI governance, AWS, research security, GCC High, or relevant certifications is preferred. This role is ideal for someone who wants direct ownership of a growing security and compliance program and is comfortable moving between tenant administration, audit evidence, engineering governance, customer conversations, and executive briefings. About Finch AI Finch AI turns complex text into accurate, trusted, real-time intelligence that helps organizations understand risk and act decisively. Our platform combines entity intelligence, knowledge graphs, agentic AI, and deep domain expertise to support critical missions. Our remote-first team of engineers, analysts, data scientists, and mission experts values curiosity, ownership, collaboration, and integrity. We seek people who enjoy solving difficult problems and building technology with real-world impact. Finch AI is an equal opportunity employer. Reasonable accommodations are available during the hiring process by contacting hr@finchai.com.
Head of Security & Compliance
Aerospike Inc
Principal Technical Program Manager - Security and Compliance (Chronosphere)
Paloaltonetworks
IT Security & Compliance Specialist I - EHRA - Early Career
Nc
Security & Compliance Lead
LTHS, Inc.
2026 Security Vulnerability, Risk, and Compliance Analyst Technical Intern (Jan and May 2027 hires)
Church
Legal Counsel, Data Security & Compliance
Plaud