Назад
Company hidden
5 дней назад

Senior Security, Compliance, Privacy and IT Leader

175 000 - 200 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior/lead
Английский
b2
Страна
US/Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security, Compliance, Privacy and IT Leader (Security/GRC/Cloud): Owning company-wide security, compliance, privacy, IT operations, and cloud protection for an intelligent commerce platform with an accent on SOC 2, data governance, incident response, and application security. Focus on building resilient security programs, securing cloud and SaaS environments, driving remediation with engineering teams, and advising executives on risk.

Location: Remote within the United States and Canada

Base salary: $175,000–$200,000 USD annually, varying by U.S. geographic market, knowledge, skills, and experience.

Company

hirify.global develops intelligent, personalized commerce experiences for direct-to-consumer brands.

What you will do

  • Own security, compliance, privacy, IT, risk management, and data governance across the company.
  • Lead SOC 2 Type 2, GDPR, CCPA/CPRA, Shopify security, audits, third-party assessments, and customer security reviews.
  • Develop business continuity and disaster recovery plans, test resilience, and lead incident response exercises and security incidents.
  • Secure cloud infrastructure, applications, CI/CD pipelines, identities, networks, endpoints, SaaS platforms, email, domains, and DNS.
  • Drive vulnerability management, penetration testing, remediation, authentication, logging, monitoring, and secrets management with DevOps and Engineering.
  • Report security, risk, and compliance matters to executive leadership and manage technology tooling and budgets.

Requirements

  • 8+ years of experience in security and GRC, including end-to-end ownership of a SOC 2 Type 2 program.
  • Hands-on experience securing a major cloud environment, preferably GCP, and administering a broad SaaS environment with identity and access management.
  • Working knowledge of GDPR, CCPA/CPRA, data governance, compliance automation, cloud security, and macOS device management tools.
  • Application security knowledge including OWASP Top 10, SAST, CI/CD, and secrets management.
  • Experience with business continuity and disaster recovery planning, incident response exercises, vulnerability management, and penetration testing.
  • Ability to influence without formal authority, communicate risk to executives, work independently, automate workflows, and support a fully remote environment.

Nice to have

  • Experience in the Shopify ecosystem.
  • Certifications such as CISSP, CISM, CCSP, or CIPP.
  • Workflow automation or scripting experience.

Culture & Benefits

  • Fully remote work within the United States and Canada.
  • Flexible vacation policy, holidays, parental leave, sick leave, and a birthday holiday.
  • Health, dental, and insurance coverage for employees and families.
  • Retirement benefits including U.S. 401(k), Canadian TFSA and RRSP options, plus a 3% gross salary contribution.
  • Collaborative environment focused on ownership, empathy, creativity, and long-term partnerships.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →