Director, Security and Compliance

New
R
RebuyE-commerce technology
Location: Remote - USFull-TimeDirector
Salary175,000 - 200,000 USD per year
Apply NowOpens the employer's application page

Job Details

Experience
8+ years in security and GRC
Required Skills
GCPCI/CD

Requirements

  • Bring 8+ years of experience in security and GRC.
  • Have end-to-end ownership experience for a SOC 2 Type 2 program.
  • Bring hands-on experience securing a major cloud environment; GCP is preferred.
  • Have working knowledge of GDPR, CCPA/CPRA, and data governance practices.
  • Have experience with compliance automation, cloud security, and macOS device management tools such as Vanta, Orca, or Iru, or equivalents.
  • Have experience administering and securing a broad SaaS environment, including identity and access management.
  • Have experience building and testing business continuity and disaster recovery plans and running incident response exercises.
  • Bring application security fluency, including OWASP Top 10, SAST, CI/CD, and secrets management.
  • Be able to influence without authority and communicate risk to executives in business terms.
  • Have experience in the Shopify ecosystem.
  • Workflow automation or scripting experience is listed as a qualification.
  • Certifications such as CISSP, CISM, CCSP, or CIPP are listed.

Responsibilities

  • Lead compliance programs, including SOC 2 Type 2, GDPR, CCPA/CPRA, and Shopify partner security requirements, through audits and third-party assessments.
  • Own security policies, risk management, vendor risk management, and periodic access reviews.
  • Maintain the Trust Center and support Sales with customer security reviews and questionnaires.
  • Own business continuity and disaster recovery planning, and facilitate incident response tabletop exercises.
  • Manage privacy documentation, data subject requests, and reviews of products, partnerships, data sharing, and contractual terms.
  • Lead security incident response, vulnerability management, and annual penetration testing.
  • Set application security standards and partner with DevOps and Engineering on CI/CD, infrastructure, authentication, monitoring, and secrets management.
  • Secure cloud, identity and access, network controls, email, domain, and DNS.
  • Manage endpoint devices and SaaS platforms, and provide IT support to employees.
  • Report to executive leadership and own security tooling and budget decisions.
View Full Description & ApplyYou'll be redirected to the employer's site
175,000 - 200,000 USD per year
Apply Now