
Director, Security and Compliance
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States, +1 more country.
• Oversee security, compliance, privacy, and IT operations across the organization.
• Lead compliance programs for SOC 2 Type 2, GDPR, CCPA/CPRA, and Shopify partners through audits and assessments by third parties.
• Manage security policies, risk management, and vendor risk management initiatives.
• Conduct regular access reviews across all company systems.
• Maintain the Trust Center and assist the Sales team with customer security evaluations and questionnaires.
• Direct security awareness training and processes related to the personnel lifecycle concerning security.
• Assist with cyber insurance application processes and renewals.
• Manage business continuity and disaster recovery planning, including routine testing and validation.
• Facilitate tabletop exercises for incident response.
• Oversee data governance and privacy documentation, which includes the privacy policy, DPA, subprocessor list, and vulnerability disclosure policy.
• Handle data subject requests and support automated processes.
• Evaluate products, partnerships, data-sharing agreements, and contracts for their impact on privacy and security.
• Contribute to the development of AI governance.
• Manage the incident response program and coordinate notifications to customers and regulatory bodies in collaboration with the Legal team.
• Implement vulnerability management across cloud environments, code, and endpoints.
• Administer annual penetration testing from scoping to remediation.
• Collaborate with DevOps on CI/CD, deployments, and infrastructure security matters.
• Establish application security standards and promote their adoption within the Engineering team.
• Lead initiatives for authentication, logging, monitoring, secrets management, cloud security, identity and access management, network controls, and sensitive data monitoring.
• Manage email, domain, and DNS security protocols.
• Oversee the endpoint fleet, including device management, configuration baselines, patching, as well as hardware procurement and fulfillment.
• Administer and secure the company's SaaS platforms.
• Provide IT support to employees.
• Present quarterly reports to executive leadership regarding security, risk, and compliance matters.
• Manage tooling and budget decisions for a significant segment of the technology stack, including monitoring cloud spending.
• Advise the organization on matters of security and compliance.
• A minimum of 8 years of experience in security and Governance, Risk, and Compliance (GRC).
• Comprehensive ownership of a SOC 2 Type 2 program.
• Practical experience securing a major cloud environment, preferably GCP.
• Familiarity with GDPR, CCPA/CPRA, and best practices in data governance.
• Experience with compliance automation, cloud security, and macOS device management tools, such as Vanta, Orca, Iru, or similar.
• Proven experience in administering and securing a diverse SaaS environment, particularly in identity and access management.
• Background in building and testing Business Continuity Planning (BCP) and Disaster Recovery (DR) plans, as well as conducting incident response exercises.
• Proficiency in application security, including OWASP Top 10, SAST, CI/CD, and secrets management.
• Ability to influence stakeholders without direct authority and communicate risks in business terms to executives.
• Self-motivated in a dynamic, fully remote work environment.
• Experience within the Shopify ecosystem.
• Knowledge of workflow automation or scripting.
• Relevant certifications such as CISSP, CISM, CCSP, or CIPP.
• Fully remote work opportunities available within the U.S. and Canada.
• Flexible vacation policy.
• Generous holiday schedule.
• Parental leave benefits.
• Sick leave policy.
• Birthday holiday.
• Comprehensive health, dental, and insurance coverage for employees and their families at no cost.
• 401(k) retirement plans for employees based in the U.S.
• TFSA and RRSP retirement plans for employees in Canada.
• 3% contribution of gross salary regardless of location.
OpenLoop
Funcional Health Tech
Salesforce
CNO Financial Group
Get handpicked remote jobs straight to your inbox weekly.