Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Rebuy Engine

Director, Security and Compliance

Rebuy Engine

. Own security, compliance, privacy, and IT across the company .

Posted 10/6/2026full-timeRemote • United States, CanadaLead💰 $175,000 - $200,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive expertise in security, compliance, and risk management, with a strong focus on SOC 2 Type 2, GDPR, and CCPA/CPRA. Proficient in leading security initiatives, incident response, and data governance while effectively communicating risks to executive leadership.

Highest-signal resume keywords
SOC 2 Type 2 Program OwnershipCloud Security (GCP Preferred)Compliance Automation ExperienceApplication Security Fluency (OWASP Top 10)Certifications (CISSP, CISM, CCSP, CIPP)

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security ComplianceRisk ManagementData GovernanceIncident ResponseVulnerability ManagementBusiness Continuity PlanningDisaster RecoveryIdentity and Access ManagementApplication Security StandardsWorkflow Automation
Soft Skills
Influencing Without AuthorityEffective CommunicationSelf-Direction
Tools & Technologies
VantaOrcaIruSaaS PlatformsCI/CD ToolsMacOS Device Management
Certifications & Qualifications
CISSPCISMCCSPCIPP
Industry Keywords
SOC 2 Type 2GDPRCCPA/CPRACyber InsuranceTrust CenterSales Security ReviewsAI GovernanceShopify Ecosystem

Tech Stack

Tools & technologies
CloudDNSGoogle Cloud PlatformMacOS

About the role

Key responsibilities & impact
  • Own security, compliance, privacy, and IT across the company
  • Lead SOC 2 Type 2, GDPR, CCPA/CPRA, and Shopify partner security compliance programs through audits and third-party assessments
  • Own security policies, risk management, and vendor risk management
  • Run periodic access reviews across company systems
  • Maintain the Trust Center and support Sales with customer security reviews and questionnaires
  • Lead security awareness training and security-related personnel lifecycle processes
  • Support cyber insurance applications and renewals
  • Own business continuity and disaster recovery planning, including regular testing and validation
  • Facilitate incident response tabletop exercises
  • Own data governance and privacy documentation, including the privacy policy, DPA, subprocessor list, and vulnerability disclosure policy
  • Manage data subject requests and supporting automated processes
  • Review products, partnerships, data-sharing arrangements, and agreements for privacy and security impact
  • Help shape AI governance
  • Own the incident response program and coordinate customer and regulatory notifications with Legal
  • Run vulnerability management across cloud, code, and endpoints
  • Manage annual penetration testing from scoping through remediation
  • Partner with DevOps on CI/CD, deployments, and infrastructure security
  • Set application security standards and drive adoption across Engineering
  • Lead authentication, logging, monitoring, secrets management, cloud security, identity and access, network controls, and sensitive-data monitoring initiatives
  • Own email, domain, and DNS security
  • Manage the endpoint fleet, including device management, configuration baselines, patching, and hardware procurement and fulfillment
  • Administer and secure company SaaS platforms
  • Provide IT support to employees
  • Report quarterly to executive leadership on security, risk, and compliance
  • Own tooling and budget decisions for a significant portion of the technology stack, including cloud-spend monitoring
  • Advise the company on security and compliance

Requirements

What you’ll need
  • 8+ years in security and GRC
  • End-to-end ownership of a SOC 2 Type 2 program
  • Hands-on experience securing a major cloud environment; GCP preferred
  • Working knowledge of GDPR, CCPA/CPRA, and data governance practices
  • Experience with compliance automation, cloud security, and macOS device management tools such as Vanta, Orca, Iru, or equivalents
  • Experience administering and securing a broad SaaS environment, including identity and access management
  • Experience building and testing BCP/DR plans and running incident response exercises
  • Application security fluency, including OWASP Top 10, SAST, CI/CD, and secrets management
  • Ability to influence without authority and communicate risk to executives in business terms
  • Self-direction in a fast-moving, fully remote environment
  • Experience in the Shopify ecosystem
  • Workflow automation or scripting experience
  • Certifications such as CISSP, CISM, CCSP, or CIPP

Benefits

Comp & perks
  • Fully remote work within the U.S. and Canada
  • Flexible vacation policy
  • Generous holiday schedule
  • Parental leave
  • Sick policy
  • Birthday holiday
  • 100% free health, dental, and insurance coverage for employees and their families
  • 401(k) retirement plans for U.S. employees
  • TFSA and RRSP retirement plans for Canadian employees
  • 3% contribution of gross salary regardless of location