What are the responsibilities and job description for the Security & Compliance Lead position at iFrame?
Trust & compliance
Security & Compliance Lead
Build and run the security and compliance program for a fast-growing GPU cloud. You'll own SOC 2 Type II, ISO 27001 certification, HIPAA-ready posture, and the BYOK / HYOK roadmap. You'll be the named person on every customer security questionnaire.
Apply by email All open roles
Team Trust & compliance
Location San Francisco / Remote (US)
Type Full-time
Apply by email
Hiring manager replies within 5 business days.
The team
About The Team
Trust & compliance is a small standalone function that reports to the founder. You'll start as the first dedicated hire on the team and pick up a security engineer in the first six months, with budget for an external auditor and a fractional vCISO if you want one.
Reports to the founder. Owns the trust pages, the audit calendar, and the security questionnaire library.
The role
What you'll do
What we're looking for
Nice to have, not required
In writing, like everything else
We publish bands. We meet them. The number you see on the offer is the same number your future peers got at the same level. We do not negotiate; we level.
Base
$240,000 – $310,000 USD.
Equity
Senior-leadership equity grant, refreshed on tenure milestones.
Notes
Budget for an external auditor and a fractional vCISO is approved on day one.
How to apply
One email is enough
Send a short note to careers@iframe.ai with the role title in the subject line. Include your CV or LinkedIn, one or two links to work you're proud of, and a sentence on why this role specifically. Hiring managers reply within five business days, regardless of outcome.
A hiring manager reads every email. Reply within five business days.
30–45 minutes. Scope, role, mutual fit. We share the comp band on this call.
3–4 sessions on the same day. Real problems, no homework, no whiteboard riddles.
Same-week offer at the published band for your level. Start dates are flexible.
Equal opportunity
We hire on the work. Race, gender, age, nationality, religion, sexual orientation, disability, and veteran status do not factor into our decisions. We sponsor visas for senior roles in the US, UK, and EU — bring it up on the manager call.
Need an accommodation for the interview process? Mention it in your application or write careers@iframe.ai.
Also open
Other roles you might consider
Ship the next 2× on the open-source model catalog. Triton, CUDA, ROCm. You will publish what you ship.
View role
Lead a paper / quarter on multi-thousand-GPU pre-training. Co-appointment with a partner university available.
View role
Bring up B300 racks, drive InfiniBand fabric to spec, run capacity planning across seven regions. Pager included.
View role
All open roles
One last thing
If this role isn't quite right but you'd be a fit at iframe.ai, write anyway.
Senior engineers and researchers can apply outside the listed roles. The bar is the same. The reply window is the same.
Apply: Security & Compliance Lead General application
Security & Compliance Lead
Build and run the security and compliance program for a fast-growing GPU cloud. You'll own SOC 2 Type II, ISO 27001 certification, HIPAA-ready posture, and the BYOK / HYOK roadmap. You'll be the named person on every customer security questionnaire.
Apply by email All open roles
Team Trust & compliance
Location San Francisco / Remote (US)
Type Full-time
- Senior
Apply by email
Hiring manager replies within 5 business days.
The team
About The Team
Trust & compliance is a small standalone function that reports to the founder. You'll start as the first dedicated hire on the team and pick up a security engineer in the first six months, with budget for an external auditor and a fractional vCISO if you want one.
Reports to the founder. Owns the trust pages, the audit calendar, and the security questionnaire library.
The role
What you'll do
- 01 Run the annual SOC 2 Type II audit — scoping, evidence collection, control testing, report delivery — and keep the audit window stable each year.
- 02 Drive ISO 27001 certification end-to-end (Statement of Applicability, ISMS, internal audit, certification body).
- 03 Maintain HIPAA-ready posture and the BAA program; keep a small but real list of healthcare customers signable.
- 04 Ship BYOK then HYOK on the platform with the runtime and cluster teams. Own the customer-facing key-management story.
- 05 Own customer security questionnaires and pre-sales review (CAIQ v4, SIG, custom). Scale the answer library so AEs do not bottleneck on you.
- 06 Handle incident response, breach-notification clock, and post-mortem write-ups for any security incident.
What we're looking for
- Seven-plus years in security and compliance at a cloud / SaaS / infrastructure company; at least one full SOC 2 Type II under your name.
- Operational experience running an ISMS — ISO 27001 certified or one cert away.
- Real understanding of cloud-infra security primitives: KMS / HSM, hardware roots of trust, network segmentation, IDS/IPS, vulnerability management.
- Comfort writing — questionnaire answers, customer-facing trust pages, board-level updates.
- Calm decision-making under pressure. Real incident-response experience preferred.
Nice to have, not required
- FedRAMP Moderate or DOJ CJIS familiarity (we are not pursuing, but customers ask).
- Experience with HSM / KMS engineering and key-management protocol design.
- Privacy-program experience (GDPR Art. 28, CPRA service-provider).
- Past CISO or security lead of a compute / GPU / inference business.
In writing, like everything else
We publish bands. We meet them. The number you see on the offer is the same number your future peers got at the same level. We do not negotiate; we level.
Base
$240,000 – $310,000 USD.
Equity
Senior-leadership equity grant, refreshed on tenure milestones.
Notes
Budget for an external auditor and a fractional vCISO is approved on day one.
How to apply
One email is enough
Send a short note to careers@iframe.ai with the role title in the subject line. Include your CV or LinkedIn, one or two links to work you're proud of, and a sentence on why this role specifically. Hiring managers reply within five business days, regardless of outcome.
- 01
A hiring manager reads every email. Reply within five business days.
- 02
30–45 minutes. Scope, role, mutual fit. We share the comp band on this call.
- 03
3–4 sessions on the same day. Real problems, no homework, no whiteboard riddles.
- 04
Same-week offer at the published band for your level. Start dates are flexible.
Equal opportunity
We hire on the work. Race, gender, age, nationality, religion, sexual orientation, disability, and veteran status do not factor into our decisions. We sponsor visas for senior roles in the US, UK, and EU — bring it up on the manager call.
Need an accommodation for the interview process? Mention it in your application or write careers@iframe.ai.
Also open
Other roles you might consider
- Runtime
Ship the next 2× on the open-source model catalog. Triton, CUDA, ROCm. You will publish what you ship.
View role
- Research lab
Lead a paper / quarter on multi-thousand-GPU pre-training. Co-appointment with a partner university available.
View role
- Cluster & SRE
Bring up B300 racks, drive InfiniBand fabric to spec, run capacity planning across seven regions. Pager included.
View role
All open roles
One last thing
If this role isn't quite right but you'd be a fit at iframe.ai, write anyway.
Senior engineers and researchers can apply outside the listed roles. The bar is the same. The reply window is the same.
Apply: Security & Compliance Lead General application
Salary : $240,000 - $310,000