Security Engineer
Headway Inc is a global tech company, revolutionizing lifelong learning by creating digital products for over 150 million users worldwide. Our mission is to help people grow. We’re proud to be ranked 4th among the World’s Top EdTech Сompanies by TIME magazine. We believe lifelong learning should be accessible, personalized, and impactful to each individual. That’s how we change the world and why we bring together exceptional minds.
Our team is the core of our achievements. We believe in people and shared values SELECT. That’s why, together with Rostyslav Vasiukov, CTO at Headway Inc, we’re looking for a Security Engineer to own the security function for the company.
Why do we need you?
Security work already happens across Infrastructure and Engineering, but ownership is fragmented. As Headway Inc scales and our AI transformation accelerates, we need a single person who can see the complete risk picture, make clear trade-offs, and drive the most important issues to resolution.
We’re looking for someone who can turn separate security activities into a coherent company-wide function: setting priorities, creating clear accountability, and helping teams make secure decisions without slowing the business down.
How will you work?
This is our only dedicated security role today. You will report directly to the CTO and have the autonomy to shape how security operates across the company.
You will partner with IT Infrastructure, Core Platform, and teams driving AI adoption. Your role is not to execute every security task alone, but to set risk-based priorities, establish clear ownership, align teams, and ensure the most important risks are addressed.
You will build on an existing foundation across Google Workspace, GCP, and GitLab SecOps, turning existing tools and practices into a coherent and scalable security system.
What will you own?
Corporate Security. Your primary focus from day one:
- Own and continuously improve the company’s corporate security posture across identity, access, endpoints, cloud infrastructure, and employee security.
- Identify and prioritize the most important risks, balancing security needs with business impact.
- Strengthen incident detection, response, awareness, and operational readiness.
- Turn existing tools and initiatives into a coherent, repeatable security system.
Product Security. As you grow into the role:
- Partner with Core Platform and Engineering to integrate security into how products are designed, built, released, and monitored.
- Establish a clear approach to vulnerability management and security risks in code, dependencies, infrastructure, and critical product changes.
- Introduce practical controls that improve security without creating unnecessary delivery bottlenecks.
AI Security. As our AI transformation develops, you will:
- Define practical guardrails for using AI tools and building AI-enabled capabilities safely.
- Address risks related to sensitive data, access, third-party AI providers, and AI-enabled product features.
- Help teams understand what is allowed, what is restricted, and when security involvement is required.
- Enable fast AI adoption while keeping security built in by design.
Security ownership and visibility. Across all three areas:
- Maintain a company-wide view of security risks, priorities, owners, and progress.
- Coordinate security incidents and ensure corrective actions are completed.
- Communicate risks and trade-offs clearly to Engineering, Operations, and company leadership.
- Use automation and AI to make security operations more scalable and effective.
Who are you?
- You think like an owner, not an auditor. An over-permissioned IAM role, a GitLab pipeline with more access than it needs, a laptop that quietly fell out of compliance — you don’t wait for someone else to flag it or for it to show up on a report. You catch what the checklist misses.
- You’re hands-on by default. You read the logs, write the script, and configure the control yourself, without waiting for someone else to grant access or open a ticket.
- You can run a domain start to finish. Whether that’s an identity system, a cloud environment, or a fleet of endpoints — spotting the gap, prioritizing it against everything else competing for attention, closing it, and proving it stayed closed.
- You put AI and automation to real use — triaging alerts, monitoring for anomalies across cloud and endpoint logs, and clearing routine work fast, not just experimenting with it on the side.
- Your judgment is grounded in business impact, not just severity scores — you know an exposed admin credential matters more than a stale test account, and you act accordingly.
- You work as a partner to the business. You’re able to explain a risk to an engineer, the CTO, or a lawyer in language each of them relates to, and focused on finding a safe way forward rather than blocking progress.
- You drop your own assumptions fast. The moment the data tells you a risk isn’t what you thought, you adjust easily — and you’re just as quick to pick up a domain you’ve never owned before.
- You run autonomously across identity, cloud, and code — no ready backlog, no one setting your tasks — you build the plan, chase the priorities, and own the outcome.
What do we offer?
- Work within an ambitious team on a socially impactful education product.
- An office with a reliable shelter, generators, satellite internet, and other amenities.
- Access to our corporate knowledge base and professional communities.
- Personal development plan.
- Compensation for English language learning, external training, and courses.
- Medical insurance and full sick leave compensation.
- Company doctor and massage in the office.
- Sports activities: running, yoga, boxing, and more.
- Corporate holidays: we go on a week-long paid holiday to rest and recharge twice a year. Besides that, we provide 20 paid vacation days per year.
- Supporting initiatives that help Ukraine.
Are you interested? Send your CV!