Togal.AI Logo

Togal.AI

Director of Security

Posted One Month Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Lead Togal's security program: own SOC 2 compliance, manage audits and Vanta, respond to customer security reviews, design and lead incident response, evaluate monitoring/MDR/SIEM, tighten cloud security posture, and coordinate breach communications with Legal and executive leadership.
The summary above was generated by AI

We are an innovative technology company providing a cutting-edge, AI-powered cloud platform for the construction industry. Created by industry experts with deep estimating experience, our software dramatically streamlines the pre-construction process. Our solution uses advanced machine learning to automate traditionally time-consuming takeoff tasks, helping estimators work up to 80% faster while reducing costly errors.

Our collaborative platform enables real-time teamwork, instant drawing analysis, and features a revolutionary conversational AI interface that transforms how professionals interact with construction plans. Founded by construction industry veterans, our award-winning application automates the takeoff process, enabling estimators to analyze blueprints in seconds rather than hours or days.

What you'll do
  • Own Togal's SOC 2 Type II program end-to-end — evidence collection, audit management, and control ownership in Vanta — so it's audit-ready year-round, not just before an audit.

  • Turn around customer security questionnaires and vendor security reviews quickly and accurately.

  • Be Togal's front-line security contact for customers and prospects, including calls with customer-side CISOs and security teams during deal cycles and MSA negotiations.

  • Design a written incident-response and notification policy — clear triggers, timelines, escalation paths, and roles — that's actually followed, replacing today's ad hoc handling by the CTO and CEO.

  • Lead incident response when something does happen: containment, investigation, and coordinating any outside help needed (e.g., an MDR/IR retainer for surge capacity) — this is "own it when it happens," not the day-to-day center of the role.

  • Evaluate whether to buy, outsource, or build additional security monitoring — assess managed detection/SIEM options against what we actually need before committing engineering time to standing anything up ourselves.

  • Assess and tighten cloud security posture (IAM, configuration, logging) alongside the CTO and engineering team.

  • Partner with Legal and the CEO on breach determination and external communication, as a defined process rather than a one-off scramble.

What you bring

Must-haves:

  • Experience running a SOC 2 or similar compliance program end-to-end, including audit management and tooling (Vanta or equivalent).

  • Comfortable being the primary voice in customer-facing security conversations — you can sit across from a customer's CISO and hold your own.

  • Solid grounding in cloud security fundamentals (IAM, configuration management, logging) rather than just general cloud familiarity.

  • Enough hands-on technical depth to lead an incident when one occurs — you don't need to be a forensics specialist, but you should be credible investigating and coordinating a response.

  • Comfortable operating independently at an early-stage company, building the function as you go rather than stepping into an existing team or playbook.

Nice-to-haves:

  • Experience standing up a security/trust function from scratch at a startup or scale-up.

  • Background in construction tech or B2B SaaS.

  • Familiarity with email authentication and phishing/account-compromise forensics (DKIM/SPF/DMARC).

  • Experience evaluating or managing an MDR/IR retainer relationship.

You'd be Togal's first dedicated security hire, with the mandate to build the function the way you think it should work rather than inherit someone else's backlog. You'll be the person enterprise customers trust when security becomes a deal-maker or deal-breaker, work closely with the CTO and CEO, and have a direct hand in the deals where security is the deciding factor.

We are an equal opportunity employer committed to building a diverse team. We welcome applications from candidates of all backgrounds who are passionate about using technology to transform the construction industry.

Join us in revolutionizing pre-construction estimating with the power of AI!

Similar Jobs

4 Hours Ago
In-Office or Remote
Delaware, USA
187K-275K Annually
Expert/Leader
187K-275K Annually
Expert/Leader
Fintech • Information Technology • Financial Services
Leads enterprise AI security architecture and strategy across LLM applications, RAG pipelines, agent workflows, and cloud-native platforms. Establishes security standards, governance requirements, guardrails, threat models, and secure development patterns. Drives remediation of AI-specific risks including prompt injection, jailbreaks, data exposure, unsafe tool usage, and excessive permissions. Partners with senior engineering, product, architecture, and security leaders, leads investigations, supports automated security testing, represents AI security in governance forums, and mentors security engineers.
Top Skills: Agent-Based WorkflowsAi/Ml PlatformsAWSAzureCi/CdCloud-Native PlatformsGCPLlmMcp IntegrationsRag
2 Days Ago
In-Office or Remote
230K-288K Annually
Expert/Leader
230K-288K Annually
Expert/Leader
Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Lead DigitalOcean’s AI security strategy, governance framework, threat modeling, and multi-year roadmap. Partner with security, engineering, and data science teams to secure AI products, deploy guardrails, conduct adversarial testing and red teaming, and monitor AI/ML systems. Provide architectural reviews, executive risk briefings, and guidance on emerging threats including prompt injection, model supply-chain risks, agentic AI, and data exfiltration.
Top Skills: Agentic AiAi/MlGoIso/Iec 42001Large Language ModelsMitre AtlasNist Ai RmfOwasp Llm Top 10PythonRetrieval-Augmented Generation (Rag)
2 Days Ago
In-Office or Remote
San Francisco, CA, USA
230K-288K Annually
Expert/Leader
230K-288K Annually
Expert/Leader
Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Lead DigitalOcean’s AI security strategy, governance framework, roadmap, and organizational programs. Build and operationalize AI/ML security controls, tooling, guardrails, and automation; conduct threat modeling, adversarial testing, and AI red teaming. Review AI architectures, guide high-risk product decisions, monitor deployed models, and address risks involving RAG, agents, model supply chains, and prompt injection. Represent AI security to executives and external communities while translating emerging research and threats into engineering guidance and policy.
Top Skills: Agentic Ai FrameworksAi/MlEu Ai ActGoIso/Iec 42001Mitre AtlasModel ApisNist Ai RmfOwasp Llm Top 10PythonRag

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account