Security Trust Lead positions focus on delivering results in their domain. This page aggregates open Security Trust Lead roles and what employers typically expect.
# **About Us** Since 2013, we’ve been building a CRM that gets out of your way and helps your team sell more, faster. Now we’re building AI into every part of it, so Close does the busywork and your team does the selling. No manual data entry, no 10-click workflows. Just communication-first, AI-powered sales software designed to help you succeed and scale. We're bootstrapped and profitable, which means we answer to our customers and play by our own rules. We're proud of our 120-person, 100% remote team, focused on building Close so that no small, scaling business fails because it can't figure out sales. # **About the Role** We have 11k+ customers, which means we have a lot of data in our care. Earning and keeping their trust — rigorous security and privacy practices, plus the compliance and audit work that verifies it to customers — has so far been spread across engineering leadership, our founders, and our ops team. It's high time this had a real owner. You'll be the first person at Close whose full-time job is protecting our customers' data and our company: GRC (security governance, risk, and compliance), internal security (identity, devices, access, vendors), incidents, and the customer-facing resources that prove we do this well. Your mandate is to build this like an engineer — automate the evidence, codify the processes, use AI aggressively. We recommend giving http://grc.engineering a read; this is the mentality we're hiring for. ## **You are** - **A hands-on operator, with 5+ years of building Security & Trust programs.** You've personally run security and compliance programs, ideally at a 50–300 person company. You’ve been the one configuring SSO, running access reviews, answering the SOC 2 auditor's questions. - **Technical enough to know how our systems work.** You can reason about SSO/IAM configuration details, trace how customer data flows through third-party tools, and dig through logs (e.g., in Loki) to run down an incident yourself. - **Automation and efficiency minded.** You'll happily grind through manual work when it's needed - screenshotting evidence, searching logs - but you refuse to still be doing it by hand a year later, so you automate it away with scripts, APIs, and AI. - **AI-positive.** You see AI as something to help us adopt faster, not just a risk to manage. Your instinct is to find the safe path to yes and you can tell the difference between exposure and vibes. ## **You will** - **Run our GRC program — then automate it.** Vanta day to day (controls, policies, alerts, evidence, vendor reviews), leading our SOC 2 Type 2 audits, annual risk assessments, and evaluating additional frameworks (ISO 27001, HIPAA). Wherever a recurring check, evidence pull, or list (like our GDPR subprocessors) can come from code or an API instead of by hand, make it so. - **Own how customer data moves through our stack.** Audit what flows to third-party tools (and stop what shouldn't), and build a real process for deletion requests across our analytics stack. - **Be the security gate for new tools and vendors.** Confirm SOC 2 status, get the DPA signed, add them in Vanta, update the subprocessor list — with a process that lets the team adopt new tools (AI especially) quickly and safely. Procurement and spend stay with finance/ops; the security and privacy review is yours. - **Make Close best-in-class at communicating trustworthiness.** Own http://trust.close.com and our security/privacy/GDPR pages, and turn them into the place where customers' security questions can answer themselves. - **Coordinate product security audits.** Run pen tests and audits of our product jointly with Engineering — vendor selection, scoping, and the artifacts we need for customers and partners (e.g., Google OAuth restricted scopes). Engineering fixes what's found; you make sure the audits happen and produce what we need. - **Investigate and clean up security incidents.** When something looks off, you're the one who digs in to run it down and c…