Salary
💰 $240,000 - $432,000 per year
Tech Stack
AWSCloudGoogle Cloud Platform
About the role
- Own and grow Duolingo's Security Program across Platform Security, Compliance, and Corporate IT
- Lead and scale a high-leverage organization, setting strategy and coaching managers and individual contributors
- Be responsible for engineering performance and execution across security teams
- Partner with Engineering, Legal, Audit, and Workplace to protect learner data and enable developer velocity
- Develop engineers and managers: define strategic goals, plan tasks, and review code
- Identify and catalog risks across the company and ensure timely remediation
- Design and implement systems and processes to improve security posture
- Partner with external consultants and vendors to integrate security tooling into products
Requirements
- Track record owning incident response, detection/response, and risk management; ability to translate risk to business tradeoffs
- Prior responsibility for endpoint management/MDM, identity/SSO/MFA, fleet security, SaaS administration, and helpdesk
- Modern application security leadership and mobile-app security experience
- Cloud security (AWS/GCP), identity/IAM, secrets management, and IaC controls experience
- Familiarity with one or more national and/or international regulations such as GDPR, ISO, and SOX
- Extensive experience in fast-growing, consumer-facing, data-driven startups, ideally mobile app based
- A Bachelor’s degree in Computer Science or related technical field
- Experience securing a large infrastructure deployment on AWS or Google Cloud
- Established security champions programs and developer self-service guardrails (policy-as-code, paved roads)
- Run a successful bug bounty; prior work with HackerOne/Bugcrowd
- Equity compensation
- World-class benefits (see link)
- Limitless learning opportunities, mentorship and collaboration with world-class minds
- Interview accommodations available (contact accommodations@duolingo.com)
ATS Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
incident responsedetection/responserisk managementendpoint managementidentity managementsingle sign-onmulti-factor authenticationcloud securitysecrets managementinfrastructure as code
Soft skills
leadershipcoachingstrategic planningperformance managementrisk assessmentcollaborationcommunicationtask planningcode reviewproblem-solving