Director, Security and Compliance

Rebuy, Inc.
•$175,000 - $200,000•Remote

About The Position

At Rebuy, we're on a mission to revolutionize shopping with intelligent, personalized experiences that wow customers around the globe. As a fully remote team, we power some of the fastest growing DTC brands like Tecovas, Momofuku, and many more. We believe in ownership, drive, and empathy and strongly uphold that every team member plays a vital role in shaping the future of intelligent commerce. Our culture thrives on collaboration, creativity, and genuine passion. We don’t just build great tech - we build lasting partnerships, a strong community, and a place where people love to work. Rebuy is looking for a senior, hands-on leader to own security, compliance, privacy, and IT across the company. Reporting to the COO and briefing the executive team quarterly, you'll lead our compliance programs, protect our cloud infrastructure and applications, manage privacy and data governance, and keep our people and systems secure and productive. This is an individual contributor leadership role. You'll set direction and drive security initiatives in partnership with our DevOps and Engineering teams. This is a great fit for someone who's comfortable as the accountable owner across many domains and can influence without formal authority.

Requirements

  • 8+ years in security and GRC, including end-to-end ownership of a SOC 2 Type 2 program.
  • Hands-on experience securing a major cloud environment (GCP preferred).
  • Working knowledge of GDPR, CCPA/CPRA, and data governance practices.
  • Experience with compliance automation, cloud security, and macOS device management tools (e.g., Vanta, Orca, Iru, or equivalents).
  • Experience administering and securing a broad SaaS environment, including identity and access management.
  • Experience building and testing BCP/DR plans and running incident response exercises.
  • Application security fluency (e.g., OWASP Top 10, SAST, CI/CD, secrets management) sufficient to set standards and partner credibly with engineers.
  • Ability to influence without authority and communicate risk to executives in business terms.
  • Self-direction in a fast-moving, fully remote environment. You prioritize ruthlessly, document thoroughly, and automate where you can.
  • Experience in the Shopify ecosystem.
  • Workflow automation or scripting experience.
  • Certifications such as CISSP, CISM, CCSP, or CIPP.

Responsibilities

  • Lead Rebuy's compliance programs, including SOC 2 Type 2 (Security, Availability, Confidentiality), GDPR, CCPA/CPRA, and Shopify partner security requirements, through audits and third-party assessments.
  • Own company security policies, risk management, and vendor risk management.
  • Run periodic access reviews across company systems.
  • Maintain our Trust Center and support Sales with customer security reviews and questionnaires.
  • Lead security awareness training and the security side of personnel lifecycle processes.
  • Support cyber insurance applications and renewals.
  • Own business continuity and disaster recovery planning, including regular testing and validation.
  • Facilitate incident response tabletop exercises
  • Own the data governance program and Rebuy's privacy documentation, including the privacy policy, DPA, subprocessor list, and vulnerability disclosure policy.
  • Manage data subject requests and the automated processes that support them.
  • Review new products, partnerships, and data-sharing arrangements for privacy and security impact.
  • Review customer and vendor agreements for privacy and security terms in partnership with Legal.
  • Help shape AI governance that supports Rebuy's open approach to AI tools while protecting company and customer data.
  • Own the incident response program, lead response to security incidents, and coordinate customer and regulatory notifications with Legal.
  • Run vulnerability management across cloud, code, and endpoints, driving remediation with owning teams.
  • Manage annual penetration testing from scoping through remediation.
  • Partner with DevOps on CI/CD, deployments, and infrastructure so security is built in from the start.
  • Set application security standards and drive adoption across Engineering.
  • Lead security initiatives such as authentication, logging, and monitoring alongside DevOps and Engineering.
  • Define secrets management standards.
  • Secure our cloud environment, including identity and access, network controls, and monitoring of sensitive data.
  • Own email, domain, and DNS security.
  • Manage the company's endpoint fleet, including device management, configuration baselines, patching, and hardware procurement and fulfillment for a remote workforce.
  • Administer and secure the company's SaaS platforms.
  • Provide IT support to employees.
  • Report quarterly to executive leadership on security, risk, and compliance.
  • Own tooling and budget decisions for a significant portion of the technology stack, including monitoring cloud spend.
  • Serve as the company's trusted advisor on security and compliance.

Benefits

  • Flexible vacation policy
  • Generous holiday schedule
  • Parental leave
  • Sick policy
  • Birthday holiday
  • 100% free health, dental, and insurance for you and your family
  • 401(k) retirement plans (U.S. employees)
  • TFSA and RRSP retirement plans (Canadian employees)
  • 3% contribution of your gross salary to retirement plans
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service