About Quora
Quora’s mission is to grow and share the world’s knowledge. To do so, we have two knowledge sharing products:
- Quora: a global knowledge sharing platform with over 400M monthly unique visitors, bringing people together to share insights on various topics and providing a unique platform to learn and connect with others.
- Poe: a platform providing millions of global users with one place to chat, explore and build with a wide variety of AI language models (bots), including GPT-4, Claude 3, Gemini Pro, DALL-E 3 and more. As AI capabilities rapidly advance, Poe provides a single platform to instantly integrate and utilize these new models.
About The Team And Role
We are seeking a highly experienced Head of Security to lead the development and management of security operations for both Quora and Poe products, and to represent Quora's security interests to customers and regulatory bodies. This role encompasses a variety of responsibilities, including identifying vulnerabilities, implementing best-in-class security practices, and developing long-term security strategies. The ideal candidate will possess a proven track record in team building, engineering, and upholding the highest security standards.
Responsibilities
- Hire, lead, and manage the security team
- Lead the identification and continuous enhancement of security measures across engineering processes, products, and infrastructure
- Develop and maintain security policies, standards, and guidelines that align with organizational objectives and legal requirements, including compliance and audit planning
- Collaborate with various departments such as Legal, IT, Facilities, and Operations to develop and implement secure engineering practices
- Conduct regular security assessments and audits, ensuring compliance with industry standards
- Lead the coordinated response to security incidents, from detection to remediation, root cause analysis, and prevention
- Stay informed about emerging threats and technologies, and advise the leadership team accordingly
- Mentor and guide engineering teams on best practices for secure development, threat modeling, and testing
- Design and execute security training and awareness programs tailored for the engineering department and all employees
Minimum Requirements
- Ability to be available for meetings and impromptu communication during Quora's “coordination hours" (Mon-Fri: 9am-3pm Pacific Time)
- 8+ years of experience in Infrastructure and Information Security
- 3+ years of experience leading a team
- Proven experience in designing and securing solutions in a complex and regulated enterprise environment
- Skilled in defining security requirements and assisting teams in implementing these through collaborative architecture and engineering
- In-depth knowledge of AWS security best practices and security controls, including IAM, CloudTrail, CloudWatch, etc
- Strong understanding of security concepts, such as secure coding, encryption, and authentication
- Knowledge of industry standards like SOC 2, ISO 27001 and GDPR
- Comprehensive understanding of advanced persistent threats, attacker methodologies, attack lifecycle, and the MITRE framework
Preferred Requirements
- Experience in leading a company-wide security program that encompasses security in Infrastructure, IT, Facilities, Operations, and achieving compliance
- Experience in building secure consumer products at internet scale
- Passion for Quora's mission and goals.
Additional Information
We are accepting applications on an ongoing basis.
Quora offers a wide range of benefits including medical/dental/vision coverage, equity refreshers, remote work reimbursement, paid time off, employee assistance programs, and more. Benefits are country-specific and may vary. For more information on benefits, visit this link: https://www.careers.quora.com/benefits
Benefits Extracted with AI
- Medical/Dental/Vision coverage
- Equity refreshers
- Remote work reimbursement
- Paid time off
- Employee assistance programs
Similar jobs
Last update: 23 minutes ago
Staff Software Engineer
Join Aiven as a Staff Software Engineer to develop cloud operations platforms using open-source technologies. Hybrid work in Berlin.
Front-end Angular Engineer
Join Zivver as a Front-end Angular Engineer to shape the future of secure web applications. Work with Angular, TypeScript, and more in Amsterdam.
Senior Software Engineer - Embedded Systems and Cryptography
Join Adva Network Security as a Senior Software Engineer in Berlin, focusing on embedded systems and cryptography.
Staff Software Engineer, Data Platform
Join Personio as a Staff Software Engineer in Berlin to build scalable data platforms using Kafka, Kubernetes, and AWS. Drive innovation and excellence.
Senior Software Engineer - Python, Django, Angular
Join Ilkari as a Senior Software Engineer to lead development in Python, Django, and Angular, creating scalable solutions in a hybrid work environment.
iOS Developer
Join Tezza as an iOS Developer to enhance our app with Swift and SwiftUI, working remotely in a creative team.
Senior Systems Engineer, Managed Operations
Join AWS as a Senior Systems Engineer in Berlin to lead operations for the European Sovereign Cloud, ensuring high-availability AWS services.
Expert Machine Learning Engineer
Join Dataroots as an Expert Machine Learning Engineer to design and deliver AI-powered solutions, focusing on machine learning models.
Senior Cloud DevOps Engineer
Join netgo as a Senior Cloud DevOps Engineer in Berlin. Work with Kubernetes, GitOps, and more in a dynamic team environment.
Senior Full Stack Engineer - Climate Tech - Rust & TypeScript
Join Climatiq as a Senior Full Stack Engineer to develop climate tech solutions using Rust and TypeScript. Remote work available.
Platform Engineer with Cloud and DevOps Expertise
Join ITQ as a Platform Engineer to design, implement, and maintain cloud-native platforms using Kubernetes and DevOps practices.
Software Engineer II - Developer Experience
Join Elastic as a Software Engineer II in Developer Experience, focusing on test frameworks for Kibana. Remote work, competitive benefits.
Senior Product Engineer [Rust & Typescript]
Join Attio as a Senior Product Engineer working with Rust & TypeScript to build innovative CRM features. Remote work available.
Senior Full Stack Engineer (PHP, Angular, React)
Seeking a Senior Full Stack Engineer with PHP, Angular, React expertise for remote work in the EU. 6+ years experience required.
Senior DevOps Engineer
Join CARFAX Europe as a Senior DevOps Engineer to manage AWS infrastructure, develop CI/CD pipelines, and enhance system observability.
Senior Software Engineer - Dispatching
Join as a Senior Software Engineer to lead dispatching services design, optimizing global networks with Go, Ruby, and React.
Senior Software Engineer - Backend Development
Join Sysdig as a Senior Software Engineer to develop scalable backend services using Go, RESTful APIs, and microservices in a hybrid work environment.
Senior Software Engineer Mobile (React Native)
Join Safe as a Senior Software Engineer Mobile (React Native) to develop high-quality mobile apps, collaborate with cross-functional teams, and mentor peers.
Senior Software Engineer - AWS, Python, Ruby on Rails
Join HeyJobs as a Senior Software Engineer to design scalable systems using AWS, Python, and Ruby on Rails in a dynamic team.
Senior NodeJS Developer
Join Semrush as a Senior NodeJS Developer to build and enhance digital marketing tools. Work remotely with flexible hours.
Senior Software Engineer - C#/.NET
Join TrueLayer as a Senior Software Engineer in Milan, working with C#, .NET, AWS, and Kubernetes to build scalable systems.
Senior Ruby Developer
Join Triad Group Plc as a Senior Ruby Developer, working remotely with Ruby on Rails, JavaScript, and more. Great benefits and career growth.
Senior DevOps Engineer with Linux, Kubernetes, and GCP
Join Redcare Pharmacy as a Senior DevOps Engineer to enhance infrastructure efficiency using Linux, Kubernetes, and GCP.
Junior Security Software Engineer
Join CHECK24 as a Junior Security Software Engineer in Berlin, focusing on application security, vulnerability management, and penetration testing.