Cyncly Logo

Cyncly

Director - Security

Reposted One Month Ago
Remote
Hiring Remotely in United States
150K-175K Annually
Senior level
Remote
Hiring Remotely in United States
150K-175K Annually
Senior level
Lead and own global hosting and infrastructure operations across cloud (Azure), co-location, and hybrid environments. Manage major incident response, reliability, capacity planning, M&A infrastructure integrations, core infrastructure projects, security/compliance (SOC2, GDPR), and a distributed hosting operations team. Drive observability, automation, and DR readiness while partnering with enterprise architecture, security, and senior leadership to deliver scalable, secure hosting services.
The summary above was generated by AI

Job Title: Director - Security 

Location: USA / EST time zone

Contract: Permanent

About Us 

Cyncly is a global technology powerhouse with 2,400+ employees and 70,000+ customers across 100+ countries. Cyncly transforms the way customizable products and spaces are imagined, designed, sold, managed and made. Our end-to-end software solutions connect professional designers, retailers and manufacturers to the world's largest repository of product content. Today, our business spans across the Kitchen & Bath, Furniture, Window, Glass & Door, and Flooring industries with operations in North & South America, Europe, Asia Pacific and Africa. 

Cyncly brings over 30 years of experience to deliver more value for our customers through an expanded portfolio of end-to-end solutions. Our global presence allows us to provide world-class support and sales with a local touch, providing the best possible customer experience. 

Cyncly is now embarking on an exciting journey as we continue to expand through strong organic growth and complementary acquisitions, backed by leading growth private equity firms specialized in technology. 

About the Role
The Director – Security is a senior IT leadership role responsible for defining, executing, and continuously maturing Cyncly's global cyber security strategy, data protection programme, and information security posture. Reporting to the Head of IT & Cyber Security, this role is the primary owner of all security disciplines — from threat detection and incident response to security architecture, data governance, and regulatory compliance.
A critical element of this role is owning Cyncly's compliance obligations end-to-end, including achieving and maintaining SOC 2 Type II certification across Cyncly's global operations, and ensuring adherence to GDPR, ISO 27001, and other applicable frameworks. The Director will act as Cyncly's senior authority on all matters relating to information security risk, data privacy, and cyber resilience, partnering closely with Product, Engineering, Legal, and business leadership to embed security into the fabric of everything Cyncly does.

Key Responsibilities

Cyber Security Strategy & Leadership

  • Define and own Cyncly's global cyber security strategy, roadmap, and operating model, aligning security investment and priorities to business risk and growth objectives.
  • Build and lead a high-performing, globally distributed cyber security team, setting clear direction, developing talent, and fostering a culture of security awareness and accountability.
  • Act as the primary security advisor to the Head of IT & Cyber Security, CTO, and senior leadership, translating threats and technical risks into clear, business-relevant guidance; represent Cyncly's security posture to customers, auditors, regulators, and the Board.
  • Establish and govern security policies, standards, and procedures organisation-wide; drive continuous improvement through threat intelligence, industry benchmarking, and emerging best practices.

Compliance, Certifications & Regulatory Obligations

  • Own end-to-end accountability for Cyncly's SOC 2 Type II certification programme — including scoping, control design, evidence collection, auditor management, and remediation of findings — ensuring successful annual certification and ongoing continuous compliance.
  • Lead and maintain compliance with ISO 27001, GDPR, CCPA, and other applicable data protection regulations across all jurisdictions; serve as primary contact for external auditors, regulatory bodies, and certification authorities.
  • Develop and maintain a compliance calendar and evidence management framework, ensuring Cyncly is audit-ready at all times; proactively monitor the regulatory landscape to identify and address new obligations.
  • Collaborate with Legal, Finance, and HR to ensure organisation-wide policies — data retention, privacy notices, HR security controls, and supplier assurance — meet all compliance obligations.

Data & Information Security

  • Define and implement Cyncly's data classification framework, data governance policies, and information lifecycle management practices; oversee DLP controls, encryption standards, and data access management across all repositories, cloud platforms, and SaaS applications.
  • Embed data privacy by design into all product development, infrastructure, and business processes; manage end-to-end responses to DSARs, breach notifications, and privacy incidents in accordance with GDPR and local privacy laws.
  • Partner with Enterprise Architecture and Engineering to ensure all data flows, storage, and processing activities are documented, controlled, and compliant with applicable regulations.

Threat Detection, Incident Response & Security Operations

  • Own and mature Cyncly's SOC capability — in-house or managed — ensuring 24/7 detection, triage, and response across endpoints, cloud, network, and application layers.
  • Develop, maintain, and test Cyncly's IR plan and cyber crisis playbooks including tabletop exercises; act as senior Incident Commander leading containment, eradication, recovery, and post-incident review.
  • Drive adoption of threat intelligence platforms, SIEM/SOAR, and EDR/XDR solutions; reduce MTTD/MTTR through automation and lead the vulnerability management and penetration testing programmes.

Security Architecture & Engineering

  • Define and govern security architecture principles across cloud (Azure/AWS), on-premises, hybrid, and SaaS environments, ensuring security by design in all technology programmes.
  • Lead zero-trust network architecture and micro-segmentation; embed security into CI/CD pipelines, IaC, and cloud landing zones (DevSecOps); provide architecture sign-off for major programmes and M&A integrations.

Identity, Access & Privileged Access Management

  • Own Cyncly's IAM programme including RBAC, least-privilege enforcement, and access certification; lead PAM controls ensuring all privileged accounts are governed, monitored, and auditable.
  • Drive SSO, MFA, and Conditional Access adoption across all platforms; ensure timely provisioning and deprovisioning for all joiners, movers, and leavers.

Mergers & Acquisitions — Security Due Diligence & Integration

  • Lead cyber security due diligence for M&A targets, evaluating security posture, data protection practices, compliance status, and technical debt, providing risk-rated findings to inform deal decisions.
  • Define and execute security integration roadmaps; build repeatable M&A security playbooks to accelerate future acquisitions and ensure acquired entities meet SOC 2 and applicable compliance obligations.

Security Awareness, Culture & Third-Party Risk

  • Design and deliver a global security awareness programme including phishing simulations, role-specific training, and executive briefings; manage third-party risk via assessment, contractual controls, and audits.
  • Build and maintain a security champion network across Engineering and Product, fostering a security-first culture at the development and operational level.

Qualifications and Skills

Required Qualifications

  • Bachelor's degree or equivalent in Computer Science, Information Security, or Cybersecurity; advanced degree preferred.
  • 20+ years of experience in information security and data protection, with 10+ years in a senior security leadership or director-level role.
  • Proven SOC 2 Type II certification experience in a complex, global SaaS organisation; deep expertise in GDPR, CCPA, and global data privacy regulations.
  • Track record of leading cloud security transformations, zero-trust implementations, and M&A security integrations across globally distributed organisations.

Mandatory Technical & Domain Expertise

  • Cloud Security: Deep expertise in Microsoft Azure (Security Centre, Defender for Cloud, Sentinel); AWS or GCP advantageous.
  • Compliance Frameworks: SOC 2, ISO 27001/27002, NIST CSF, CIS Controls, GDPR/CCPA; PCI DSS or HIPAA a plus.
  • Security Operations: SIEM (Sentinel, Splunk), SOAR, EDR/XDR, and vulnerability management tools (Qualys, Tenable, Rapid7).
  • Data & Identity Security: DLP, data classification, encryption, Active Directory, Azure AD/Entra ID, PAM (CyberArk, BeyondTrust), SSO, MFA, Conditional Access.
  • DevSecOps & Network Security: SAST/DAST/SCA in CI/CD, IaC security scanning, container/Kubernetes security, zero-trust networking, firewall management (Palo Alto, Cisco).

Professional Certifications

  • Required: CISSP or CISM. Strongly preferred: CCSP or CRISC.
  • Preferred: ISO 27001 Lead Implementer or Lead Auditor; SOC 2 examination credentials; CEH, OSCP, or equivalent.

Competency Requirements

  • Security Leadership: Credible at Board and C-suite level; translates complex threats into business risk language.
  • Strategic Thinking: Long-term security vision balanced with immediate compliance demands in a fast-growing, acquisition-driven organisation.
  • Compliance Ownership: Methodical and detail-driven; manages concurrent audits without BAU disruption.
  • Crisis Leadership: Calm and decisive under pressure; leads incident response with clear executive communication.
  • Collaboration & Influence: Engages credibly across Engineering, Product, Legal, Finance, and Business to drive security outcomes.
  • Analytical & Risk-Driven: Uses data and risk frameworks to prioritise decisions and quantify security value.
  • Self-directed & Adaptable: Operates autonomously at pace in a PE-backed, M&A-active global environment.

Working for us

 At Cyncly, we’re a global family that collaborates with humility and respect for one another. With more than 2,400 employees around the world, we not only recognize our diverse perspectives, but we also champion our different outlooks and firmly believe it to be what makes us better together.

You can expect to work in a supportive and nurturing environment, with experts in their fields who strive for quality and excellence without compromising others. We also believe in a flexible and autonomous working environment that focuses on the continual growth of our employees.

Diversity of experience and skills combined with passion are a key to innovation and brilliance, so we encourage applicants from all backgrounds to apply to our roles.

That’s who we are: A team that recognizes our strength is in working together to not only get things done but also lead the industry with a bold approach that’s dedicated to making our customers better. Come join us.

In accordance with applicable pay transparency laws, we are committed to providing clear and equitable compensation information. For this remote position, the expected salary range is $150,000 - 175,000 USD, depending on location, experience, and qualifications. This role may also be eligible for additional compensation such as bonuses, commissions, as well as a comprehensive benefits package. Candidates applying from jurisdictions with specific pay disclosure requirements (e.g., California, Colorado, New York, Washington, Illinois, British Columbia) will receive location-specific compensation details in compliance with local laws.

Equal Opportunity Employer Statement: 

Cyncly is committed to equal opportunity and does not discriminate based on race, color, creed, religion, gender, age, sexual orientation, national origin, disability, veteran status, or any other characteristic protected by law. 

Applicants must be legally authorized to work in the country in which they are applying to work (United States or Canada). This role is not eligible for employer sponsorship now or in the future.

Similar Jobs

2 Days Ago
Remote
United States
204K-326K Annually
Expert/Leader
204K-326K Annually
Expert/Leader
Cloud • Fintech • Food • Information Technology • Software • Hospitality
Leads security assurance and compliance transformation for a regulated payments and lending platform. Owns continuous controls monitoring, automated evidence collection, enterprise security and third-party risk, business continuity governance, assurance evidence, and second-line independent reviews. Manages and develops the security compliance team while partnering with engineering and customer trust functions to scale automated compliance across PCI, SOC, SOX, and ISO frameworks.
Top Skills: Automated Evidence CollectionCloud EnvironmentsCompliance-As-CodeContinuous Controls MonitoringIsoPciSocSox
14 Days Ago
In-Office or Remote
Delaware, USA
187K-275K Annually
Expert/Leader
187K-275K Annually
Expert/Leader
Fintech • Information Technology • Financial Services
Leads enterprise AI security architecture and strategy across LLM applications, RAG pipelines, agent workflows, and cloud-native platforms. Establishes security standards, governance requirements, guardrails, threat models, and secure development patterns. Drives remediation of AI-specific risks including prompt injection, jailbreaks, data exposure, unsafe tool usage, and excessive permissions. Partners with senior engineering, product, architecture, and security leaders, leads investigations, supports automated security testing, represents AI security in governance forums, and mentors security engineers.
Top Skills: Agent-Based WorkflowsAi/Ml PlatformsAWSAzureCi/CdCloud-Native PlatformsGCPLlmMcp IntegrationsRag
20 Days Ago
Remote
United States
190K-220K Annually
Senior level
190K-220K Annually
Senior level
Insurance
Leads the company’s information security operations and reports to the CISO. Oversees SIEM, threat detection, vulnerability management, penetration testing, incident response, SOC 2 Type II compliance, third-party risk, security awareness, cloud and endpoint security, and regulatory cybersecurity coordination. Manages security policies, breach readiness, tabletop exercises, KPIs, audits, and emerging technology evaluations while partnering with IT, infrastructure, compliance, regulators, and executive leadership.
Top Skills: Cloud SecurityEdr/XdrElasticIso 27001Nist Cybersecurity FrameworkPamPenetration TestingSIEMSoc 2 Type IiSsoVulnerability Scanners

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account