Director, Security and Compliance

Posted 2 days ago

This is a fully remote position, open to applicants in United States, +1 more country.

📋 Description

• Oversee security, compliance, privacy, and IT operations across the organization.

• Lead compliance programs for SOC 2 Type 2, GDPR, CCPA/CPRA, and Shopify partners through audits and assessments by third parties.

• Manage security policies, risk management, and vendor risk management initiatives.

• Conduct regular access reviews across all company systems.

• Maintain the Trust Center and assist the Sales team with customer security evaluations and questionnaires.

• Direct security awareness training and processes related to the personnel lifecycle concerning security.

• Assist with cyber insurance application processes and renewals.

• Manage business continuity and disaster recovery planning, including routine testing and validation.

• Facilitate tabletop exercises for incident response.

• Oversee data governance and privacy documentation, which includes the privacy policy, DPA, subprocessor list, and vulnerability disclosure policy.

• Handle data subject requests and support automated processes.

• Evaluate products, partnerships, data-sharing agreements, and contracts for their impact on privacy and security.

• Contribute to the development of AI governance.

• Manage the incident response program and coordinate notifications to customers and regulatory bodies in collaboration with the Legal team.

• Implement vulnerability management across cloud environments, code, and endpoints.

• Administer annual penetration testing from scoping to remediation.

• Collaborate with DevOps on CI/CD, deployments, and infrastructure security matters.

• Establish application security standards and promote their adoption within the Engineering team.

• Lead initiatives for authentication, logging, monitoring, secrets management, cloud security, identity and access management, network controls, and sensitive data monitoring.

• Manage email, domain, and DNS security protocols.

• Oversee the endpoint fleet, including device management, configuration baselines, patching, as well as hardware procurement and fulfillment.

• Administer and secure the company's SaaS platforms.

• Provide IT support to employees.

• Present quarterly reports to executive leadership regarding security, risk, and compliance matters.

• Manage tooling and budget decisions for a significant segment of the technology stack, including monitoring cloud spending.

• Advise the organization on matters of security and compliance.


⛳️ Requirements

• A minimum of 8 years of experience in security and Governance, Risk, and Compliance (GRC).

• Comprehensive ownership of a SOC 2 Type 2 program.

• Practical experience securing a major cloud environment, preferably GCP.

• Familiarity with GDPR, CCPA/CPRA, and best practices in data governance.

• Experience with compliance automation, cloud security, and macOS device management tools, such as Vanta, Orca, Iru, or similar.

• Proven experience in administering and securing a diverse SaaS environment, particularly in identity and access management.

• Background in building and testing Business Continuity Planning (BCP) and Disaster Recovery (DR) plans, as well as conducting incident response exercises.

• Proficiency in application security, including OWASP Top 10, SAST, CI/CD, and secrets management.

• Ability to influence stakeholders without direct authority and communicate risks in business terms to executives.

• Self-motivated in a dynamic, fully remote work environment.

• Experience within the Shopify ecosystem.

• Knowledge of workflow automation or scripting.

• Relevant certifications such as CISSP, CISM, CCSP, or CIPP.


🏝️ Benefits

• Fully remote work opportunities available within the U.S. and Canada.

• Flexible vacation policy.

• Generous holiday schedule.

• Parental leave benefits.

• Sick leave policy.

• Birthday holiday.

• Comprehensive health, dental, and insurance coverage for employees and their families at no cost.

• 401(k) retirement plans for employees based in the U.S.

• TFSA and RRSP retirement plans for employees in Canada.

• 3% contribution of gross salary regardless of location.

People also viewed

OpenLoop1 day ago

Staff Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Funcional Health Tech1 day ago

Information Security Governance Analyst (Mid-Level)

BR flagBrazil OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Salesforce1 day ago

Security Architect Lead

US flagArizona, +13 more statesFull-timeCybersecurity / Security Engineer$150.1k – $227k/year
ApplyView job
CNO Financial Group1 day ago

Lead IT Security Architect – SailPoint

US flagIllinois, +6 more statesFull-timeCybersecurity / Security Engineer$130.5k – $195.7k/year
ApplyView job
GuidePoint Security1 day ago

Security Architect – AD/Entra ID

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Applied Research Solutions1 day ago

Information System Security Engineer – ISSE

US flagOhio OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers