Playlab
Head of Privacy & Security
- Location
- US
- Arrangement
- Remote
- Employment type
- Full-time
- Level
- Director
- Posted
- 16 July 2026 (about 2 months ago)
Checked 26 days agoApplications go to the employer, never to RoleSprint
About this role
ABOUT PLAYLAB
Playlab is a tech non-profit dedicated to helping educators and students become critical consumers and creators of AI.
We believe that an open-source, community-driven approach is key to harnessing the potential of AI in education. We equip communities with AI tools and hands-on professional development that empowers educators & students to build custom AI apps for their unique context. Over 60,000 educators have published apps on Playlab – and the impact is growing every day.
At Playlab, we believe that AI is a new design material - one that should be shaped by many to bring their ideas about learning to life. If you're passionate about building creative, equitable futures for students and teachers, we hope you'll join us.
THE ROLE
Playlab seeks a Head of Security & Privacy to lead our security and privacy efforts and protect the students, educators, and partners who use the platform. You will drive the security engineering, compliance, and privacy programs forward with end-to-end ownership of risk and customer assurance. You will promote effective and thoughtful decision making to reduce uncertainty and increase organizational velocity.
The building blocks are in place, but the next phase of Playlab’s security, compliance, and privacy programs will require maturing and scaling with a growing organization. Playlab’s mission depends on safeguarding educational data for users around the world. Earning trust means delivering on a roadmap that spans tackling AI threats, tracking evolving privacy legislation, and building security automation that makes Playlab a leader in the space.
As a nonprofit, we're not chasing an IPO - trust and responsibility is a core part of why people choose to partner with us, and this role is a leader in that work.
EXAMPLES OF THE WORK
- Expand SIEM and detection engineering pipelines to alert on and investigate anomalies before they turn into incidents
- Standardize and enforce RBAC on critical systems, including non-human and AI agent identities
- Add LLM-assisted and highly contextual code analysis to security-relevant pull requests, addressing tenant isolation and prompt injection threats
- Design data de-identification and isolation approaches for privacy-by-design use cases
- Lead work on meeting best in class privacy requirements supporting our expansion into the EU
- Hire and grow your 1-2 other key members of the Privacy & Security team in the next 6 months
EXPECTATIONS
- Keep an up-to-date risk register and security roadmap, communicating clearly through regular updates
- Support engineering team with secure design reviews that provide actionable and tradeoff-informed recommendations
- Equip customer-facing teams with top-notch trust center content, including security knowledge bases and customer assurance collateral
- Lead SOC 2 compliance operations and audits to reduce overhead on engineering and support teams
- Lead the incident response function to ensure rapid recovery capabilities
- Partner with Trust and Safety on child safety and responsible AI deployments
- Support safely open sourcing code and data to meet our public good mission
- Work cross-functionally to build partnerships instead of roadblocks
QUALIFICATIONS
- 7+ years in security roles, with at least 3 years in leadership positions
- Background implementing security controls in fast-moving engineering organizations - you know how to balance security with velocity
- Demonstrated examples of projects tackling AppSec challenges and integrating with software development (DevSecOps)
- Experience securing container-based cloud environments (Playlab is on AWS EKS) including IAM, virtual network security, and logging and auditing capabilities
- Experience leading GDPR compliance and SOC 2 audits
- Excellent writing and communication abilities, turning complicated problems into actionable consensus
BONUS POINTS FOR...
- Background in education data privacy (e.g. FERPA, COPPA)
- Experience defending systems from AI threats (e.g. prompt injection)
- Experience in nonprofit or mission-driven organizations
TECHNOLOGIES
AWS, Kubernetes, Terraform, GitHub, Google Workspace, Vanta, Linear, OpenAI, Anthropic, Vercel
WHY JOIN US?
- Build the product & engineering team behind AI in education: You won't just manage engineers — you'll double a team and shape how it builds technology that's changing how 60,000+ educators across the globe use AI with their students. Much of what we build is headed toward the public domain.
- Real closeness to users: We're in schools every week — deep-dive 1:1s, group experimentation sessions, strategic planning with entire school districts. Engineering decisions here are grounded in real classrooms, not abstract personas.
- Impact over growth: We're a nonprofit focused on transformation, responsibility, and enabling both educators and students to drive the future of education with AI — as agents, not passive consumers. We're not optimizing for the lowest common denominator.
- Mission-aligned team: Join a small, passionate group committed to equity, creativity, and joyful learning.
- Flexible work: Enjoy a remote-first environment with autonomy and a strong culture of collaboration.
- Competitive pay & benefits: Includes salary, healthcare, retirement, generous time off, and opportunities for professional growth.
Eligible remote locations
- US
Related jobs
Ready to make a decision?
This role is either worth your time or it isn’t.
Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.
Nothing is submitted automatically. You choose what happens next.
About this listing
Published on Ashby under the board identifier Playlab, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.
RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.
Published 16 July 2026, last checked 26 days ago. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.