The Director creates the conditions for those leaders to succeed and makes sure their work adds up to a coherent company-wide strategy. Your next missions 👇 Set the strategy, roadmap, and investment priorities Define and evolve a multi-year Cybersecurity & IT strategy aligned with Back Market's business goals, risk appetite, technology strategy, and growth plans Translate that strategy into a focused portfolio of initiatives, with clear outcomes, sequencing, ownership, dependencies, and measures of success Own the operating rhythm for the full scope: planning, budgeting, program tracking, KPI and SLA reporting, risk reviews, and executive communication Make pragmatic investment and prioritization recommendations, balancing resilience, customer trust, regulatory expectations, employee experience, and engineering velocity Establish the governance forums and decision mechanisms needed to keep priorities clear and accountability visible Lead and grow a high-performing leadership organization Lead through the managers and senior individual contributors responsible for Security Operations, Governance Risk & Compliance, IT Operations Engineering, IT Support, and relevant security engineering or product security capabilities Coach, challenge, and develop your leaders, helping them grow their scope, judgment, influence, and ability to build strong teams of their own Create clear career paths, succession plans, and development opportunities across the organization Build a high-trust environment where teams have genuine ownership, collaborate across boundaries, and are encouraged to improve how work gets done Attract and retain exceptional talent, define what great leadership and execution look like, and continuously raise the bar without creating unnecessary bureaucracy Ensure that responsibilities, decision rights, and interfaces between the teams are explicit, understood, and respected Turn cybersecurity into a business enabler Act as a trusted advisor to the VP of Engineering, CTO, Executive Committee, and senior leaders across the business Explain complex security, IT, and risk topics in clear business language, including the trade-offs, options, costs, and consequences of different decisions Engage with Heads of and cross-functional streams across Back Market to advocate for security and resilience in all areas of the business Build alignment rather than relying on authority, and help teams adopt secure and resilient ways of working because they understand the rationale and value Partner with Finance and senior technology leadership on investment cases, budget stewardship, vendor strategy, and the value delivered by the portfolio Steer enterprise cyber risk and trust Own the cyber risk management process at the strategic level, using the GRC framework as the foundation for security decisions and prioritization Ensure that material risks, control gaps, exceptions, and remediation plans are visible, understood, and actively managed Escalate critical risks when they exceed the organization's risk appetite or require executive arbitration Support security compliance efforts across the organization, ensuring alignment and buy-in from peers and key stakeholders across ISO 27001, PCI DSS, GDPR, NIS2, and contractual partner requirements Partner with the VP Legal and DPO on the company's data privacy strategy, ensuring privacy and security requirements are considered early in business, product, and technology decisions Represent Back Market's security maturity and risk posture to investors, auditors, regulators, strategic partners, and major customers Serve as the senior escalation point for major or complex security incidents, ensuring the right executive communication, decision-making, learning, and follow-through without displacing the operational ownership of the incident response teams Enable secure products and resilient technology Partner with Engineering, Product, and other Bureau of Technology directors to ensure security requirements are integrated into product and feature development from the beginning Sponsor and evolve Product Security and secure software development lifecycle practices, including security-by-design, threat modeling, appropriate testing, and pragmatic guardrails Ensure the security roadmap addresses the most important risks across cloud infrastructure, corporate systems, identity and access, endpoints, applications, data, and third-party services Set the expectations for Security Operations across threat intelligence, vulnerability management, security monitoring, incident readiness, risk assessment and project design reviews, fraud support, AI security, and associated SLA and KPI tracking Ensure IT Operations and IT Support provide a reliable, scalable, and high-quality experience for Back Makers across our global offices and remote workforce Champion automation, standardization, and engineering-led approaches that reduce manual work and improve reliability, while leaving day-to-day technical ownership with the appropriate functional teams Build security culture and external credibility Foster a security-aware culture through clear communication about the evolving threat landscape, key initiatives, practical expectations, and the role every Back Maker plays in protecting the company Sponsor awareness, education, and Security Champion programs that make secure behavior accessible and relevant to different audiences Represent Back Market in relevant security communities, industry groups, partner forums, and regulatory conversations Build trusted relationships with strategic technology partners, auditors, insurers, and external security providers Help Back Market demonstrate that strong security, responsible technology, and business agility reinforce one another You could be a good fit if you've: A proven track record of building, scaling, and developing organizations that span multiple security and/or IT domains 12 to 15+ years of experience across cybersecurity, information security, IT, or related technology leadership roles, including at least 5 years leading managers and multi-team organizations Experience operating as a strategic partner to a CTO, VP Engineering, executive committee, or equivalent senior leadership group Proven expertise and a solid grasp of the domains listed below: security operations, cyber risk and governance, compliance and assurance, security architecture, product security, cloud security, IT operations, or corporate technology Demonstrated ability to turn business strategy and risk appetite into a practical security and IT roadmap, investment plan, and operating model Experience communicating security and technology risk to executive, board-level, investor, partner, audit, and non-technical audiences A mature, risk-based approach.