Cyncly Logo

Cyncly

Director - Security

Reposted One Month Ago
Remote
Hiring Remotely in United States
150K-175K Annually
Senior level
Remote
Hiring Remotely in United States
150K-175K Annually
Senior level
Lead and own global hosting and infrastructure operations across cloud (Azure), co-location, and hybrid environments. Manage major incident response, reliability, capacity planning, M&A infrastructure integrations, core infrastructure projects, security/compliance (SOC2, GDPR), and a distributed hosting operations team. Drive observability, automation, and DR readiness while partnering with enterprise architecture, security, and senior leadership to deliver scalable, secure hosting services.
The summary above was generated by AI

Job Title: Director - Security 

Location: USA / EST time zone

Contract: Permanent

About Us 

Cyncly is a global technology powerhouse with 2,400+ employees and 70,000+ customers across 100+ countries. Cyncly transforms the way customizable products and spaces are imagined, designed, sold, managed and made. Our end-to-end software solutions connect professional designers, retailers and manufacturers to the world's largest repository of product content. Today, our business spans across the Kitchen & Bath, Furniture, Window, Glass & Door, and Flooring industries with operations in North & South America, Europe, Asia Pacific and Africa. 

Cyncly brings over 30 years of experience to deliver more value for our customers through an expanded portfolio of end-to-end solutions. Our global presence allows us to provide world-class support and sales with a local touch, providing the best possible customer experience. 

Cyncly is now embarking on an exciting journey as we continue to expand through strong organic growth and complementary acquisitions, backed by leading growth private equity firms specialized in technology. 

About the Role
The Director – Security is a senior IT leadership role responsible for defining, executing, and continuously maturing Cyncly's global cyber security strategy, data protection programme, and information security posture. Reporting to the Head of IT & Cyber Security, this role is the primary owner of all security disciplines — from threat detection and incident response to security architecture, data governance, and regulatory compliance.
A critical element of this role is owning Cyncly's compliance obligations end-to-end, including achieving and maintaining SOC 2 Type II certification across Cyncly's global operations, and ensuring adherence to GDPR, ISO 27001, and other applicable frameworks. The Director will act as Cyncly's senior authority on all matters relating to information security risk, data privacy, and cyber resilience, partnering closely with Product, Engineering, Legal, and business leadership to embed security into the fabric of everything Cyncly does.

Key Responsibilities

Cyber Security Strategy & Leadership

  • Define and own Cyncly's global cyber security strategy, roadmap, and operating model, aligning security investment and priorities to business risk and growth objectives.
  • Build and lead a high-performing, globally distributed cyber security team, setting clear direction, developing talent, and fostering a culture of security awareness and accountability.
  • Act as the primary security advisor to the Head of IT & Cyber Security, CTO, and senior leadership, translating threats and technical risks into clear, business-relevant guidance; represent Cyncly's security posture to customers, auditors, regulators, and the Board.
  • Establish and govern security policies, standards, and procedures organisation-wide; drive continuous improvement through threat intelligence, industry benchmarking, and emerging best practices.

Compliance, Certifications & Regulatory Obligations

  • Own end-to-end accountability for Cyncly's SOC 2 Type II certification programme — including scoping, control design, evidence collection, auditor management, and remediation of findings — ensuring successful annual certification and ongoing continuous compliance.
  • Lead and maintain compliance with ISO 27001, GDPR, CCPA, and other applicable data protection regulations across all jurisdictions; serve as primary contact for external auditors, regulatory bodies, and certification authorities.
  • Develop and maintain a compliance calendar and evidence management framework, ensuring Cyncly is audit-ready at all times; proactively monitor the regulatory landscape to identify and address new obligations.
  • Collaborate with Legal, Finance, and HR to ensure organisation-wide policies — data retention, privacy notices, HR security controls, and supplier assurance — meet all compliance obligations.

Data & Information Security

  • Define and implement Cyncly's data classification framework, data governance policies, and information lifecycle management practices; oversee DLP controls, encryption standards, and data access management across all repositories, cloud platforms, and SaaS applications.
  • Embed data privacy by design into all product development, infrastructure, and business processes; manage end-to-end responses to DSARs, breach notifications, and privacy incidents in accordance with GDPR and local privacy laws.
  • Partner with Enterprise Architecture and Engineering to ensure all data flows, storage, and processing activities are documented, controlled, and compliant with applicable regulations.

Threat Detection, Incident Response & Security Operations

  • Own and mature Cyncly's SOC capability — in-house or managed — ensuring 24/7 detection, triage, and response across endpoints, cloud, network, and application layers.
  • Develop, maintain, and test Cyncly's IR plan and cyber crisis playbooks including tabletop exercises; act as senior Incident Commander leading containment, eradication, recovery, and post-incident review.
  • Drive adoption of threat intelligence platforms, SIEM/SOAR, and EDR/XDR solutions; reduce MTTD/MTTR through automation and lead the vulnerability management and penetration testing programmes.

Security Architecture & Engineering

  • Define and govern security architecture principles across cloud (Azure/AWS), on-premises, hybrid, and SaaS environments, ensuring security by design in all technology programmes.
  • Lead zero-trust network architecture and micro-segmentation; embed security into CI/CD pipelines, IaC, and cloud landing zones (DevSecOps); provide architecture sign-off for major programmes and M&A integrations.

Identity, Access & Privileged Access Management

  • Own Cyncly's IAM programme including RBAC, least-privilege enforcement, and access certification; lead PAM controls ensuring all privileged accounts are governed, monitored, and auditable.
  • Drive SSO, MFA, and Conditional Access adoption across all platforms; ensure timely provisioning and deprovisioning for all joiners, movers, and leavers.

Mergers & Acquisitions — Security Due Diligence & Integration

  • Lead cyber security due diligence for M&A targets, evaluating security posture, data protection practices, compliance status, and technical debt, providing risk-rated findings to inform deal decisions.
  • Define and execute security integration roadmaps; build repeatable M&A security playbooks to accelerate future acquisitions and ensure acquired entities meet SOC 2 and applicable compliance obligations.

Security Awareness, Culture & Third-Party Risk

  • Design and deliver a global security awareness programme including phishing simulations, role-specific training, and executive briefings; manage third-party risk via assessment, contractual controls, and audits.
  • Build and maintain a security champion network across Engineering and Product, fostering a security-first culture at the development and operational level.

Qualifications and Skills

Required Qualifications

  • Bachelor's degree or equivalent in Computer Science, Information Security, or Cybersecurity; advanced degree preferred.
  • 20+ years of experience in information security and data protection, with 10+ years in a senior security leadership or director-level role.
  • Proven SOC 2 Type II certification experience in a complex, global SaaS organisation; deep expertise in GDPR, CCPA, and global data privacy regulations.
  • Track record of leading cloud security transformations, zero-trust implementations, and M&A security integrations across globally distributed organisations.

Mandatory Technical & Domain Expertise

  • Cloud Security: Deep expertise in Microsoft Azure (Security Centre, Defender for Cloud, Sentinel); AWS or GCP advantageous.
  • Compliance Frameworks: SOC 2, ISO 27001/27002, NIST CSF, CIS Controls, GDPR/CCPA; PCI DSS or HIPAA a plus.
  • Security Operations: SIEM (Sentinel, Splunk), SOAR, EDR/XDR, and vulnerability management tools (Qualys, Tenable, Rapid7).
  • Data & Identity Security: DLP, data classification, encryption, Active Directory, Azure AD/Entra ID, PAM (CyberArk, BeyondTrust), SSO, MFA, Conditional Access.
  • DevSecOps & Network Security: SAST/DAST/SCA in CI/CD, IaC security scanning, container/Kubernetes security, zero-trust networking, firewall management (Palo Alto, Cisco).

Professional Certifications

  • Required: CISSP or CISM. Strongly preferred: CCSP or CRISC.
  • Preferred: ISO 27001 Lead Implementer or Lead Auditor; SOC 2 examination credentials; CEH, OSCP, or equivalent.

Competency Requirements

  • Security Leadership: Credible at Board and C-suite level; translates complex threats into business risk language.
  • Strategic Thinking: Long-term security vision balanced with immediate compliance demands in a fast-growing, acquisition-driven organisation.
  • Compliance Ownership: Methodical and detail-driven; manages concurrent audits without BAU disruption.
  • Crisis Leadership: Calm and decisive under pressure; leads incident response with clear executive communication.
  • Collaboration & Influence: Engages credibly across Engineering, Product, Legal, Finance, and Business to drive security outcomes.
  • Analytical & Risk-Driven: Uses data and risk frameworks to prioritise decisions and quantify security value.
  • Self-directed & Adaptable: Operates autonomously at pace in a PE-backed, M&A-active global environment.

Working for us

 At Cyncly, we’re a global family that collaborates with humility and respect for one another. With more than 2,400 employees around the world, we not only recognize our diverse perspectives, but we also champion our different outlooks and firmly believe it to be what makes us better together.

You can expect to work in a supportive and nurturing environment, with experts in their fields who strive for quality and excellence without compromising others. We also believe in a flexible and autonomous working environment that focuses on the continual growth of our employees.

Diversity of experience and skills combined with passion are a key to innovation and brilliance, so we encourage applicants from all backgrounds to apply to our roles.

That’s who we are: A team that recognizes our strength is in working together to not only get things done but also lead the industry with a bold approach that’s dedicated to making our customers better. Come join us.

In accordance with applicable pay transparency laws, we are committed to providing clear and equitable compensation information. For this remote position, the expected salary range is $150,000 - 175,000 USD, depending on location, experience, and qualifications. This role may also be eligible for additional compensation such as bonuses, commissions, as well as a comprehensive benefits package. Candidates applying from jurisdictions with specific pay disclosure requirements (e.g., California, Colorado, New York, Washington, Illinois, British Columbia) will receive location-specific compensation details in compliance with local laws.

Equal Opportunity Employer Statement: 

Cyncly is committed to equal opportunity and does not discriminate based on race, color, creed, religion, gender, age, sexual orientation, national origin, disability, veteran status, or any other characteristic protected by law. 

Applicants must be legally authorized to work in the country in which they are applying to work (United States or Canada). This role is not eligible for employer sponsorship now or in the future.

Similar Jobs

4 Days Ago
Easy Apply
Remote
United States
Easy Apply
148K-248K Annually
Entry level
148K-248K Annually
Entry level
Cloud • Security • Software • Cybersecurity • Automation
Leads GitLab’s National Security Group regional sales team, driving new and expansion revenue across U.S. federal agencies. Responsibilities include hiring and coaching Account Executives, forecasting, pipeline management, complex deal strategy, executive negotiations, federal procurement, FedRAMP-related selling, partner engagement, and account expansion. The role collaborates with Customer Success, Product, Marketing, Renewals, distributors, and systems integrators while traveling as needed for customer and team engagements.
Top Skills: CRMDevsecopsFedrampGitlabMarketing AutomationSalesforce
6 Days Ago
Remote
United States
275K-440K Annually
Senior level
275K-440K Annually
Senior level
Cloud • Fintech • Food • Information Technology • Software • Hospitality
Lead Toast’s product and platform security organization, overseeing security platform engineering, application and cloud security, secure development practices, offensive security, vulnerability management, hardware security, and developer enablement. Partner with product and engineering leaders to establish secure defaults and scalable guardrails while reducing developer friction. Manage and grow a multi-team security engineering organization, expand security champions and tooling adoption, and align security posture with business and product priorities.
Top Skills: AIApplication SecurityAutomationCi/CdCloud SecurityCloud-Native SecurityContainersDetection EngineeringHardware SecurityInfrastructure As CodeMicroservicesPenetration TestingPurple TeamingRed TeamingSecure Development LifecycleSoftware Supply Chain SecurityThreat ModelingVulnerability Management
21 Days Ago
In-Office or Remote
Delaware, USA
187K-275K Annually
Expert/Leader
187K-275K Annually
Expert/Leader
Fintech • Information Technology • Financial Services
Leads enterprise AI security architecture and strategy across LLM applications, RAG pipelines, agent workflows, and cloud-native platforms. Establishes security standards, governance requirements, guardrails, threat models, and secure development patterns. Drives remediation of AI-specific risks including prompt injection, jailbreaks, data exposure, unsafe tool usage, and excessive permissions. Partners with senior engineering, product, architecture, and security leaders, leads investigations, supports automated security testing, represents AI security in governance forums, and mentors security engineers.
Top Skills: Agent-Based WorkflowsAi/Ml PlatformsAWSAzureCi/CdCloud-Native PlatformsGCPLlmMcp IntegrationsRag

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account