Search Remote Jobs

Director, Security and Compliance

Job not on LinkedIn

🔥 30 minutes ago

🌐 United States, Canada – Remote

infoinfo

💵 $175k - $200k / year

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Rebuy Engine

Rebuy Engine

51 - 200 employees

Founded 2017

🛍️ eCommerce

🤖 Artificial Intelligence

☁️ SaaS

💰 $17M Series A on 2023-02

eCommerce • Artificial Intelligence • SaaS

Rebuy Engine is a fully connected end-to-end personalization platform powered by AI, designed to enhance e-commerce experiences. The platform aids businesses in creating intelligent shopping experiences through data-driven insights, personalized product recommendations, and seamless integrations with major e-commerce platforms like Shopify Plus. With a focus on increasing conversion rates and average order value (AOV), Rebuy Engine empowers merchants to streamline their sales processes, optimize merchandising strategies, and ultimately drive more revenue across the customer journey.

📋 Description

• Own security, compliance, privacy, and IT across the company • Lead SOC 2 Type 2, GDPR, CCPA/CPRA, and Shopify partner security compliance programs through audits and third-party assessments • Own security policies, risk management, and vendor risk management • Run periodic access reviews across company systems • Maintain the Trust Center and support Sales with customer security reviews and questionnaires • Lead security awareness training and security-related personnel lifecycle processes • Support cyber insurance applications and renewals • Own business continuity and disaster recovery planning, including regular testing and validation • Facilitate incident response tabletop exercises • Own data governance and privacy documentation, including the privacy policy, DPA, subprocessor list, and vulnerability disclosure policy • Manage data subject requests and supporting automated processes • Review products, partnerships, data-sharing arrangements, and agreements for privacy and security impact • Help shape AI governance • Own the incident response program and coordinate customer and regulatory notifications with Legal • Run vulnerability management across cloud, code, and endpoints • Manage annual penetration testing from scoping through remediation • Partner with DevOps on CI/CD, deployments, and infrastructure security • Set application security standards and drive adoption across Engineering • Lead authentication, logging, monitoring, secrets management, cloud security, identity and access, network controls, and sensitive-data monitoring initiatives • Own email, domain, and DNS security • Manage the endpoint fleet, including device management, configuration baselines, patching, and hardware procurement and fulfillment • Administer and secure company SaaS platforms • Provide IT support to employees • Report quarterly to executive leadership on security, risk, and compliance • Own tooling and budget decisions for a significant portion of the technology stack, including cloud-spend monitoring • Advise the company on security and compliance

🎯 Requirements

• 8+ years in security and GRC • End-to-end ownership of a SOC 2 Type 2 program • Hands-on experience securing a major cloud environment; GCP preferred • Working knowledge of GDPR, CCPA/CPRA, and data governance practices • Experience with compliance automation, cloud security, and macOS device management tools such as Vanta, Orca, Iru, or equivalents • Experience administering and securing a broad SaaS environment, including identity and access management • Experience building and testing BCP/DR plans and running incident response exercises • Application security fluency, including OWASP Top 10, SAST, CI/CD, and secrets management • Ability to influence without authority and communicate risk to executives in business terms • Self-direction in a fast-moving, fully remote environment • Experience in the Shopify ecosystem • Workflow automation or scripting experience • Certifications such as CISSP, CISM, CCSP, or CIPP

🏖️ Benefits

• Fully remote work within the U.S. and Canada • Flexible vacation policy • Generous holiday schedule • Parental leave • Sick policy • Birthday holiday • 100% free health, dental, and insurance coverage for employees and their families • 401(k) retirement plans for U.S. employees • TFSA and RRSP retirement plans for Canadian employees • 3% contribution of gross salary regardless of location

Apply Now

Similar Jobs

🔥 1 hour ago

Rithum

501 - 1000

🛍️ eCommerce

📣 Marketing

🤖 Artificial Intelligence

Staff Information Security Engineer securing AI adoption, products, and workforce at Rithum, a global commerce network. Building automated controls, AI security tooling, and threat models.

🔥 1 hour ago

AECOM

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Transit safety specialist leading FTA/APTA-compliant security and risk-management projects for AECOM, a global infrastructure consulting firm. Developing safety analyses, certifications, PTASPs, and client training.

🔥 3 hours ago

Beale Infrastructure

11 - 50

🏗️ Construction

📡 Telecommunications

🏠 Real Estate

Security design authority delivering physical and electronic protection systems for Beale’s hyperscale data center campuses. Establishing standards and overseeing design, construction quality, and tenant turnover.

🔥 7 hours ago

Peraton

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

AWS Cloud Security Engineer securing Peraton’s FedRAMP-authorized AWS infrastructure. Maintaining cloud controls, compliance monitoring, and ATO support for national security missions.

🔥 9 hours ago

Connected Logistics

51 - 200

📦 Logistics

💼 Consulting

🎖️ Defense

Cybersecurity Technology Management Analyst auditing federal information systems and ICS applications. Supporting DOD/DLA compliance, RMF documentation, vulnerability mitigation, and accreditation readiness.