Qualifications
Responsibilities
Benefits
As VP, Chief Information Security Officer, you will be responsible for Commerce’s overall information security, compliance, and cyber risk program across our SaaS platform, product offerings, and corporate systems. You will lead a talented team of information security, governance, risk, and compliance professionals based in multiple locations, working closely with teams across the company to build and scale a world class information security and compliance program. You will interact directly with security teams within our merchant, prospective customer, and partner communities to collaborate on solutions to shared trust, risk, and security challenges.
The right candidate will be a collaborative and forward thinking technology leader with a strong point of view on security in a complex, advanced SaaS environment. Speaking with partners, customers, executives, and board members with comfort and clarity is as important to success as developing a strong roadmap for platform, product, corporate, and compliance security.
What You’ll Do
Define and lead Commerce’s cybersecurity and GRC strategy, including policies, standards, and programs that protect corporate and customer digital assets, reduce business risk, and support effective governance and compliance
Oversee security investigations and incident response, including impact analysis, executive updates, post incident recommendations, and plans to avoid similar issues in the future
Direct and approve the design of security systems, identity and access policies, and GRC procedures that support a secure, scalable SaaS environment
Maintain a current understanding of the cyber threat landscape, including relevant risks to SaaS platforms, cloud environments, ecommerce, and the broader technology industry
Translate threat, regulatory, and customer requirements into actionable plans that protect the business and support growth
Ensure compliance with applicable laws, regulations, customer commitments, and industry frameworks
Schedule and oversee periodic security audits, compliance assessments, certifications, and customer assurance activities
Oversee identity and access management, third party risk management, vulnerability management, secure configuration practices, and security awareness programs
Ensure cybersecurity and GRC policies and procedures are communicated clearly to employees and that compliance expectations are understood and enforced.
Oversee teams, employees, contractors, and vendors involved in cybersecurity and GRC, including hiring, performance management, mentoring, and team development
Continuously update the cybersecurity and GRC strategy to incorporate new technology, evolving threats, customer expectations, and business priorities.
Brief the executive team and board on security posture, key risks, incidents, program maturity, and investment priorities
Communicate security best practices and business relevant risks across the company, beyond security and IT, to strengthen shared ownership of security
Who You Are
Proven background leading information security within SaaS or platform oriented global companies
Strong understanding of current and emerging technologies for security in a cloud based, microservices based environment
Expansive experience with compliance frameworks such as SOX, PCI, GDPR, CCPA, SOC 2, and ISO 27001, and their application as both a service provider and a customer
Familiarity and comfort with modern DevOps processes as well as distributed cloud environments such as GCP and AWS
Experience partnering with Product, Engineering, Legal, Privacy, Sales, IT, and executive leadership to align security priorities with business objectives
Ability to communicate cyber risk, security posture, and investment tradeoffs clearly to executives, board members, customers, auditors, and technical teams
History of building and growing collaborative security and compliance teams that cross functional teams value working with
Experience with corporate cybersecurity in a distributed, cloud first environment
Work Where You Thrive
For candidates based in the Austin or Atlanta metro area, the position follows a hybrid work model with three days per week in the office, balancing focused individual work with meaningful in-person collaboration.
#LI-REMOTE
#LI-GC1
(Pay Transparency Range: $240,000.00 - $305,000.00)
Compensation Transparency
The national base salary range for this role is posted above in this job post.
Final compensation will be determined based on factors such as relevant experience, skills, qualifications and geographic location. We also consider internal equity to help ensure fair and consistent pay practices across our teams.
Where applicable, this role may also be eligible for variable compensation (such as bonus or commission), equity, and benefits in accordance with local policies. Details will be shared during the hiring process. We are committed to equitable and transparent pay practices that align to market data, internal equity, and individual contribution.
About BigCommerce
Similar Jobs

More Jobs at BigCommerce





More Information Technology Jobs