← Back to jobs

Remote job

Director, Security and Compliance

Other Full-time Permanent United States

Job details

Not specified Salary
United States Eligibility
Director Experience
Full-time Employment

About this role

Role overview A fully remote organization is hiring a senior, hands-on individual contributor to own security, compliance, privacy, and IT across the company. Reporting to the COO with quarterly executive briefings, this leader will run compliance programs, protect cloud and applications, manage data governance and privacy, and keep a distributed workforce's systems secure and productive. The role is best suited to someone comfortable being the accountable owner across many domains who can drive initiatives through influence rather than formal authority.

Responsibilities

- Lead compliance programs including SOC 2 Type 2 (Security, Availability, Confidentiality), GDPR, CCPA/CPRA, and partner-platform security requirements through audits and third-party assessments. - Own company security policies, risk and vendor risk management, periodic access reviews, the Trust Center, customer security questionnaires, awareness training, and cyber insurance renewals. - Run business continuity and disaster recovery planning, including regular testing, validation, and incident response tabletop exercises. - Own the data governance program and privacy documentation (policy, DPA, subprocessor list, vulnerability disclosure policy), manage data subject requests, and review new products, partnerships, and agreements for privacy and security impact. - Lead the incident response program, vulnerability management across cloud, code, and endpoints, annual penetration testing, and partner with DevOps/Engineering on CI/CD, deployments, and infrastructure. - Set application security standards, define secrets management, secure the cloud environment (identity, network, monitoring), manage email/domain/DNS security, and run IT operations including endpoint fleet, SaaS administration, and support for a remote workforce.

Requirements

- 8+ years in security and GRC, including end-to-end ownership of a SOC 2 Type 2 program. - Hands-on experience testing BCP/DR plans and running incident response exercises. - Application security fluency (e.g., OWASP Top 10, SAST, CI/CD, secrets management) sufficient to set standards and partner credibly with engineers. - Ability to influence without authority and communicate risk to executives in business terms. - Self-direction in a fast-moving, fully remote environment with strong prioritization, documentation, and automation habits. - Experience in the Shopify ecosystem, workflow automation/scripting, and certifications such as CISSP, CISM, CCSP, or CIPP.

Benefits and work setup

- Fully remote across the U.S. and Canada, with flexible vacation, generous holidays, parental leave, sick time, and a birthday holiday. - 100% employer-paid health, dental, and insurance coverage for employees and their families, plus a 3% gross salary retirement contribution (401(k) for U.S. employees, TFSA/RRSP for Canadian employees). - U.S. base pay range of $175,000-$200,000 USD annually, varying by location, knowledge, skills, and experience.

Skills detected in the listing

GDPRCCPAGCP
Detected Oct 7, 2026
Last verified Oct 8, 2026

Hidden Jobs Access

Unlock application links

Read the full job details for free. An active Hidden Jobs Access subscription is required to open the original application link.

Weekly

FREE $6.99/week after trial
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching
  • Cancel anytime before day 7

Monthly

$35.99 $17.99 /month
  • 35% cheaper than weekly
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching

Lifetime

$99.99 $49.99 /forever
  • One-time payment
  • Original application links
  • Daily or weekly job alerts
  • Premium filters and CV matching
Hidden Jobs gives subscribers direct access to original application links
Offer ends in 00:00:00 Your profile-fit rate expires at midnight