Job Title: Director - Security
Location: USA / EST time zone
Contract: Permanent
About Us
Cyncly is a global technology powerhouse with 2,400+ employees and 70,000+ customers across 100+ countries. Cyncly transforms the way customizable products and spaces are imagined, designed, sold, managed and made. Our end-to-end software solutions connect professional designers, retailers and manufacturers to the world's largest repository of product content. Today, our business spans across the Kitchen & Bath, Furniture, Window, Glass & Door, and Flooring industries with operations in North & South America, Europe, Asia Pacific and Africa.
Cyncly brings over 30 years of experience to deliver more value for our customers through an expanded portfolio of end-to-end solutions. Our global presence allows us to provide world-class support and sales with a local touch, providing the best possible customer experience.
Cyncly is now embarking on an exciting journey as we continue to expand through strong organic growth and complementary acquisitions, backed by leading growth private equity firms specialized in technology.
About the Role
The Director – Security is a senior IT leadership role responsible for defining, executing, and continuously maturing Cyncly's global cyber security strategy, data protection programme, and information security posture. Reporting to the Head of IT & Cyber Security, this role is the primary owner of all security disciplines — from threat detection and incident response to security architecture, data governance, and regulatory compliance.
A critical element of this role is owning Cyncly's compliance obligations end-to-end, including achieving and maintaining SOC 2 Type II certification across Cyncly's global operations, and ensuring adherence to GDPR, ISO 27001, and other applicable frameworks. The Director will act as Cyncly's senior authority on all matters relating to information security risk, data privacy, and cyber resilience, partnering closely with Product, Engineering, Legal, and business leadership to embed security into the fabric of everything Cyncly does.
Key Responsibilities
Cyber Security Strategy & Leadership
- Define and own Cyncly's global cyber security strategy, roadmap, and operating model, aligning security investment and priorities to business risk and growth objectives.
- Build and lead a high-performing, globally distributed cyber security team, setting clear direction, developing talent, and fostering a culture of security awareness and accountability.
- Act as the primary security advisor to the Head of IT & Cyber Security, CTO, and senior leadership, translating threats and technical risks into clear, business-relevant guidance; represent Cyncly's security posture to customers, auditors, regulators, and the Board.
- Establish and govern security policies, standards, and procedures organisation-wide; drive continuous improvement through threat intelligence, industry benchmarking, and emerging best practices.
Compliance, Certifications & Regulatory Obligations
- Own end-to-end accountability for Cyncly's SOC 2 Type II certification programme — including scoping, control design, evidence collection, auditor management, and remediation of findings — ensuring successful annual certification and ongoing continuous compliance.
- Lead and maintain compliance with ISO 27001, GDPR, CCPA, and other applicable data protection regulations across all jurisdictions; serve as primary contact for external auditors, regulatory bodies, and certification authorities.
- Develop and maintain a compliance calendar and evidence management framework, ensuring Cyncly is audit-ready at all times; proactively monitor the regulatory landscape to identify and address new obligations.
- Collaborate with Legal, Finance, and HR to ensure organisation-wide policies — data retention, privacy notices, HR security controls, and supplier assurance — meet all compliance obligations.
Data & Information Security
- Define and implement Cyncly's data classification framework, data governance policies, and information lifecycle management practices; oversee DLP controls, encryption standards, and data access management across all repositories, cloud platforms, and SaaS applications.
- Embed data privacy by design into all product development, infrastructure, and business processes; manage end-to-end responses to DSARs, breach notifications, and privacy incidents in accordance with GDPR and local privacy laws.
- Partner with Enterprise Architecture and Engineering to ensure all data flows, storage, and processing activities are documented, controlled, and compliant with applicable regulations.
Threat Detection, Incident Response & Security Operations
- Own and mature Cyncly's SOC capability — in-house or managed — ensuring 24/7 detection, triage, and response across endpoints, cloud, network, and application layers.
- Develop, maintain, and test Cyncly's IR plan and cyber crisis playbooks including tabletop exercises; act as senior Incident Commander leading containment, eradication, recovery, and post-incident review.
- Drive adoption of threat intelligence platforms, SIEM/SOAR, and EDR/XDR solutions; reduce MTTD/MTTR through automation and lead the vulnerability management and penetration testing programmes.
Security Architecture & Engineering
- Define and govern security architecture principles across cloud (Azure/AWS), on-premises, hybrid, and SaaS environments, ensuring security by design in all technology programmes.
- Lead zero-trust network architecture and micro-segmentation; embed security into CI/CD pipelines, IaC, and cloud landing zones (DevSecOps); provide architecture sign-off for major programmes and M&A integrations.
Identity, Access & Privileged Access Management
- Own Cyncly's IAM programme including RBAC, least-privilege enforcement, and access certification; lead PAM controls ensuring all privileged accounts are governed, monitored, and auditable.
- Drive SSO, MFA, and Conditional Access adoption across all platforms; ensure timely provisioning and deprovisioning for all joiners, movers, and leavers.
Mergers & Acquisitions — Security Due Diligence & Integration
- Lead cyber security due diligence for M&A targets, evaluating security posture, data protection practices, compliance status, and technical debt, providing risk-rated findings to inform deal decisions.
- Define and execute security integration roadmaps; build repeatable M&A security playbooks to accelerate future acquisitions and ensure acquired entities meet SOC 2 and applicable compliance obligations.
Security Awareness, Culture & Third-Party Risk
- Design and deliver a global security awareness programme including phishing simulations, role-specific training, and executive briefings; manage third-party risk via assessment, contractual controls, and audits.
- Build and maintain a security champion network across Engineering and Product, fostering a security-first culture at the development and operational level.
Qualifications and Skills
Required Qualifications
- Bachelor's degree or equivalent in Computer Science, Information Security, or Cybersecurity; advanced degree preferred.
- 20+ years of experience in information security and data protection, with 10+ years in a senior security leadership or director-level role.
- Proven SOC 2 Type II certification experience in a complex, global SaaS organisation; deep expertise in GDPR, CCPA, and global data privacy regulations.
- Track record of leading cloud security transformations, zero-trust implementations, and M&A security integrations across globally distributed organisations.
Mandatory Technical & Domain Expertise
- Cloud Security: Deep expertise in Microsoft Azure (Security Centre, Defender for Cloud, Sentinel); AWS or GCP advantageous.
- Compliance Frameworks: SOC 2, ISO 27001/27002, NIST CSF, CIS Controls, GDPR/CCPA; PCI DSS or HIPAA a plus.
- Security Operations: SIEM (Sentinel, Splunk), SOAR, EDR/XDR, and vulnerability management tools (Qualys, Tenable, Rapid7).
- Data & Identity Security: DLP, data classification, encryption, Active Directory, Azure AD/Entra ID, PAM (CyberArk, BeyondTrust), SSO, MFA, Conditional Access.
- DevSecOps & Network Security: SAST/DAST/SCA in CI/CD, IaC security scanning, container/Kubernetes security, zero-trust networking, firewall management (Palo Alto, Cisco).
Professional Certifications
- Required: CISSP or CISM. Strongly preferred: CCSP or CRISC.
- Preferred: ISO 27001 Lead Implementer or Lead Auditor; SOC 2 examination credentials; CEH, OSCP, or equivalent.
Competency Requirements
- Security Leadership: Credible at Board and C-suite level; translates complex threats into business risk language.
- Strategic Thinking: Long-term security vision balanced with immediate compliance demands in a fast-growing, acquisition-driven organisation.
- Compliance Ownership: Methodical and detail-driven; manages concurrent audits without BAU disruption.
- Crisis Leadership: Calm and decisive under pressure; leads incident response with clear executive communication.
- Collaboration & Influence: Engages credibly across Engineering, Product, Legal, Finance, and Business to drive security outcomes.
- Analytical & Risk-Driven: Uses data and risk frameworks to prioritise decisions and quantify security value.
- Self-directed & Adaptable: Operates autonomously at pace in a PE-backed, M&A-active global environment.
Working for us
At Cyncly, we’re a global family that collaborates with humility and respect for one another. With more than 2,400 employees around the world, we not only recognize our diverse perspectives, but we also champion our different outlooks and firmly believe it to be what makes us better together.
You can expect to work in a supportive and nurturing environment, with experts in their fields who strive for quality and excellence without compromising others. We also believe in a flexible and autonomous working environment that focuses on the continual growth of our employees.
Diversity of experience and skills combined with passion are a key to innovation and brilliance, so we encourage applicants from all backgrounds to apply to our roles.
That’s who we are: A team that recognizes our strength is in working together to not only get things done but also lead the industry with a bold approach that’s dedicated to making our customers better. Come join us.
In accordance with applicable pay transparency laws, we are committed to providing clear and equitable compensation information. For this remote position, the expected salary range is $150,000 - 175,000 USD, depending on location, experience, and qualifications. This role may also be eligible for additional compensation such as bonuses, commissions, as well as a comprehensive benefits package. Candidates applying from jurisdictions with specific pay disclosure requirements (e.g., California, Colorado, New York, Washington, Illinois, British Columbia) will receive location-specific compensation details in compliance with local laws.
Equal Opportunity Employer Statement:
Cyncly is committed to equal opportunity and does not discriminate based on race, color, creed, religion, gender, age, sexual orientation, national origin, disability, veteran status, or any other characteristic protected by law.
Applicants must be legally authorized to work in the country in which they are applying to work (United States or Canada). This role is not eligible for employer sponsorship now or in the future.
Skills Required
- Bachelor's degree or equivalent in Computer Science, IT, Engineering, or related field
- Advanced degree (preferred)
- 5-10 years progressive experience in IT infrastructure and hosting operations with minimum 5-7 years in senior leadership/director-level
- Experience managing enterprise-scale hosting environments spanning cloud (Azure), co-location, and hybrid architectures
- Proven track record leading complex infrastructure programmes, M&A integrations, and large-scale migration projects
- Experience operating across global, distributed organisations with EST/CST coverage and time zone bridging to APAC/EMEA
- Strong exposure to AIOps tooling, automation platforms, and observability solutions
- Deep hands-on and architectural knowledge of Microsoft Azure (IaaS, PaaS, SaaS)
- Familiarity with AWS or GCP (advantage)
- Expertise in enterprise networking: SD-WAN, routing & switching, VPNs, DNS/DHCP, firewall administration (Cisco, Palo Alto, or equivalent)
- Experience with virtualization and compute technologies: VMware vSphere/NSX, Hyper-V
- Experience with software-defined and enterprise storage: SAN, NAS, object storage
- Proficiency with monitoring and observability platforms (e.g., Datadog, Dynatrace, Azure Monitor, PagerDuty)
- Experience implementing ITIL-based service management frameworks and familiarity with ServiceNow or similar ITSM
- Solid understanding of Identity & Access Management: Active Directory, Azure AD/Entra ID, PAM solutions, SSO/MFA
- Experience designing and managing enterprise backup solutions and business continuity/disaster recovery strategies
- Proven incident command experience leading P1/P2 major incidents and coordinating cross-functional bridge calls and on-call rotations
- Experience embedding security-by-design and meeting regulatory/compliance standards (e.g., SOC 2, GDPR)
- Ability to represent IT to C-suite and present complex technical topics to non-technical stakeholders
- Must be legally authorized to work in the United States or Canada; role is not eligible for employer sponsorship
What We Do
Cyncly was created in September of 2022 as the new brand to unite Compusoft, 2020 and their affiliate companies after the two companies merged in 2021. The combined group created a global software powerhouse with more than 2,300 employees and 70,000+ customers across 100+ countries. Our company brings the best together, providing specialized visualization, sales, manufacturing and content solutions for customers wanting to bring spaces to life and bring life to spaces. Our business spans across kitchen, bathroom, furniture, flooring and windows, doors & glass industries with operations in North America, Europe, South America, Asia Pacific and Africa. Cyncly's brands — Compusoft, 2020, 3CAD, Access IT (contract ERP), FeneTech, First Degree Systems, Focco, GO-2B, M3B, Promob, Soft Tech, RFMS and Virtual Worlds — offer end-to-end software solutions that connect designers, retailers, manufacturers, contractors and consumers to make spaces amazing. From inspiration to installation, whether a whole room or a part of it, Cyncly equips customers with the software to transform vision into reality









