安全与人工智能赋能主管
Head of Security & AI Enablement
Anrok 是领先的税务自动化平台,使企业能够在全球范围内扩展而无需面对合规复杂性。
随着数字经济在过去十年增长了六倍,软件公司从不再担心销售税,到现在需要监控风险敞口、计算税率并跨 20 多个美国州和许多国家提交税务申报。这给本应能与客户无缝交易的公司造成了关键瓶颈。
Anrok 通过连接计费和支付系统,端到端自动化税务监控、计算和申报,消除了这种复杂性。我们的统一平台处理不断变化的市政、州和联邦层面的税务法规,让公司可以专注于增长,而不是合规。
我们的客户包括:
- 40% 的福布斯 Top 50 AI 公司
- 20% 的福布斯 Top 100 Cloud 公司
- 像 Notion、Anthropic 和 Cursor 这样的顶级公司
我们正在为大大小小的公司实现合规的数字商业,获得来自 Spark Capital、Sequoia、Index 和 Khosla Ventures 等领先投资者超过 1 亿美元的资金支持。
我们正在寻找一位有经验的技术领导者,负责并推动 Anrok 的安全、IT 和 AI 操作系统的演进,以适应公司规模的扩大。作为我们首位安全与 AI 赋能负责人,你将负责身份管理、企业 IT、合规和信息安全、应用安全以及 AI 自动化能力——构建让快速成长的团队安全高效运作的系统,同时避免不可接受的风险或运营复杂性。这是一个高影响力职位,向我们的 COO 汇报,并直接影响 Anrok 作为一家公司的运行方式。
在这一职位中,你将:
- 与工程团队合作,通过威胁建模为关键系统建立最佳实践的应用安全,进行安全设计评审、漏洞接收与优先级排序、依赖项和软件供应链风险、渗透测试、CI/CD 中的安全测试、修复 SLA 和风险接受、产品安全事件响应以及面向客户的安全保证。
- 全权负责所有合规义务,包括 SOC 2 Type II、ISO 27001 和 GDPR ——作为审计、续期和跨职能准备的直接责任人。制定并执行随业务增长的安全策略、访问控制和治理框架。
- 负责企业 IT 基础设施和运营 ——包括终端设备管理、SaaS 堆栈管理以及 IT 支持 ——管理和
查看英文原文
Anrok is the leading tax automation platform enabling businesses to expand globally without compliance complexity.
As the digital economy has grown 6x over the last decade, software businesses have gone from not worrying about sales tax to needing to monitor exposure, calculate rates, and file returns across 20+ US states and many countries worldwide. This creates a critical bottleneck for companies that should be able to transact with customers everywhere.
Anrok eliminates this complexity by connecting with billing and payment systems to automate tax monitoring, calculations, and filing end-to-end. Our unified platform handles the ever-changing maze of tax laws at municipal, state, and federal levels—so companies can focus on growth, not compliance.
Our customers include:
- 40% of Forbes Top 50 AI companies
- 20% of Forbes Top 100 Cloud companies
- Top companies like Notion, Anthropic, and Cursor
We’re making compliant digital commerce a reality for companies big and small, backed by over $100M from leading investors including Spark Capital, Sequoia, Index, and Khosla Ventures.
We’re looking for an experienced technology leader to own and evolve Anrok's Security, IT, and AI operating system as we scale. As our first Head of Security & AI Enablement, you'll be the single owner of identity, corporate IT, compliance and information security, application security, and AI-automation capabilities—building the systems that let a rapidly growing team operate securely and efficiently, without unacceptable risk or operational complexity. This is a high-impact role reporting to our COO, with direct influence over how Anrok runs as a company.
IN THIS ROLE, YOU WILL
- Partner with Engineering to establish best-in-class application security through threat modeling for critical systems, secure design reviews, vulnerability intake and prioritization, dependency and software supply chain risk, penetration testing, security testing in CI/CD, remediation SLAs and risk acceptance, product security incident response, customer facing security-assurance.
- Own all compliance obligations end-to-end, including SOC 2 Type II, ISO 27001, and GDPR—serving as the DRI for audits, renewals, and cross-functional readiness. Develop and enforce security policies, access controls, and governance frameworks that grow with the business.
- Own corporate IT infrastructure and operations—including endpoint management, SaaS stack administration, and IT support—managing and developing our IT team.
- Establish strong AI governance in order to safely increase the organization's velocity. This will include: model approval and vendor management, data classification and model-use restrictions, agent identities and IAM, framework for human approvals, prompt-injection and data-exfiltration protections, logging and monitoring of agent actions, AI incident response, cost, quality, and business impact measurement.
- Build the infrastructure to support teams building AI-powered internal tools and infrastructure, deploying LLM-based automations, internal copilots, and agentic workflows to improve how Anrok operates at scale
- Partner with Legal and Finance on data privacy obligations, vendor risk management, and third-party security assessments
- Evaluate, procure, and manage the internal technology stack, ensuring we’re using the right tools as we scale
- Report on security and compliance posture to executive leadership as needed
WHAT EXCITES US
- 10+ years in IT, security, or a related technical role, with 3+ years in a leadership position at a scaling tech company
- Hands-on experience building or deploying AI/LLM-powered internal tools or automations—you default to AI-first solutions for operational problems
- Strong application security fundamentals—you can review AppSec findings, work with engineers on remediations, and evaluate risk without needing to write the code yourself
- Genuine familiarity with GDPR and international data privacy obligations, relevant to a fintech handling customer financial data across jurisdictions
- Track record of building lightweight but durable compliance and governance programs—practical, not checkbox theater
- Proven ownership of SOC 2 Type II renewals end-to-end—you’ve been the DRI, not just a contributor
- Technically credible with strong business fluency: you can present to a board, negotiate a vendor contract, and review a penetration test in the same week
- Self-starter who thrives in ambiguity, builds scalable systems, and knows when to automate vs. hire
- You’re curious and motivated to learn new tools — you've experimented with AI in your work or on your own, you're excited about what's possible, and you've built something with it (an application, a workflow, a creative solution to a real problem) that you can walk us through.
WHAT WE OFFER
- The equity upside of an early-stage startup with the product-market fit of a later-stage company.
- Daily lunch and snacks for those working out of our office hubs.
- Medical, dental, and vision insurance covered 100%.
- One Medical membership covered, flexible sick benefits, and more.
- Annual learning and development stipend for books, online courses, and conferences, as well as a curious team to share your learnings with.
- Home internet reimbursement stipend.
- Wellness reimbursement program.
- Annual team off-sites and in-person opportunities around our growing Anrok hubs.
- Home office setup stipend to ensure you have the equipment you need to thrive at work.
At Anrok, we embrace a dynamic and flexible hybrid work environment based out of our growing office hubs - San Francisco, New York City, Salt Lake City, and Dublin where we collaborate in-person 3 days per week.
Please be aware, job-seekers may be at risk of targeting by malicious actors looking for personal data. Anrok recruiters will only reach out via LinkedIn or email with an anrok.com http://anrok.com domain. Any outreach claiming to be from Anrok via other sources should be ignored.