Jobs / United States / Tremendous
Head of Security
Tremendous · 🇺🇸 New York, New York, New York, United States
Sponsorship verdict
Sponsorship possible
One solid signal, not two — worth applying, and worth asking about sponsorship early.
- Employer is on a government sponsor recordThe US Department of Labor certified 3 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Apr 2026) — the step every H-1B hire needs first. Source: LCA disclosure data (US Department of Labor (OFLC)).
- The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
- No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
- Confirmed live todayWhen a source last listed this job as open.
US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).
A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.
Or apply yourself on the official page →
Sponsor Radar — Tremendous
The US Department of Labor certified 3 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Apr 2026) — the step every H-1B hire needs first. Source: LCA disclosure data (US Department of Labor (OFLC)).
Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Tremendous →
About the role
Tremendous is the global platform built for businesses to send payoutsâgift cards and moneyâto anyone, anywhere, instantly. We're trusted by 20,000+ organizations, from startups to giants like Atlassian, MIT, and United Way, to reach millions of recipients worldwide. We're profitable and growing without outside investors. We're fully remote, with a high-documentation, low-meeting culture that leaves more time for the work that mattersâand for your life outside it. Our employee NPS sits in the high 80s. We move billions of dollars through our systems. That makes security existential, and it's why we're making our first dedicated security hire. About The Role You'll be our first Head of Security. There's already a real foundation hereâbug bounty, pen tests, automated code and configuration scanning on the production and code side, phishing simulations on the people side. Youâll add to it across access and identity, SecOps and monitoring, incident response, vendor security, employee security practices, and policy. You'll own the whole posture. This is a player-coach role. Early on, you'll do the scoping and the hands-on work yourself; this is not a role where you direct from above. As the work demands it, we're fully prepared to build a team hereâand we're looking to you to define what that team should be and when. You'll report to the VP of Engineering , Tremendous' most senior technical leader. We've deliberately placed security with Engineering so you're set up to drive real implementation fastâembedded with the people whose work you're securing, not siloed in a compliance function. As the security function matures, we'll revisit this. What You'll Do • Own Tremendous' security posture end-to-end, partnering with our engineering team on production infrastructure and code security. • Assess where we have gaps, prioritize them, and tackle our highest-leverage gaps first. Weâll have opinions, but you own the prioritization and implementation. • Treat incident response as core, not afterthought. We may not be able to prevent a breach, but your job is making sure it's small, contained, and that we know exactly what to do. • Drive security as a cultural shift across the companyâintroducing controls incrementally, working with teams rather than over them. "Yes, and," not "no." • Lead our AI-security posture. We invest heavily in AI tooling; your job is to manage that risk and enable it, not to ban it. • Define when and how to staff up the security function, and hire your own team. What You'll Bring • Real, hands-on security experience at a company that scaledâideally as an early security hire who grew with the business through high growth. • Deep experience in at least one core security domainâproduct/production security, security operations, or access/identity and policyâwith enough range to reason across the others. You defined the security posture, not just executed someone elseâs playbook. • An engineer's mindset. You reach for code to solve problems and can read our codebase and understand our infrastructure (Ruby on Rails; TypeScript + React; PostgreSQL; Google Cloud). You won't write much day-to-day, but you're not lost in the code. • Judgment over checklists. You can explain the actual risk of a given decision, hold a firm line where it matters, and give ground where "best practice" doesn't apply to us or real business need pulls the other way. You can hold your own in a debate about whether to open up broad data access for AI tooling. • Bedside manner. You drive hard change by bringing the team around to your point of view, rather than just telling them no. Engineers and the rest of the company want to work with you. • Experience building or co-building a small security team is a plus