STORD

VP, Security

STORD • $160K — $200K *
US-AnywhereRemote in United States
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years in security, with 5+ years leading a security function at a SaaS or platform company.
  • Expertise in cloud-native security at scale, including AWS/GCP, Kubernetes, and microservices.
  • Proven experience in M&A security diligence and integration.
  • Track record of building security programs aligned with NIST CSF, SOC 2, and ISO 27001, with successful audit outcomes.
  • Experience in establishing and managing 24/7 detection and response capabilities.

Responsibilities

  • Set the security strategy and multi-year roadmap, aligning with NIST CSF 2.0.
  • Establish and manage 24/7 detection and response operations, transitioning from MDR to in-house capabilities.
  • Build and maintain a comprehensive security technical stack, including SIEM/SOAR and vulnerability management.
  • Oversee security diligence and integration for M&A activities, ensuring compliance with security standards.
  • Collaborate with Product and Engineering to implement secure-by-default designs and manage penetration testing.

Benefits

  • Opportunity to lead a capable team and shape the security strategy for international expansion.
  • Involvement in high-stakes M&A activities, influencing security integration processes.
  • Access to cutting-edge security technologies and frameworks.
  • Chance to work closely with executive leadership and influence company-wide security governance.
  • A role that directly impacts customer trust and product security.
Full Job Description
This is a build role, not a maintain role. You'll inherit a real foundation - SOC 2 Type II attestation across our core platforms, a public Trust Center, EU-U.S. Data Privacy Framework certification, and a small, capable team - and you'll own what comes next: the strategy, the team, the technical stack, and the operating rhythm that carry Stord through international expansion, continued M&A, AI deployment across the product, and eventual public-market scrutiny. What You'll Own Strategy and governance. Set the security strategy and the multi-year roadmap. Run our program against NIST CSF 2.0 and expand audit scopes and certifications. Establish AI governance across our models, agents, and Stord Labs work. Security operations. Stand up 24/7 detection and response, initially through an MDR partnership, and progressively bring detection engineering in-house. Own incident response end to end - playbooks, on-call, tabletop exercises with the executive team, and the postmortems that actually change something. Security engineering. Build and operate the technical stack: SIEM/SOAR, EDR/XDR, cloud security posture management, API security, secrets management, and vulnerability management. Harden CI/CD across a 200+ person engineering organization - signed commits, SBOM generation, dependency and secrets scanning, SAST/DAST in the pipeline. M&A security integration. Stord acquires companies, and every deal brings inherited systems, credentials, and technical debt. You'll own security diligence on future targets and the integration playbook that gets acquired environments to our standard on a predictable timeline. Product and customer trust. Partner with Product and Engineering on secure-by-default design across Logistics, Brands, and Commerce. Own penetration testing and our bug bounty program. Be the executive voice in enterprise security reviews and questionnaires - the ones that decide whether a deal closes this quarter or next. Resilience. Own business continuity and disaster recovery for an operation where downtime means orders don't ship. Prove recovery works by testing it, not by documenting it. Team. Lead and grow a team spanning GRC, security operations, security engineering, application security, and cloud/infrastructure security, plus an MDR partner. You'll inherit the existing team, then define and hire the rest of the structure yourself. What We're Looking For • 12+ years in security, including 5+ leading a security function at a SaaS or platform company. • Depth in cloud-native security at scale - AWS/GCP, Kubernetes, microservices, CI/CD, API security. You should be able to hold your own in an architecture review, not just read the summary. • Hands-on experience owning M&A security diligence and integration. • Track record building a security program against NIST CSF, SOC 2, and ISO 27001 - and passing the audits. • Experience standing up or running 24/7 detection and response, whether in-house, through MDR, or a hybrid. • Executive and Board communication chops. You can explain residual risk to a board, a trade-off to a CFO, and a control to an engineer, and be understood by all three. • Judgment about where to spend. You know which risks justify a control, which justify a conversation, and which justify neither. Bonus Points • You've taken a company through IPO readiness, or operated in a public company - SEC cybersecurity disclosure, SOX IT controls, Board reporting cadence. • You've secured operational or physical environments - warehouses, manufacturing, robotics, OT/IoT - not just cloud. • You've built AI/ML security governance for production systems, ideally against NIST AI RMF. • EU/UK regulatory experience: GDPR, DPF, NIS2, the EU AI Act. • You've worked somewhere the physical world breaks when software fails.

About STORD

STORD is a cloud-based warehousing and distribution network that provides modern logistics infrastructure for businesses of all sizes. The company's platform connects a network of warehouses across the United States and provides businesses with real-time visibility, control, and optimization of their inventory and supply chain operations. STORD's mission is to empower businesses with the technology and infrastructure they need to compete in today's fast-paced, global economy.
Learn more about STORD
Size
100 employees
Industry

Similar Jobs

More Jobs at STORD

More Information Technology Jobs

Find similar VP, Security jobs: