Associate Director, Cybersecurity, Privacy & IT

Dr. Squatch•Marina del Rey, CA
•$190,000 - $215,000•Hybrid

About The Position

Dr. Squatch is looking for an Associate Director of Cybersecurity, Privacy & IT to lead three connected functions: our security program, our privacy compliance program, and the internal technology our employees use every day. You'll own the strategy, and the team for all three. As part of Unilever, we now operate against a global control framework, and a meaningful share of this role is integration work: mapping our controls to enterprise standards, participating in assessment and reporting cycles, aligning identity, endpoint, and third-party risk practices, and translating between a global program and a business that still runs at startup speed. Doing that well, protecting the company without slowing it down, is the core challenge of the job. This role will also continue to drive the security strategy and represent Dr. Squatch in enterprise-level security and privacy governance. You'll sit on the Technology leadership team alongside data engineering, analytics, and business systems, partner closely with eCommerce, marketing, and legal, and present directly to our executive team on risk, incidents, and investment decisions.

Requirements

  • 8–12 years across cybersecurity, IT, and/or privacy, including end-to-end ownership of a security program rather than a single function within one.
  • Demonstrated experience applying a security and risk framework, such as NIST CSF, CIS Controls, ISO 27001, or SOC 2, in a real environment, not just on paper.
  • Hands-on depth in a cloud-first, SaaS-first stack: identity (Okta or equivalent), endpoint management, email security, logging and detection.
  • Working knowledge of CCPA/CPRA and GDPR, and experience operationalizing them, not only interpreting them.
  • Direct people management experience, including developing a more junior manager or engineer into greater scope. You'll inherit a capable IT Manager whose growth is part of your job.
  • Judgment about where to spend limited resources, and the communication skills to explain that tradeoff to executives in business terms, and to hold the line when the answer is no.
  • Comfort taking a vague problem and turning it into a specific, sequenced plan.
  • You get things done without perfect resources, and you act with urgency.
  • You play to win. You hold high standards, take ownership, and stay invested in the outcome.
  • Team first. You're humble, you help outside your own wheelhouse, and you're good to work with when something is on fire.
  • You can hold a security line and stay a partner to the business at the same time.

Nice To Haves

  • Experience at a company operating inside a larger parent organization, or through an acquisition integration.
  • Ecommerce or DTC background, and familiarity with Shopify, ad platform data flows, and consumer data at scale.
  • CISSP, CISM, CIPP/US, or CIPP/E.

Responsibilities

  • Maintain the cybersecurity risk register: identify risks to our data and systems, assess likelihood and impact, and prioritize what gets addressed first.
  • Own the multi-year security roadmap.
  • Evaluate, select, implement, and operate security tooling across endpoint, email, identity, cloud, and application layers.
  • Monitor and triage vulnerabilities and emerging threats; drive remediation to completion with the teams that own the systems.
  • Manage our MDR and incident response partners, and own the incident response plan, including tabletop exercises and post-incident reviews.
  • Run security awareness training and phishing simulation for employees and contractors.
  • Lead the IT function and manage the IT Manager by setting priorities and service expectations, and actively developing them toward broader ownership of IT operations over time.
  • Own identity and access management end to end via SSO, MFA, provisioning and deprovisioning, and periodic access reviews across our SaaS estate.
  • Own endpoint management and device lifecycle, from procurement through secure decommissioning.
  • Set the standard for IT support responsiveness and make sure onboarding and offboarding are fast, complete, and auditable.
  • Own SaaS governance: what tools we use, who approves them, how they're reviewed for security, and what happens to the data in them.
  • Own our privacy compliance program across CCPA/CPRA, other US state privacy laws, and UK and EU GDPR.
  • Run consumer rights request intake and fulfillment with Customer Support, and keep the process defensible as volume grows.
  • Maintain data mapping, records of processing, retention schedules, and privacy notices; partner with Legal and outside counsel on assessments and filings.
  • Advise Marketing and eComm on consent management, cookies, pixels, and data sharing with ad and analytics partners.
  • Own third-party and vendor risk review, including DPAs and security assessments for new tools.
  • Serve as our point of contact for Unilever security, privacy, and IT governance workstreams.
  • Map our controls to enterprise standards, close identified gaps, and manage the reporting and assessment cadence.
  • Lead our part of systems and identity integration projects, negotiating sequencing and exceptions where a global standard doesn't fit a DTC business.
  • Prepare Dr. Squatch for audits and control testing, and own the evidence.
  • Own acceptable use, data handling, and review standards for AI tools across the company.
  • Assess AI vendors for security and privacy risk before adoption, and keep an inventory of what's in use and what data it touches.
  • Partner with the Data team so governance enables adoption rather than blocking it.

Benefits

  • medical
  • dental
  • vision
  • 401k with Squatch match
  • PTO
  • healthy snacks
  • frequent company events
  • free products
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service