VP, Security

Posted Yesterday
Be an Early Applicant
Hiring Remotely in United States
Remote
Expert/Leader
Logistics • Software
The Role
Lead Stord’s enterprise security function and build its long-term strategy, governance, operations, engineering, application and cloud security capabilities. Own NIST, SOC 2 and ISO programs, 24/7 detection and response, incident management, M&A security integration, secure product development, penetration testing, customer trust, business continuity and disaster recovery. Lead the security team, MDR partnership, executive and board communications, AI governance, and security readiness for international growth, acquisitions and potential public-market scrutiny.
Summary Generated by Built In
ABOUT STORD
Stord is The Consumer Experience Company, powering seamless checkout through delivery for today's leading brands. Stord is rapidly growing and strategically scaling teams across the entire company, and seeking energetic experts to help us achieve our mission.
By combining comprehensive commerce-enablement technology with high-volume fulfillment services, Stord provides brands a platform to compete with retail giants. Stord manages over $10 billion of commerce annually through its fulfillment, warehousing, transportation, and operator-built software suite including OMS, Pre- and Post-Purchase, and WMS platforms. Stord is leveling the playing field for all brands to deliver the best consumer experience at scale.
With Stord, brands can increase cart conversion, improve unit economics, and drive sustained customer loyalty. Stord’s end-to-end commerce solutions combine best-in-class omnichannel fulfillment and shipping with leading technology to ensure fast shipping, reliable delivery promises, easy access to more channels, and improved margins on every order.
Hundreds of leading DTC and B2B companies like True Classic, Native, Seed Health, goodr, Sundays for Dogs, and more trust Stord to deliver industry-leading consumer experiences on every order. Stord is headquartered in Atlanta with facilities across the United States, Canada, and Europe. Stord is backed by top-tier investors including Kleiner Perkins, Franklin Templeton, Founders Fund, Strike Capital, Baillie Gifford, and Salesforce Ventures.

This is a build role, not a maintain role. You'll inherit a real foundation — SOC 2 Type II attestation across our core platforms, a public Trust Center, EU-U.S. Data Privacy Framework certification, and a small, capable team — and you'll own what comes next: the strategy, the team, the technical stack, and the operating rhythm that carry Stord through international expansion, continued M&A, AI deployment across the product, and eventual public-market scrutiny.

What You'll Own

Strategy and governance.

Set the security strategy and the multi-year roadmap. Run our program against NIST CSF 2.0 and expand audit scopes and certifications. Establish AI governance across our models, agents, and Stord Labs work.

Security operations.

Stand up 24/7 detection and response, initially through an MDR partnership, and progressively bring detection engineering in-house. Own incident response end to end — playbooks, on-call, tabletop exercises with the executive team, and the postmortems that actually change something.

Security engineering.

Build and operate the technical stack: SIEM/SOAR, EDR/XDR, cloud security posture management, API security, secrets management, and vulnerability management. Harden CI/CD across a 200+ person engineering organization — signed commits, SBOM generation, dependency and secrets scanning, SAST/DAST in the pipeline.

M&A security integration.

Stord acquires companies, and every deal brings inherited systems, credentials, and technical debt. You'll own security diligence on future targets and the integration playbook that gets acquired environments to our standard on a predictable timeline.

Product and customer trust.

Partner with Product and Engineering on secure-by-default design across Logistics, Brands, and Commerce. Own penetration testing and our bug bounty program. Be the executive voice in enterprise security reviews and questionnaires — the ones that decide whether a deal closes this quarter or next.

Resilience.

Own business continuity and disaster recovery for an operation where downtime means orders don't ship. Prove recovery works by testing it, not by documenting it.

Team.

Lead and grow a team spanning GRC, security operations, security engineering, application security, and cloud/infrastructure security, plus an MDR partner. You'll inherit the existing team, then define and hire the rest of the structure yourself.What We're Looking For
  • 12+ years in security, including 5+ leading a security function at a SaaS or platform company.
  • Depth in cloud-native security at scale — AWS/GCP, Kubernetes, microservices, CI/CD, API security. You should be able to hold your own in an architecture review, not just read the summary.
  • Hands-on experience owning M&A security diligence and integration.
  • Track record building a security program against NIST CSF, SOC 2, and ISO 27001 — and passing the audits.
  • Experience standing up or running 24/7 detection and response, whether in-house, through MDR, or a hybrid.
  • Executive and Board communication chops. You can explain residual risk to a board, a trade-off to a CFO, and a control to an engineer, and be understood by all three.
  • Judgment about where to spend. You know which risks justify a control, which justify a conversation, and which justify neither.

Bonus Points
  • You've taken a company through IPO readiness, or operated in a public company — SEC cybersecurity disclosure, SOX IT controls, Board reporting cadence.
  • You've secured operational or physical environments — warehouses, manufacturing, robotics, OT/IoT — not just cloud.
  • You've built AI/ML security governance for production systems, ideally against NIST AI RMF.
  • EU/UK regulatory experience: GDPR, DPF, NIS2, the EU AI Act.
  • You've worked somewhere the physical world breaks when software fails.

Skills Required

  • 12+ years of experience in security
  • 5+ years leading a security function at a SaaS or platform company
  • Cloud-native security experience at scale, including AWS or GCP, Kubernetes, microservices, CI/CD and API security
  • Experience owning M&A security diligence and integration
  • Experience building security programs against NIST CSF, SOC 2 and ISO 27001 and passing audits
  • Experience standing up or operating 24/7 detection and response through an internal, MDR or hybrid model
  • Executive and board communication experience
  • Demonstrated judgment in security risk prioritization and control investment
  • IPO readiness or public-company experience, including SEC cybersecurity disclosure, SOX IT controls and board reporting
  • Security experience with warehouses, manufacturing, robotics, OT or IoT environments
  • AI/ML security governance experience, ideally using NIST AI RMF
  • EU/UK regulatory experience with GDPR, DPF, NIS2 or the EU AI Act
  • Experience in environments where software failures affect physical operations
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Atlanta, GA
222 Employees
Year Founded: 2015

What We Do

Stord is on a mission to migrate supply chains to the cloud—empowering brands to build sophisticated, agile, and integrated supply chains. Founded in 2015 and headquartered in the heart of Atlanta's vibrant tech community, Stord is pioneering the world's first Cloud Supply Chain. The Cloud Supply Chain is the convergence of the digital and physical elements of logistics. With Stord's Cloud Supply Chain, businesses can build, expand, and optimize their physical supply chain operations across freight, warehousing, and fulfillment, with the speed, flexibility, and ease of modern cloud software.

Similar Jobs

Engine Logo Engine

VP, Security

Artificial Intelligence • Fintech • Software • Travel
Easy Apply
Remote
United States
1000 Employees
298K-400K Annually
In-Office or Remote
Annapolis Junction, MD, USA
14420 Employees
201K-384K Annually
Remote
United States
3600 Employees
197K-288K Annually

Trace3 Logo Trace3

VP, Security

Big Data • Cloud
Remote
United States
944 Employees
250K-350K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account