Cyncly Logo

Cyncly

Director - Security

Reposted One Month Ago
Remote
Hiring Remotely in United States
150K-175K Annually
Senior level
Remote
Hiring Remotely in United States
150K-175K Annually
Senior level
Lead and own global hosting and infrastructure operations across cloud (Azure), co-location, and hybrid environments. Manage major incident response, reliability, capacity planning, M&A infrastructure integrations, core infrastructure projects, security/compliance (SOC2, GDPR), and a distributed hosting operations team. Drive observability, automation, and DR readiness while partnering with enterprise architecture, security, and senior leadership to deliver scalable, secure hosting services.
The summary above was generated by AI

Job Title: Director - Security 

Location: USA / EST time zone

Contract: Permanent

About Us 

Cyncly is a global technology powerhouse with 2,400+ employees and 70,000+ customers across 100+ countries. Cyncly transforms the way customizable products and spaces are imagined, designed, sold, managed and made. Our end-to-end software solutions connect professional designers, retailers and manufacturers to the world's largest repository of product content. Today, our business spans across the Kitchen & Bath, Furniture, Window, Glass & Door, and Flooring industries with operations in North & South America, Europe, Asia Pacific and Africa. 

Cyncly brings over 30 years of experience to deliver more value for our customers through an expanded portfolio of end-to-end solutions. Our global presence allows us to provide world-class support and sales with a local touch, providing the best possible customer experience. 

Cyncly is now embarking on an exciting journey as we continue to expand through strong organic growth and complementary acquisitions, backed by leading growth private equity firms specialized in technology. 

About the Role
The Director – Security is a senior IT leadership role responsible for defining, executing, and continuously maturing Cyncly's global cyber security strategy, data protection programme, and information security posture. Reporting to the Head of IT & Cyber Security, this role is the primary owner of all security disciplines — from threat detection and incident response to security architecture, data governance, and regulatory compliance.
A critical element of this role is owning Cyncly's compliance obligations end-to-end, including achieving and maintaining SOC 2 Type II certification across Cyncly's global operations, and ensuring adherence to GDPR, ISO 27001, and other applicable frameworks. The Director will act as Cyncly's senior authority on all matters relating to information security risk, data privacy, and cyber resilience, partnering closely with Product, Engineering, Legal, and business leadership to embed security into the fabric of everything Cyncly does.

Key Responsibilities

Cyber Security Strategy & Leadership

  • Define and own Cyncly's global cyber security strategy, roadmap, and operating model, aligning security investment and priorities to business risk and growth objectives.
  • Build and lead a high-performing, globally distributed cyber security team, setting clear direction, developing talent, and fostering a culture of security awareness and accountability.
  • Act as the primary security advisor to the Head of IT & Cyber Security, CTO, and senior leadership, translating threats and technical risks into clear, business-relevant guidance; represent Cyncly's security posture to customers, auditors, regulators, and the Board.
  • Establish and govern security policies, standards, and procedures organisation-wide; drive continuous improvement through threat intelligence, industry benchmarking, and emerging best practices.

Compliance, Certifications & Regulatory Obligations

  • Own end-to-end accountability for Cyncly's SOC 2 Type II certification programme — including scoping, control design, evidence collection, auditor management, and remediation of findings — ensuring successful annual certification and ongoing continuous compliance.
  • Lead and maintain compliance with ISO 27001, GDPR, CCPA, and other applicable data protection regulations across all jurisdictions; serve as primary contact for external auditors, regulatory bodies, and certification authorities.
  • Develop and maintain a compliance calendar and evidence management framework, ensuring Cyncly is audit-ready at all times; proactively monitor the regulatory landscape to identify and address new obligations.
  • Collaborate with Legal, Finance, and HR to ensure organisation-wide policies — data retention, privacy notices, HR security controls, and supplier assurance — meet all compliance obligations.

Data & Information Security

  • Define and implement Cyncly's data classification framework, data governance policies, and information lifecycle management practices; oversee DLP controls, encryption standards, and data access management across all repositories, cloud platforms, and SaaS applications.
  • Embed data privacy by design into all product development, infrastructure, and business processes; manage end-to-end responses to DSARs, breach notifications, and privacy incidents in accordance with GDPR and local privacy laws.
  • Partner with Enterprise Architecture and Engineering to ensure all data flows, storage, and processing activities are documented, controlled, and compliant with applicable regulations.

Threat Detection, Incident Response & Security Operations

  • Own and mature Cyncly's SOC capability — in-house or managed — ensuring 24/7 detection, triage, and response across endpoints, cloud, network, and application layers.
  • Develop, maintain, and test Cyncly's IR plan and cyber crisis playbooks including tabletop exercises; act as senior Incident Commander leading containment, eradication, recovery, and post-incident review.
  • Drive adoption of threat intelligence platforms, SIEM/SOAR, and EDR/XDR solutions; reduce MTTD/MTTR through automation and lead the vulnerability management and penetration testing programmes.

Security Architecture & Engineering

  • Define and govern security architecture principles across cloud (Azure/AWS), on-premises, hybrid, and SaaS environments, ensuring security by design in all technology programmes.
  • Lead zero-trust network architecture and micro-segmentation; embed security into CI/CD pipelines, IaC, and cloud landing zones (DevSecOps); provide architecture sign-off for major programmes and M&A integrations.

Identity, Access & Privileged Access Management

  • Own Cyncly's IAM programme including RBAC, least-privilege enforcement, and access certification; lead PAM controls ensuring all privileged accounts are governed, monitored, and auditable.
  • Drive SSO, MFA, and Conditional Access adoption across all platforms; ensure timely provisioning and deprovisioning for all joiners, movers, and leavers.

Mergers & Acquisitions — Security Due Diligence & Integration

  • Lead cyber security due diligence for M&A targets, evaluating security posture, data protection practices, compliance status, and technical debt, providing risk-rated findings to inform deal decisions.
  • Define and execute security integration roadmaps; build repeatable M&A security playbooks to accelerate future acquisitions and ensure acquired entities meet SOC 2 and applicable compliance obligations.

Security Awareness, Culture & Third-Party Risk

  • Design and deliver a global security awareness programme including phishing simulations, role-specific training, and executive briefings; manage third-party risk via assessment, contractual controls, and audits.
  • Build and maintain a security champion network across Engineering and Product, fostering a security-first culture at the development and operational level.

Qualifications and Skills

Required Qualifications

  • Bachelor's degree or equivalent in Computer Science, Information Security, or Cybersecurity; advanced degree preferred.
  • 20+ years of experience in information security and data protection, with 10+ years in a senior security leadership or director-level role.
  • Proven SOC 2 Type II certification experience in a complex, global SaaS organisation; deep expertise in GDPR, CCPA, and global data privacy regulations.
  • Track record of leading cloud security transformations, zero-trust implementations, and M&A security integrations across globally distributed organisations.

Mandatory Technical & Domain Expertise

  • Cloud Security: Deep expertise in Microsoft Azure (Security Centre, Defender for Cloud, Sentinel); AWS or GCP advantageous.
  • Compliance Frameworks: SOC 2, ISO 27001/27002, NIST CSF, CIS Controls, GDPR/CCPA; PCI DSS or HIPAA a plus.
  • Security Operations: SIEM (Sentinel, Splunk), SOAR, EDR/XDR, and vulnerability management tools (Qualys, Tenable, Rapid7).
  • Data & Identity Security: DLP, data classification, encryption, Active Directory, Azure AD/Entra ID, PAM (CyberArk, BeyondTrust), SSO, MFA, Conditional Access.
  • DevSecOps & Network Security: SAST/DAST/SCA in CI/CD, IaC security scanning, container/Kubernetes security, zero-trust networking, firewall management (Palo Alto, Cisco).

Professional Certifications

  • Required: CISSP or CISM. Strongly preferred: CCSP or CRISC.
  • Preferred: ISO 27001 Lead Implementer or Lead Auditor; SOC 2 examination credentials; CEH, OSCP, or equivalent.

Competency Requirements

  • Security Leadership: Credible at Board and C-suite level; translates complex threats into business risk language.
  • Strategic Thinking: Long-term security vision balanced with immediate compliance demands in a fast-growing, acquisition-driven organisation.
  • Compliance Ownership: Methodical and detail-driven; manages concurrent audits without BAU disruption.
  • Crisis Leadership: Calm and decisive under pressure; leads incident response with clear executive communication.
  • Collaboration & Influence: Engages credibly across Engineering, Product, Legal, Finance, and Business to drive security outcomes.
  • Analytical & Risk-Driven: Uses data and risk frameworks to prioritise decisions and quantify security value.
  • Self-directed & Adaptable: Operates autonomously at pace in a PE-backed, M&A-active global environment.

Working for us

 At Cyncly, we’re a global family that collaborates with humility and respect for one another. With more than 2,400 employees around the world, we not only recognize our diverse perspectives, but we also champion our different outlooks and firmly believe it to be what makes us better together.

You can expect to work in a supportive and nurturing environment, with experts in their fields who strive for quality and excellence without compromising others. We also believe in a flexible and autonomous working environment that focuses on the continual growth of our employees.

Diversity of experience and skills combined with passion are a key to innovation and brilliance, so we encourage applicants from all backgrounds to apply to our roles.

That’s who we are: A team that recognizes our strength is in working together to not only get things done but also lead the industry with a bold approach that’s dedicated to making our customers better. Come join us.

In accordance with applicable pay transparency laws, we are committed to providing clear and equitable compensation information. For this remote position, the expected salary range is $150,000 - 175,000 USD, depending on location, experience, and qualifications. This role may also be eligible for additional compensation such as bonuses, commissions, as well as a comprehensive benefits package. Candidates applying from jurisdictions with specific pay disclosure requirements (e.g., California, Colorado, New York, Washington, Illinois, British Columbia) will receive location-specific compensation details in compliance with local laws.

Equal Opportunity Employer Statement: 

Cyncly is committed to equal opportunity and does not discriminate based on race, color, creed, religion, gender, age, sexual orientation, national origin, disability, veteran status, or any other characteristic protected by law. 

Applicants must be legally authorized to work in the country in which they are applying to work (United States or Canada). This role is not eligible for employer sponsorship now or in the future.

Similar Jobs

Yesterday
Easy Apply
Remote
United States
Easy Apply
225K-305K Annually
Senior level
225K-305K Annually
Senior level
Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Leads Motive’s global security compliance, privacy, risk, audit, customer trust, and AI governance functions. Builds integrated controls across ISO, SOC, PCI DSS, FedRAMP, GDPR, and related frameworks; manages audits, privacy operations, international regulatory readiness, customer security reviews, policies, training, and human risk. The role also establishes AI-first automation, AI governance, and a path to FedRAMP while leading a distributed team and partnering across Legal, Engineering, Product, IT, Finance, Sales, and Customer Success.
Top Skills: Ai GovernanceCcpaCloud-Native SaasContinuous Control MonitoringCpraData ResidencyEu Ai ActFedrampGdprIso 27001Iso 27701Iso/Iec 42001Law 25LgpdMexican LfpdpppNist Ai Risk Management FrameworkPci DssPipedaSoc 1Soc 2Trust Portals
6 Days Ago
In-Office or Remote
Delaware, USA
187K-275K Annually
Expert/Leader
187K-275K Annually
Expert/Leader
Fintech • Information Technology • Financial Services
Leads enterprise AI security architecture and strategy across LLM applications, RAG pipelines, agent workflows, and cloud-native platforms. Establishes security standards, governance requirements, guardrails, threat models, and secure development patterns. Drives remediation of AI-specific risks including prompt injection, jailbreaks, data exposure, unsafe tool usage, and excessive permissions. Partners with senior engineering, product, architecture, and security leaders, leads investigations, supports automated security testing, represents AI security in governance forums, and mentors security engineers.
Top Skills: Agent-Based WorkflowsAi/Ml PlatformsAWSAzureCi/CdCloud-Native PlatformsGCPLlmMcp IntegrationsRag
12 Days Ago
Remote or Hybrid
221K-387K Annually
Expert/Leader
221K-387K Annually
Expert/Leader
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Leads ServiceNow’s Americas Customer Security organization, setting strategy, operating models, governance, and performance standards. Owns executive CISO-to-CISO engagements, complex security escalations, regulated deal support, security questionnaires, and customer trust initiatives. Partners with Sales, Legal, Product, Engineering, and other stakeholders to influence security posture and product roadmaps. Builds and scales high-performing teams, develops future leaders, represents the company externally, and advances cloud, AI, risk, compliance, privacy, and security maturity.
Top Skills: Agentic AiCloud SecurityGenerative Ai

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account