Head of Security & Compliance
About Unleash
Unleash is an open source feature management platform that helps development teams experiment faster with new features while reducing the risks of releasing software in production. Our mantra is “Create with freedom. Release with confidence.”
Modern software teams move fast, but releasing code safely is still one of the hardest parts of building software. That is why we created Unleash. Our platform allows teams to separate deployment from release, run controlled experiments, and roll out new functionality safely in production.
Unleash started as an open source project on GitHub in 2015. As adoption grew, the company was founded in Oslo in 2019. Today, the platform is used by thousands of development teams around the world, from startups to large enterprises running mission-critical systems. This year, Series B funding has been announced.
We are a remote-first engineering company building tools for developers, by developers. Our mission is simple. Make life easier for developers so they can ship better software faster.
Security and compliance today is split across a few people wearing many hats. As we scale, we are creating a dedicated function for it, and looking for the person who will own it end to end, and get to define how it grows from here.
About the position
As Head of Security & Compliance, you will be the first person to own security and compliance at Unleash as a dedicated function. This is a hands-on, individual contributor leadership role, you are the first and only dedicated security and compliance hire today, which means you will set direction, do the work, and act as the trusted voice on security for customers, leadership, and the rest of the organization.
This is a rare kind of opportunity. Most people in this field inherit an existing program built by someone else. Here, you get to define what "good" looks like at Unleash, backed by a leadership team that wants a real risk-based partner, not someone to rubber-stamp policy.
Responsibilities
Own and build the framework
Define what must be documented and how, and prepare board-level updates on our threat landscape and risk posture
Build out our approach to prioritizing security and compliance work across the company, working closely with our Head of Engineering.
Own customer & contract trust end to end
Take full ownership of pre-sale security reviews and post-sale escalations from customer security teams, work currently split between several people
Own contract and compliance reviews in the sales process, including the trade-off calls this requires
Own compliance & audit processes
Own passing our annual SOC 2 audit, and our ongoing compliance monitoring via Vanta
Own GDPR and data mapping from the ground up, and shape our path toward ISO 27001 if we decide to pursue it
Build what does not exist yet
Establish our first written AI usage policy, and define what counts as customer data versus data we hold about our customers
Build out third-party and vendor risk management as a proper, owned process
Who we believe you are
First of all, we believe you want to build something, not just maintain it. You have probably already carried real ownership of an audit or compliance process inside a larger company, done the hard, unglamorous work of collecting evidence and building the case, and are now looking for the chance to own the whole thing yourself.
We believe you:
Bring experience from a fast-moving, B2B SaaS environment, ideally having sold software-as-a-service to other companies
Have had real ownership of audits or compliance processes in a larger organization at some point, alongside experience in a smaller, less structured environment
Have enough technical understanding to grasp our overall security picture and ask the right questions, without needing to be hands-on at implementation
Have a pragmatic, risk-based mindset, and are energized rather than discouraged by ambiguity and a blank page
Can communicate credibly with security teams at large enterprise customers
It is also nice if you have
Hands-on ISO 27001 experience
Practical GDPR and data mapping experience
Experience with, or clear opinions on, AI/LLM data handling policy
Familiarity with automated compliance monitoring tools such as Vanta
Cloud-native understanding, ideally of AWS
What is in it for you
The rare chance to build and own a security and compliance function from scratch, not inherit someone else's
Work directly with our Head of Engineering in shaping how Unleash approaches risk and trust as we scale
Real ownership over the systems, policies, and processes you build
Flexible, remote-first working environment
Two company off-sites per year, where the whole team meets in European cities
Everything you need to do your best work
Interested in joining us?
Interview process
Video interview with a recruiter
Manager interview (meet and greet)
Case study (Completed at home)
Squad interview with your future colleagues, and walk-through of the case study
Personality test and interview with recruiter
Job offer
If this opportunity sparks your interest, please apply with your CV and a detailed LinkedIn profile. If you would like to learn more about the position, feel free to reach out to Erlend Sletvold at erlend.sletvold@getunleash.io.
Unleash is the controller of your personal data for the purposes of this recruitment. Amby AS acts as the processor of your personal data, except when you agree to join our Talent Pool, in which case Amby also becomes the data controller. We process your personal data to manage and conduct the recruitment process. You have the right to access your data, request rectification, erasure, and restriction of processing, as well as the right to object to processing and data transfer. For a more detailed understanding of how we handle your data, the purposes of processing, and your rights, please refer to Amby's Privacy Policy and Unleash Privacy Policy
- Locations
- Oslo, Madrid
- Remote status
- Fully Remote
About Unleash
Being a remote first company we believe in a diverse, supportive and collaborative culture.
Trust
We are one team – we trust each other by cheering for our successes and by always being there to support when needed.
Speed
We want to move fast. Which means that we deliver quality products without striving for perfection before collecting feedback.
Experimental
We want to deliver a world-class, innovative product. To achieve that, we need to be willing to try out different ideas and to learn, evolve, and adapt.
Fun
We want to have a culture where there is room to have fun and to enjoy ourselves, but we also recognize that there is a time to be serious.
Transparency
We believe that open and honest communication with our users, customers, employees creates an atmosphere of collective collaboration which allows us to learn and make better decisions and reach our goals.