Director of Information Security
hace 2 días
Los Angeles
Job Description Who We Are: Being naked is the #1 most sustainable option. We're #2. Since 2009, we've been on a mission to bring sustainable fashion to everyone. Named one of Fast Company's Brands That Matter and winning a Best Carbon Footprint award, we have big goals like being Climate Positive by 2025, Circular by 2030, and pushing the whole industry forward along the way. Our work has gotten love in Drapers and Sourcing Journal, and TIME wrote about how great our CEO, Hali Borenstein, is. Basically, we're saving the Earth and looking damn good doing it. We're a global brand with 50+ stores (and counting) around the world, and our own sustainable factory in LA. We innovate across categories like accessories, swimwear, and sleepwear, and we reach millions of people with campaigns like this, this and this. None of this work is possible without the incredible people behind it. We're a mission-based company that invests in an inclusive culture, so we can innovate together and ensure everyone has the space to grow, thrive, and belong. And starting right now, we want to do all that with you. Work Location: Remote, Full-time The Role: Director of Information Security: This is a critical, high-impact individual contributor role. You will be the sole dedicated security professional, responsible for both defining the strategy and executing the technical work. Success depends on the ability to collaborate extensively with the existing technology team (Engineers, Leadership, Helpdesk) to implement all necessary security changes. You will report directly to the CTO. This role requires a unique "full-stack" security leader—someone who can define a multi-year security strategy (High), translate that strategy into clear projects and policies (Medium), and be technically proficient enough to implement critical changes and troubleshoot systems personally (Low). Key Responsibilities and the H-M-L Mandate The successful candidate will be expected to operate proficiently across three core levels of engagement: • High (Strategy & Governance), • Security Vision & Roadmap: Define and champion a comprehensive, multi-year information security strategy aligned with business objectives, risk tolerance, and industry growth., • Framework Ownership: Own the selection, implementation, and continuous auditing of the NIST Cybersecurity Framework (CSF) across the entire organization., • Board-Level Communication: Develop and present clear, concise security reports, risk posture summaries, and strategic investment requests to Executive Leadership and the Board of Directors., • Risk Management: Lead the formal security risk management program, including top-level risk assessments and prioritization., • Third-Party Oversight: Evaluate and approve security controls for all third-party vendors and key software partners, including NetSuite and other platforms., • Medium (Planning & Collaboration), • Vendor Management: Select, contract, and actively manage third-party security vendors for specialized services like penetration testing and network evaluations., • Internal Collaboration: Work closely with engineers and helpdesk staff to plan the implementation of new controls, ensuring minimal disruption to business operations and end-users., • Policy Development: Translate strategic goals into concrete security policies, standards, and procedures applicable to the organization's diverse environments., • Project Leadership: Act as the technical owner and project manager for major security initiatives (e.g., SIEM implementation, access control overhaul)., • Audit & Remediation: Manage external security audits and self-assessments, planning and tracking remediation efforts based on findings., • Low (Execution & Hands-On Technical Work), • System Hardening: Directly configure and harden core corporate systems, including Google Workspace and AWS cloud environments, and corporate network infrastructure., • Tool Operation: Utilize and manage security toolsets such as CrowdStrike, JumpCloud, SIEM platforms, and open-source scanners like OpenVAS to investigate alerts, perform vulnerability scans, and conduct threat hunting., • Configuration Implementation: Execute hands-on tasks for critical security processes, such as setting up access control policies, troubleshooting security agent installations, and scripting repeatable security tasks., • ERP Security: Work directly within the NetSuite environment to manage roles, permissions, and security configurations., • Incident Response (IR) Readiness: Lead the technical planning for incident response scenarios, including ensuring logs are correctly flowing to the SIEM and actively participating in response and recovery efforts. Qualifications Required Experience • Minimum of 8+ years of progressive experience in Information Security, with at least 3 years in a Director or Senior-level individual contributor role., • Proven hands-on experience in a complex, multi-faceted business environment (including manufacturing, retail, or supply chain)., • Deep technical experience securing modern, cloud-centric environments including Google Workspace, AWS, CrowdStrike, and Identity Providers like JumpCloud., • Relevant industry certifications (CISSP, CISM, CISA, or similar)., • Experience with PCI DSS compliance., • Familiarity with security configurations within NetSuite (or similar ERP systems). Compensation: At Reformation, we believe in transparency and equity when it comes to compensation. For this role, the anticipated base salary range is $185,000 - $200,000 + 15% bonus eligibility, depending on a variety of factors, including but not limited to relevant experience, skills, qualifications, and internal compensation equity. This role may also be eligible for an annual discretionary bonus based on a range of factors, including company performance, department goals, and individual contributions. Bonus amounts and eligibility are not guaranteed and are determined at the company's discretion. Please note that compensation decisions are made thoughtfully and may vary from the listed range to reflect individual circumstances and evolving business needs. Our total rewards package also includes benefits, perks, and opportunities for growth that contribute to overall compensation. Benefits & Perks: • Eligible employees get employer-sponsored private medical, dental, and vision insurance, as well as commuter benefits to help support your travel to and from work., • We offer competitive paid time off policies including vacation, sick leave, and company holidays for eligible employees., • We offer retirement planning support for eligible employees, including the option to invest in Environmental Social Governance-aligned (fancy way to say sustainable) funds., • We're a mission-based company with offices in LA, NYC and London, as well as a global retail team, which means you'll get to collaborate with people all around the world., • You'll get access to fertility care support through Carrot, and up to a $5,000 USD reimbursement for related fertility expenses after 1 year of employment., • We care about the causes our employees care about so we donate to community efforts on a yearly basis. If you require accommodations during the application or interview process, please let us know. We're here to ensure you have what you need to show up as your best self. Still don't know if you should apply? We get it—studies show that many women and individuals from historically underrepresented communities hold back from applying unless they meet every single requirement. At Reformation, we're all about growth, not gatekeeping. If you're passionate about the role and excited about making fashion more sustainable, we'd love to hear from you. If this role doesn't totally excite you, consider applying to our general application. Want some more?! - Sustainability, Forbes, Fast Company