Director of Information Security

Fetch
Fetch

IT

Remote

USD 160k-200k / year + Equity

Posted on Aug 29, 2026
Director of Information Security
Remote
Technology
Remote
Full-time
What we’re building and why we’re building it.
Fetch helps people live rewarded every day, with a vision to become the rewards destination for everyone. We turn everyday activities into meaningful rewards, whether it’s grocery shopping, grabbing a quick meal, or playing a favorite mobile game. To date, we’ve awarded more than $1 billion in Fetch Points to our users.
Each day, more than 13 million receipts are submitted on Fetch, providing visibility into over $212 billion in gross merchandise value. This creates the largest retail-agnostic, SKU-level view of household spending, powering Fetch as an outcomes-based advertising platform that helps brands acquire and retain lifelong consumers.
The Fetch app is available on the App Store and Google Play, with more than 6 million five-star reviews from a highly engaged and loyal user base.
It’s not just our users who believe in Fetch: with investments from Softbank, ICONIQ, DST, Greycroft, and partnerships ranging from challenger brands to Fortune 500 companies, Fetch is reshaping how brands and consumers connect in the marketplace. When you work at Fetch, you play a vital role in a platform that drives brand loyalty and creates lifelong consumers with the power of Fetch points. User and partner success are at the heart of everything we do, and we extend that same commitment to our employees.
At Fetch, we value curiosity, adaptability, and the confidence to explore new tools, especially AI, to drive smarter, faster work. You don’t need to be an expert, but you should be ready to learn quickly and think critically. We welcome learners who move fast, challenge the status quo, and shape what’s next, with us. Ranked as one of America’s Best Startup Employers by Forbes for two years in a row, Fetch fosters a people-first culture rooted in trust, accountability, and innovation. We encourage our employees to challenge ideas, think bigger, and always bring the fun to Fetch.

Position Summary

The Director of Information Security owns Fetch's security function end to end: vulnerability management and AppSec, incident response and forensics, security architecture, GRC/compliance, third-party risk, and security awareness. This role is the senior full-time security leader for the company, taking day-to-day ownership of the security program.
The Director of Information Security is the dedicated, always-on owner of the security posture; someone who can run point on a critical incident, drive a vulnerability program to completion, and build the compliance backbone the company needs as it scales.

Role Purpose

  • Own the security function's day-to-day execution.
  • Reduce the company's exposure to high-blast-radius security risk, AI agent architecture, and application security.
  • Build a mature, auditable, and scalable security program (policy, controls, evidence, reporting) ahead of compliance and customer-trust demands.
  • Lead and grow a Security team, providing the people management the function has lacked.
  • Serve as the primary technical authority and incident commander for security events.
  • Represent Information Security credibly to executives, auditors, customers, and partners.

Key Responsibilities

1. Security Engineering & Vulnerability Management

  • Own the AppSec and vulnerability management program (Snyk and adjacent tooling), including pack ownership, CI/CD security gating, and repository risk classification processes.
  • Drive vulnerability remediation SLAs and hold engineering accountable to them.
  • Continuously mature the program from reactive scanning toward proactive, gated prevention.

2. Incident Response & Forensics

  • Act as an incident commander for security incidents, including coordinating cross-functional response, containment, and communication.
  • Own the bug bounty and continuous penetration testing disclosure program: triage, validation, remediation tracking, and researcher communication.
  • Facilitate post-incident reviews and root-cause analysis, with particular attention to recurring architectural risk patterns.
  • Ensure remediation of systemic issues, not just point fixes and elevate platform-level fixes when the same root cause recurs across incidents.

3. Security Architecture & Emerging Risk

  • Own security architecture review for new systems, platforms, and AI agent deployments, including AI agent identity and access patterns (eg, cross-app access, delegated identity).
  • Maintain security standards for cloud infrastructure, endpoint protection, and network/edge security.
  • Partner with IT Operations on identity-related risk (entitlement sprawl, contractor and non-employee access, and access governance) providing the security requirements and risk lens that IT Operations executes against.

4. GRC, Policy & Compliance

  • Own the security policy library, risk register, and control framework; keep them current and audit-ready.
  • Lead internal and external audits and assessments, coordinating evidence collection across IT, Engineering, and Legal.
  • Report program maturity, open risk, and remediation progress to executive leadership on a regular cadence.
  • Oversee processes to update and maintain the Enterprise Security Risk Register.

5. AI Governance & Emerging Technology Risk

  • Partner with the Chief AI Officer on the security dimensions of AI governance, including enforcement of AI acceptable-use policy and identification of security risk in new AI tooling and agent deployments.
  • Provide the security review and risk sign-off for new AI platforms, agents, and integrations prior to broad rollout.

6. Third-Party & Vendor Risk

  • Own vendor and third-party security risk assessment for new tools, integrations, and contractors.
  • Maintain a defensible, repeatable process for evaluating vendor security posture before onboarding.

7. Security Awareness & Culture

  • Own company-wide security awareness programming, phishing simulation, and targeted training following incidents or audit findings.
  • Build blameless, clear communications that raise the organization's security literacy without creating fear or confusion.

8. Team Leadership & People Management

  • Hire, coach, and develop the Security Engineering team.
  • Set team priorities, run performance management, and build a growth path for security engineers.
  • Establish team operating rhythm: on-call/incident rotation, backlog grooming, and technical review standards.

9. Executive & Cross-Functional Communication

  • Own the security content in recurring executive reporting.
  • Represent Information Security in cross-functional forums (Legal, AI governance, IT Operations, Engineering leadership).
  • Escalate material risk, resourcing gaps, or unresolved cross-functional blockers promptly and clearly.


Required Qualifications

  • 7+ years in information security, including meaningful experience in application security, incident response, and security architecture.
  • Demonstrated experience running vulnerability management programs at scale (eg, Snyk or comparable tooling).
  • Direct incident command experience, including coordinating cross-functional response to significant security events.
  • People management experience, ideally building or scaling a security engineering team.
  • Working knowledge of cloud security, identity and access management concepts, and modern AI/agent architecture risk.
  • Strong written and verbal communication skills, including comfort presenting to executive audiences.

Preferred Qualifications

  • Experience with bug bounty/responsible disclosure program management.
  • Experience building or maturing a GRC program, including audit and compliance framework experience (SOC 2, ISO 27001).
  • Familiarity with AI agent security risk, including MCP-style tool/agent architectures and identity delegation patterns.
  • Experience partnering with AI governance or data governance functions.
  • Relevant certifications (CISSP, CISM, or equivalent).

Core Competencies

  • Incident command and crisis leadership
  • Security architecture and risk assessment
  • Program and process maturity building
  • People leadership and coaching
  • Executive communication
  • Cross-functional influence without direct authority over partner teams
  • Judgment under ambiguity and time pressure
At Fetch, we'll give you the tools to feel healthy, happy and secure through:
  • Equity: We offer full-time employees equity in Fetch, so that everyone can benefit from Fetch’s growth.
  • 401k Match: Dollar-for-dollar match up to 4%.
  • Benefits for humans and pets: We offer comprehensive medical, dental and vision plans for everyone including your pets.
  • Continuing Education: Fetch provides ten thousand per year in education reimbursement.
  • Employee Resource Groups: Take part in employee-led groups that are centered around fostering a diverse and inclusive workplace through events, dialogue and advocacy. The ERGs participate in our Inclusion Council with members of executive leadership.
  • Paid Time Off: On top of our flexible PTO, Fetch observes 9 paid holidays, as well as our year-end week-long break.
  • Robust Leave Policies: 20 weeks of paid parental leave for primary caregivers, 14 weeks for secondary caregivers, and a flexible return to work schedule.
  • Calvin Care Cash: Employees who are welcoming new family members will also receive a one time $2,000 incentive to assist employees with covering the cost of childcare, clothing, diapers and much more!
  • Flexible Work Environment: Collaborate with your team in one of our stunning offices, or you can work fully remotely from anywhere in the US. We’ll ensure you are equally equipped with the hardware and software you need to get your job done in the comfort of your home. (applicable for most roles)
Fetch is an equal opportunity employer that embraces diversity, inclusion, and respect for all individuals. We do not discriminate on the basis of race, color, religion, gender, gender identity or expression, sexual orientation, age, national origin, marital status, veteran status, disability, or any other characteristic protected by applicable law. Our commitment to inclusivity ensures that everyone is treated with dignity and has the opportunity to succeed based on their talent, skills, and potential.
Fetch also provides reasonable accommodations to qualified individuals with disabilities or those with sincerely held religious beliefs, as required by law. If you need assistance with the application process or require an accommodation, please contact us at accommodations@fetch.com.
Ready to apply?
Powered by
First name *
Last name *
Email *
Phone number *
LinkedIn URL *
Resume *
Click to upload or drag and drop here
Preferred Name
What are your pronouns?
Are you legally authorized to work in the U.S.? *
Will you now or in the future require sponsorship by our company to attain or maintain your employment eligibility (e.g. H-1B visa status)? *
Please review our Privacy Policy and acknowledge below: https://fetch.com/employee-privacy-policy *
Fetch Rewards uses technology tools with artificial intelligence capabilities to help our recruiting team review applications and manage the hiring process. These tools assist (but do not replace) our recruiters and hiring managers, who make all employment decisions. Your information will not be used in any solely automated hiring decision. You may contact talent@fetchrewards.com with questions or to request accommodations or opt-out of use of AI in processing your application. For full details on how we collect, use, and protect your personal information during the recruiting process, please review our Notice at Collection for Employees and Applicants https://fetch.com/employee-privacy-policy. *
What led you to apply to Fetch? *
Pursuant to my application for employment with Fetch Rewards, I acknowledge that I may be asked to demonstrate certain knowledge, skills, abilities, and/or experiences related to my potential ability to perform the prospective duties and responsibilities for the position(s) for which I am being considered (herein after the “Demonstration”). With my confirmation below, I hereby acknowledge the following: I will not be compensated for time spent participating in the Demonstration. I am not guaranteed employment with Fetch Rewards by participating in the Demonstration. I am not displacing any existing Fetch Rewards employees by participating in the Demonstration, nor completing any task that would otherwise be assigned to any existing employees or contractors of Fetch Rewards. Fetch Rewards’s only interest in the Demonstration is that it allows them to evaluate me as a candidate for employment. The Demonstration does not provide any tangible work or work product of value to Fetch Rewards’ business. *
Are you currently located in the United States and able to work in the U.S. for this role? *
Describe the most significant security incident you personally led as the incident commander. What happened, what decisions were you accountable for, how did you coordinate Engineering and other stakeholders, and what systemic changes did you drive afterward to prevent the issue from recurring? *
What are your base salary expectations for your next role? *
Voluntary Self-Identification
To comply with government reporting requirements, we invite candidates to participate in the self-identification survey below. Your completion of this form is entirely optional, and your decision will neither influence the hiring process nor any subsequent stages. Any information you choose to share will be kept confidential and stored in a secure file. As outlined in our Equal Employment Opportunity policy, we uphold a commitment to non-discrimination based on any protected group status specified in applicable laws.
Gender
Race
Race and ethnicity descriptions
Voluntary Self-Identification of Veteran Status
VEVRAA requires Government contractors to take affirmative action to employ and advance in employment protected veterans. To help us measure the effectiveness of our outreach and recruitment efforts of veterans, we are asking you to tell us if you are a veteran covered by VEVRAA. If you believe that you belong to any of the following categories of protected veterans, please indicate by making the appropriate selection.
Veteran status descriptions
Disabled veteran
A veteran who served on active duty in the U.S. military and is entitled to disability compensation (or who but for the receipt of military retired pay would be entitled to disability compensation) under laws administered by the Secretary of Veterans Affairs, or was discharged or released from active duty because of a service-connected disability
Recently separated veteran
A veteran separated during the three-year period beginning on the date of the veteran's discharge or release from active duty in the U.S military, ground, naval, or air service
Active duty wartime or campaign badge veteran
A veteran who served on active duty in the U.S. military during a war, or in a campaign or expedition for which a campaign badge was authorized under the laws administered by the Department of Defense
Armed Forces service medal veteran
A veteran who, while serving on active duty in the U.S. military ground, naval, or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985 (61 Fed. Reg. 1209).
Veteran status
Req ID: FET-985