
51 - 200 employees
Founded 2016
🛍️ eCommerce
🤝 B2B
👥 B2C
💰 Series A on 2022-03
eCommerce • B2B • B2C
Reach is a global ecommerce optimization platform that simplifies cross-border transactions for businesses. They provide a comprehensive Merchant of Record service that facilitates international sales, managing aspects like global tax compliance and fraud protection. Their solutions empower retailers, digital brands, SaaS companies, and B2B wholesalers to enhance the customer experience by offering localized payment options and seamless integration with popular ecommerce platforms. Reach aims to help businesses expand internationally, reduce costs, and maximize conversion rates.
🕒 April 27
Improve your chances of getting an interview by checking your resume score before you apply.

51 - 200 employees
Founded 2016
🛍️ eCommerce
🤝 B2B
👥 B2C
💰 Series A on 2022-03
eCommerce • B2B • B2C
Reach is a global ecommerce optimization platform that simplifies cross-border transactions for businesses. They provide a comprehensive Merchant of Record service that facilitates international sales, managing aspects like global tax compliance and fraud protection. Their solutions empower retailers, digital brands, SaaS companies, and B2B wholesalers to enhance the customer experience by offering localized payment options and seamless integration with popular ecommerce platforms. Reach aims to help businesses expand internationally, reduce costs, and maximize conversion rates.
• Vulnerability management and offensive testing: Own the vuln lifecycle end-to-end — intake, triage, prioritization, risk acceptance, ticketing to dev teams, and remediation within SLA — and manage external pen tests and targeted assessments. Report regularly on status, SLA performance, and trends. • Security operations and incident response: Manage our MSSP partner for 24/7 SIEM and SOC monitoring; ensure telemetry, detections, and playbooks match our threat model. Serve as incident commander for real events, and run regular tabletops and post-incident reviews. • Policy, controls, and risk: Define and maintain Reach’s security policies and control framework. Design, implement, and measure the effectiveness of controls; maintain a risk register; and surface material risk decisions to leadership. • Compliance and audits: Own SOC 2 Type II and PCI DSS end-to-end with continuous control monitoring and evidence collection between audits. Serve as the primary contact for external auditors. • Application and cloud security: Partner with engineering on secure SDLC, threat modeling for new products and features, SAST/DAST/SCA coverage, and cloud security posture (IAM, configuration, workload protection). • Identity and access management: Own IAM policy, periodic access reviews, privileged access, and joiner/mover/leaver processes, in partnership with IT and People. • Third-party and customer security: Run Reach’s vendor risk program (due diligence, questionnaires, DPAs, ongoing monitoring) and own responses to customer and prospect security reviews. • Security awareness and training: Run phishing simulations, ongoing and role-targeted training, and regular company-wide sessions on new threats and best practices. • Executive reporting: Provide regular security posture updates with meaningful metrics (MTTD/MTTR, patch latency, control coverage, phishing outcomes, audit readiness). • People, budget, and tooling: Act as a mentor for your report; own the security budget and tool stack — evaluating, procuring, rationalizing, and retiring tools as the program matures.
• 8+ years in information security, with 3+ years leading a security program or a major security function. • Direct experience owning SOC 2 Type II audits end-to-end; PCI DSS experience strongly preferred. • Proven, hands-on ownership of vulnerability management programs at scale. • Experience managing an MSSP/MDR relationship for SIEM and 24/7 SOC. • Strong application and cloud security fundamentals, with hands-on experience in AWS, GCP, or Azure, and the ability to partner credibly with engineering. • Experience leading incident response end-to-end, including cross-functional coordination and working with external parties. • Experience writing and operationalizing security policies against recognized frameworks (NIST CSF, ISO 27001, CIS Controls). • Excellent written and verbal communication — credible with engineers, executives, auditors, and customers. • Comfortable as a player-coach in a lean environment, with a strong sense of ownership and bias for action. • Additional Assets • Experience in fintech, payments, or ecommerce — ideally cross-border or merchant-of-record. • Prior experience standing up or scaling a security program at a growth-stage company. • Familiarity with GRC/continuous compliance platforms (e.g., Vanta, Drata, Secureframe). • AWS experience (our primary cloud) and Atlassian suite (Jira, Confluence) for workflow and documentation. • Formal people-management experience. • Relevant certifications (e.g., CISSP, CISM, CCSP).
• Competitive compensation • Flexible remote work • Comprehensive benefits • Opportunity to build and own a security function • Direct impact on a global commerce platform • Health insurance • Retirement plans • Paid time off • Professional development • Bonuses
Apply Now🕒 April 22
Application Security Manager at Workleap embedding security in products and development workflows. You will write code, build tooling, and ensure secure software delivery.
🇨🇦 Canada – Remote
💵 $150k - $180k / year
💰 Private Equity Round on 2023-06
⏰ Full Time
🟠 Senior
🔴 Lead
👮♂️ Cybersecurity / Security Engineer
Azure
Cloud
Python
🕒 April 22
Application Security Manager embedding security directly into products, pipelines, and development workflows at ShareGate. Working closely with developers to ensure secure software delivery.
🇨🇦 Canada – Remote
💵 $150k - $180k / year
⏰ Full Time
🟠 Senior
🔴 Lead
👮♂️ Cybersecurity / Security Engineer
Azure
Cloud
Python
🕒 April 15
Principal Product Manager helping GitLab turn product strategy into business impact across security offerings. Collaborating across teams to drive growth and business performance.
🇨🇦 Canada – Remote
💵 $145.6k - $312k / year
💰 Secondary Market on 2020-11
⏰ Full Time
🔴 Lead
👮♂️ Cybersecurity / Security Engineer
Cloud
🕒 April 11
Security Director supervising security efforts and program management at L3Harris across Canada. Managing government relations and compliance with industrial security policies.
🇨🇦 Canada – Remote
💵 $173.5k - $243.5k / year
⏰ Full Time
🟠 Senior
🔴 Lead
👮♂️ Cybersecurity / Security Engineer
🗣️🇫🇷 French Required
🕒 April 9
Director of Security & Infrastructure overseeing security operations and infrastructure at Workleap and ShareGate, to ensure efficient product delivery in a reliable and secure environment.
🇨🇦 Canada – Remote
💰 Private Equity Round on 2023-06
⏰ Full Time
🔴 Lead
👮♂️ Cybersecurity / Security Engineer
🗣️🇫🇷 French Required
AWS
Azure
Google Cloud Platform
Kubernetes