About Quora
Quora’s mission is to grow and share the world’s knowledge. To do so, we have two knowledge sharing products:
- Quora: a global knowledge sharing platform with over 400M monthly unique visitors, bringing people together to share insights on various topics and providing a unique platform to learn and connect with others.
- Poe: a platform providing millions of global users with one place to chat, explore and build with a wide variety of AI language models (bots), including GPT-4, Claude 3, Gemini Pro, DALL-E 3 and more. As AI capabilities rapidly advance, Poe provides a single platform to instantly integrate and utilize these new models.
About The Team And Role
We are seeking a highly experienced Head of Security to lead the development and management of security operations for both Quora and Poe products, and to represent Quora's security interests to customers and regulatory bodies. This role encompasses a variety of responsibilities, including identifying vulnerabilities, implementing best-in-class security practices, and developing long-term security strategies. The ideal candidate will possess a proven track record in team building, engineering, and upholding the highest security standards.
Responsibilities
- Hire, lead, and manage the security team
- Lead the identification and continuous enhancement of security measures across engineering processes, products, and infrastructure
- Develop and maintain security policies, standards, and guidelines that align with organizational objectives and legal requirements, including compliance and audit planning
- Collaborate with various departments such as Legal, IT, Facilities, and Operations to develop and implement secure engineering practices
- Conduct regular security assessments and audits, ensuring compliance with industry standards
- Lead the coordinated response to security incidents, from detection to remediation, root cause analysis, and prevention
- Stay informed about emerging threats and technologies, and advise the leadership team accordingly
- Mentor and guide engineering teams on best practices for secure development, threat modeling, and testing
- Design and execute security training and awareness programs tailored for the engineering department and all employees
Minimum Requirements
- Ability to be available for meetings and impromptu communication during Quora's “coordination hours" (Mon-Fri: 9am-3pm Pacific Time)
- 8+ years of experience in Infrastructure and Information Security
- 3+ years of experience leading a team
- Proven experience in designing and securing solutions in a complex and regulated enterprise environment
- Skilled in defining security requirements and assisting teams in implementing these through collaborative architecture and engineering
- In-depth knowledge of AWS security best practices and security controls, including IAM, CloudTrail, CloudWatch, etc
- Strong understanding of security concepts, such as secure coding, encryption, and authentication
- Knowledge of industry standards like SOC 2, ISO 27001 and GDPR
- Comprehensive understanding of advanced persistent threats, attacker methodologies, attack lifecycle, and the MITRE framework
Preferred Requirements
- Experience in leading a company-wide security program that encompasses security in Infrastructure, IT, Facilities, Operations, and achieving compliance
- Experience in building secure consumer products at internet scale
- Passion for Quora's mission and goals.
Additional Information
We are accepting applications on an ongoing basis.
Quora offers a wide range of benefits including medical/dental/vision coverage, equity refreshers, remote work reimbursement, paid time off, employee assistance programs, and more. Benefits are country-specific and may vary. For more information on benefits, visit this link: https://www.careers.quora.com/benefits
Benefits Extracted with AI
- Medical/Dental/Vision coverage
- Equity refreshers
- Remote work reimbursement
- Paid time off
- Employee assistance programs
Similar jobs
Last update: 23 minutes ago
Staff Full Stack Software Engineer - Poe Core Product
Join Quora as a Staff Full Stack Software Engineer for Poe Core Product, leveraging AI technologies in a remote role.
Mid-Senior Full Stack Software Engineer - Remote
Mid-Senior Full Stack Engineer for Quora, remote. Work on core product features using Python, JavaScript, React, and Typescript.
Senior Full Stack Software Engineer - Remote
Join Quora as a Senior Full Stack Software Engineer to build cutting-edge AI features remotely. Work with Python, TypeScript, and GraphQL.
Senior Data Scientist - Remote
Senior Data Scientist role at Quora, remote, focusing on data analysis, product analytics, and AI integration.
Staff Full Stack Software Engineer - Poe Creators
Remote Staff Full Stack Software Engineer role at Quora, focusing on AI and web technologies like GraphQL, Python, and TypeScript.
Staff Full Stack Software Engineer - AI Platforms (Remote)
Remote Staff Full Stack Engineer role focused on AI platforms, requiring React, Typescript, GraphQL, Python.
Senior Software Engineer - Ads (Remote)
Senior Software Engineer for Ads, remote, skilled in Java, JavaScript, React.js, TypeScript, ad serving, and monetization.
Senior Full Stack Software Engineer - Poe Core Product
Join Quora as a Senior Full Stack Software Engineer to develop core features for Poe, a platform for AI language models.
Staff Full Stack Software Engineer - Poe Creators
Join Quora as a Staff Full Stack Software Engineer to build cutting-edge AI features for Poe Creators. Remote role.
Staff Full Stack Software Engineer - Poe Creators
Join Quora as a Staff Full Stack Software Engineer to build AI-driven features for Poe, working remotely with a focus on GraphQL, Python, and TypeScript.
Senior Full Stack Software Engineer - Poe Core Product
Senior Full Stack Engineer for AI product development with skills in React, TypeScript, GraphQL, and Python.
Senior Security Engineer
Join Squarespace as a Senior Security Engineer in Dublin, focusing on cybersecurity, incident response, and threat detection.
Privacy Engineer, Incident Response and Investigation
Join Meta as a Privacy Engineer focusing on incident response and investigation, ensuring data privacy and security.
Head of Engineering - Data Security Software
Lead the engineering team at Opaque Systems, optimizing SDLC and managing offshore centers in the AI and data privacy sector.
Director of Engineering, Security - Viator
Lead the Security and Compliance Engineering team at Viator, a Tripadvisor company, with a focus on software and security engineering.
Privacy Engineering Manager at Meta
Lead a team specializing in Privacy Incident Investigation at Meta, ensuring the security of over 3 billion users.
Senior Security Engineer
Join Magic as a Senior Security Engineer to lead security initiatives, manage vulnerabilities, and ensure compliance in a remote role.
Staff/Lead Application Security Engineer
Join Agoda as a Staff/Lead Application Security Engineer in a dynamic DevSecOps environment.
Privacy Engineer, Incident Response and Investigation
Join Meta as a Privacy Engineer focusing on incident response and investigation, ensuring data privacy and security.
Security Engineering Manager, Investigations
Lead a team focused on child safety and human exploitation investigations at Meta, leveraging technology and innovative research.
Tech Lead, Product Security Engineering
Lead product security engineering at Google Cloud, ensuring secure product development and infrastructure security.
Software Engineer 2 - Platform Security
Join Intuit as a Software Engineer 2 in Platform Security, focusing on cloud infrastructure and security best practices.
Senior Software Engineer IV (Assessments)
Join HackerOne as a Senior Software Engineer IV to lead technical projects in cybersecurity, working remotely in the US or Canada.
Software Engineer, Trust and Safety
Join GitHub as a Software Engineer in Trust and Safety, developing tools to protect our community. Remote work, competitive pay.