VP, Chief Information Security Officer

Commerce.com

Austin (TX)

Hybrid

USD 240,000 - 305,000

Full time

8 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid work model

Job summary

Commerce is seeking a VP, Chief Information Security Officer to own the company’s security, risk, and compliance program for our SaaS platform and corporate systems. You will lead a cross-location team and collaborate with partners to align security with business goals, building trust with customers and stakeholders.

The role requires proven SaaS security leadership, strong governance experience, and the ability to translate complex threats into actionable plans for executives and engineers.

Qualifications

  • Proven leadership in information security for SaaS/platform businesses.
  • Experience with SOX, PCI, GDPR, CCPA, SOC 2, ISO 27001.
  • Strong collaboration with Product, Legal, Privacy, and exec teams.

Responsibilities

  • Define and lead the cybersecurity and GRC strategy across SaaS platforms.
  • Oversee investigations, incident response, and remediation actions.
  • Direct security architecture including IAM, threat modeling, and risk management.
  • Maintain up-to-date understanding of cyber threat landscape and regulatory changes.
  • Communicate security posture to executives and board.

Skills

SaaS Security Leadership
GRC Management
Cloud Security

Tools

GCP
AWS

Job description

Welcome to the Agentic Commerce Era At Commerce, our mission is to empower businesses to innovate, grow, and thrive with our open, AI-driven commerce ecosystem. As the parent company of BigCommerce, Feedonomics, and Makeswift, we connect the tools and systems that power growth, enabling businesses to unlock the full potential of their data, deliver seamless and personalized experiences across every channel, and adapt swiftly to an ever-changing market. We believe in harnessing AI responsibly to unlock new possibilities, and we’re looking for individuals who use it intentionally to solve problems, accelerate outcomes, and expand what’s possible in their role. Our purpose is to help businesses confidently solve complex commerce challenges so they can build smarter, adapt faster, and grow on their own terms. If you want to be part of a team of bold builders, sharp thinkers, and technical trailblazers who shape the future of commerce, this is the place for you.

As VP, Chief Information Security Officer, you will be responsible for Commerce’s overall information security, compliance, and cyber risk program across our SaaS platform, product offerings, and corporate systems. You will lead a talented team of information security, governance, risk, and compliance professionals based in multiple locations, working closely with teams across the company to build and scale a world class information security and compliance program. You will interact directly with security teams within our merchant, prospective customer, and partner communities to collaborate on solutions to shared trust, risk, and security challenges. The right candidate will be a collaborative and forward thinking technology leader with a strong point of view on security in a complex, advanced SaaS environment. Speaking with partners, customers, executives, and board members with comfort and clarity is as important to success as developing a strong roadmap for platform, product, corporate, and compliance security.

What You’ll Do
  • Define and lead Commerce’s cybersecurity and GRC strategy, including policies, standards, and programs that protect corporate and customer digital assets, reduce business risk, and support effective governance and compliance
  • Oversee security investigations and incident response, including impact analysis, executive updates, post incident recommendations, and plans to avoid similar issues in the future
  • Direct and approve the design of security systems, identity and access policies, and GRC procedures that support a secure, scalable SaaS environment
  • Maintain a current understanding of the cyber threat landscape, including relevant risks to SaaS platforms, cloud environments, ecommerce, and the broader technology industry
  • Translate threat, regulatory, and customer requirements into actionable plans that protect the business and support growth
  • Ensure compliance with applicable laws, regulations, customer commitments, and industry frameworks
  • Schedule and oversee periodic security audits, compliance assessments, certifications, and customer assurance activities
  • Oversee identity and access management, third party risk management, vulnerability management, secure configuration practices, and security awareness programs
  • Ensure cybersecurity and GRC policies and procedures are communicated clearly to employees and that compliance expectations are understood and enforced.
  • Oversee teams, employees, contractors, and vendors involved in cybersecurity and GRC, including hiring, performance management, mentoring, and team development
  • Continuously update the cybersecurity and GRC strategy to incorporate new technology, evolving threats, customer expectations, and business priorities.
  • Brief the executive team and board on security posture, key risks, incidents, program maturity, and investment priorities
  • Communicate security best practices and business relevant risks across the company, beyond security and IT, to strengthen shared ownership of security
Who You Are
  • Proven background leading information security within SaaS or platform oriented global companies
  • Strong understanding of current and emerging technologies for security in a cloud based, microservices based environment
  • Expansive experience with compliance frameworks such as SOX, PCI, GDPR, CCPA, SOC 2, and ISO 27001, and their application as both a service provider and a customer
  • Familiarity and comfort with modern DevOps processes as well as distributed cloud environments such as GCP and AWS
  • Experience partnering with Product, Engineering, Legal, Privacy, Sales, IT, and executive leadership to align security priorities with business objectives
  • Ability to communicate cyber risk, security posture, and investment tradeoffs clearly to executives, board members, customers, auditors, and technical teams
  • History of building and growing collaborative security and compliance teams that cross functional teams value working with
  • Experience with corporate cybersecurity in a distributed, cloud first environment
Work Where You Thrive

For candidates based in the Austin or Atlanta metro area, the position follows a hybrid work model with three days per week in the office, balancing focused individual work with meaningful in-person collaboration.

#LI-REMOTE #LI-GC1 (Pay Transparency Range: $240,000.00 - $305,000.00)

Compensation Transparency

The national base salary range for this role is posted above in this job post. Final compensation will be determined based on factors such as relevant experience, skills, qualifications and geographic location. We also consider internal equity to help ensure fair and consistent pay practices across our teams. Where applicable, this role may also be eligible for variable compensation (such as bonus or commission), equity, and benefits in accordance with local policies. Details will be shared during the hiring process. We are committed to equitable and transparent pay practices that align to market data, internal equity, and individual contribution.

Inclusion and Belonging

At Commerce, we believe that celebrating the unique histories, perspectives and abilities of every employee makes a difference for our company, our customers and our community. We are an equal opportunity employer and the inclusive atmosphere we build together will make room for every person to contribute, grow and thrive. We are committed to creating an inclusive and accessible hiring experience for all candidates. If you require accommodations or adjustments at any stage of the recruitment process, please let us know and we will work with you to meet your needs.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VP, Chief Information Security Officer
VP, Chief Information Security Officer

BigCommerce Pty • Austin (TX), Northern (KY)

Hybrid
USD 240,000 - 305,000
VP, Chief Information Security Officer
VP, Chief Information Security Officer

BigCommerce Pty. • Austin (TX), Northern (KY)

On-site
USD 240,000 - 305,000
VP, Chief Information Security Officer
VP, Chief Information Security Officer

Commerce • Austin (TX), Northern (KY)

Hybrid
USD 240,000 - 305,000
VP, Chief Information Security Officer
VP, Chief Information Security Officer

Cacheflow • Austin (TX)

Hybrid
USD 240,000 - 305,000
VP, Chief Information Security Officer
VP, Chief Information Security Officer

bigcommerce • United States

On-site
USD 250,000 - 500,000
Staff Software Engineer
Staff Software Engineer

Cacheflow • Austin (TX)

Hybrid
USD 186,000 - 280,000
Staff Software Engineer
Staff Software Engineer

Commerce.com • Austin (TX)

Hybrid
USD 186,000 - 280,000
Software Engineer II – Remote at Commerce
Software Engineer II – Remote at Commerce

Feedinkoo • United States

Remote
USD 92,000 - 156,000
Staff Software Engineer
Staff Software Engineer

BigCommerce Pty. • Austin (TX)

On-site
USD 186,000 - 280,000
Hybrid work model
Pay transparency
Staff Software Engineer
Staff Software Engineer

Commerce • Austin (TX)

On-site
USD 186,000 - 280,000