Назад
Company hidden
4 дня назад

VP, Security (Cloud Security)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
c_level
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
VP, Security (Cloud Security): Building and scaling the security strategy, operations, engineering stack, and governance program for a commerce-enablement and fulfillment platform with an accent on cloud-native security, AI governance, M&A integration, and enterprise trust. Focus on establishing 24/7 detection and response, hardening CI/CD across a 200+ person engineering organization, and leading security readiness for international expansion and public-market scrutiny.

Location: Remote, United States

Company

Commerce-enablement technology and high-volume fulfillment services support checkout, warehousing, transportation, and order-management operations for DTC and B2B brands across the United States, Canada, and Europe.

What you will do

  • Set the security strategy and multi-year roadmap using NIST CSF 2.0, expanding audit scopes and certifications.
  • Establish AI governance for models, agents, and AI product development.
  • Build 24/7 detection and response through an MDR partnership and progressively bring detection engineering in-house.
  • Own incident response, security engineering, vulnerability management, penetration testing, and bug bounty operations.
  • Harden CI/CD across a 200+ person engineering organization with signed commits, SBOMs, dependency and secrets scanning, and SAST/DAST.
  • Lead M&A security diligence and integration, secure-by-default product design, business continuity, disaster recovery, and enterprise security reviews.

Requirements

  • 12+ years of security experience, including 5+ years leading a security function at a SaaS or platform company.
  • Strong cloud-native security experience with AWS or GCP, Kubernetes, microservices, CI/CD, and API security.
  • Hands-on ownership of M&A security diligence and integration.
  • Experience building programs against NIST CSF, SOC 2, and ISO 27001 and successfully completing audits.
  • Experience operating 24/7 detection and response in-house, through MDR, or in a hybrid model.
  • Ability to communicate residual risk, controls, and trade-offs to boards, executives, and engineering teams.

Nice to have

  • IPO readiness or public-company experience, including SEC cybersecurity disclosure, SOX IT controls, and board reporting.
  • Security experience across warehouses, manufacturing, robotics, OT, or IoT environments.
  • AI/ML security governance experience, ideally with NIST AI RMF.
  • EU or UK regulatory experience covering GDPR, DPF, NIS2, or the EU AI Act.

Culture & Benefits

  • Remote role based in the United States.
  • Opportunity to build the security organization, technical stack, and operating model for continued international expansion and M&A.
  • Existing foundation includes SOC 2 Type II attestation, a public Trust Center, EU-U.S. Data Privacy Framework certification, and an established security team.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →