Head of Cyber Defense & Trust

Gong Gong · Enterprise · San Francisco, CA · Information Security

This role leads Cyber Defense Engineering and Identity and Access Management for an AI-native SaaS company. It involves architecting and operating a hyper-automated security operations function, securing AI-specific risks in data pipelines and model training, building a Zero-Trust identity ecosystem, and translating compliance requirements into security outcomes. The role requires a blend of technical depth and strategic leadership, with a focus on building and developing a security team.

What you'd actually do

  1. Design and operate a hyper-automated security operations function for a modern, multi-cloud (AWS, GCP, Azure) SaaS environment.
  2. Gong is an AI company, and that changes everything about your threat model. You'll architect security controls that address the unique risks of large-scale data pipelines, model training environments, and AI-generated intellectual property, domains where conventional frameworks fall short and first-principles thinking is required.
  3. Own and execute the enterprise-wide IAM strategy, unifying identity management across all cloud platforms, corporate environments, and the product itself.
  4. Partner with the broader security organization to ensure the technical foundation of Gong's cloud environment supports enterprise compliance requirements (SOC 2, ISO 27001, PCI, HIPAA, FedRAMP/NIST).
  5. Recruit, develop, and lead a high-performing, globally distributed team of security engineers and identity architects.

Skills

Required

  • 12–15+ years of progressive security experience
  • meaningful leadership in a high-growth SaaS or cloud-native environment
  • Deep CDE expertise
  • hands-on background in Security Engineering and/or Security Operations
  • designing detection pipelines, incident response playbooks, and automation frameworks at scale
  • Enterprise IAM mastery
  • proven track record designing and executing IAM strategies that span cloud platforms, SaaS applications, and corporate infrastructure
  • Zero Trust architecture
  • passwordless or MFA-first approaches
  • Multi-cloud fluency
  • practical experience securing workloads across AWS, GCP, and/or Azure
  • familiarity with modern CSPM, SIEM/SOAR, and endpoint security tooling (e.g., Wiz, Google SecOps, Sentinel, CrowdStrike)
  • Compliance and risk fluency
  • working knowledge of NIST CSF, NIST 800-53, SOC 2, and related frameworks
  • ability to turn them into security architecture decisions
  • Builder mentality with executive presence

Nice to have

  • Google SecOps
  • Wiz
  • Sentinel
  • CrowdStrike

What the JD emphasized

  • architecting one
  • AI-native SaaS company
  • unique risks of large-scale data pipelines, model training environments, and AI-generated intellectual property
  • first-principles thinking is required
  • Zero Trust principles
  • passwordless authentication
  • SOC 2
  • ISO 27001
  • PCI
  • HIPAA
  • FedRAMP/NIST