SlipstreamJobsFresh Startup & VC-Backed Jobs

Director, Enterprise Security & IT

Klue - Vancouver, BC, Canada - Hybrid - posted 2026-09-29

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Klue is building the future of competitive intelligence with AI-first agents that generate market, competitor, and buyer insights. As Director of Enterprise Security & IT, you will own the security, compliance, and IT operations function—currently split across teams—and consolidate them into one unified team with a shared roadmap reporting directly to the CTO. Your core responsibilities include: **Security & Incident Readiness**: Mature Klue's security posture by designing and implementing incident response processes, governance frameworks, and detection/response capabilities. Ensure the organization is prepared before incidents occur. **Compliance & Audit Management**: Own the annual audit cycle for SOC 2 Type II, NIST CSF, and BSIMM compliance, including penetration testing. Build audit methodology and documentation that streamline reviews across the company. **Go-to-Market Security**: Manage customer security questionnaires, external assessments, and audits. Review and negotiate data protection agreements and security exhibits with customers and vendors to ensure alignment between commitments and capabilities. **Vendor & Data Governance**: Conduct full-spectrum vendor reviews including sub-processor qualification. Own data loss prevention (DLP), data retention policies, and privacy frameworks for an international customer base, including data subject access requests. **AI & Access Governance**: Define and enforce policies for AI security, including data handling, permissioning, and risk acceptance for AI tools and agents connected to company systems. Establish access governance for high-risk systems, admin access reviews, and controls on sensitive data. **Security Engineering Partnership**: Set security and compliance standards for the Engineering team. Provide tooling, policy, and guidelines to enable secure development, and translate technical work into business-relevant terms for leadership and customers. **IT Operations & Employee Enablement**: Own devices, access, and tooling across the full employee lifecycle. Manage IT vendors, define and meet SLOs for corporate systems, and partner with People to ensure smooth onboarding and offboarding. Success metrics include: consolidating three functions into one team with unified roadmap within two quarters; delivering fast, consistent customer security answers; establishing clear AI and access governance; achieving reliable corporate systems with defined SLOs; documented incident response readiness; seamless Day 1 employee experience; and active budget management with clear tradeoffs. You will shape a brand-new function from the ground up, building a small, sharp team starting with 2 people. You'll report to the CTO and work closely with the Senior Leadership Team, Engineering, Product, Sales, and People teams. This is a high-impact role where you define the operating model, culture, and technical direction for security and IT at a fast-growing, AI-first company. **Requirements** Must Haves: - Demonstrated experience running security and compliance at a company handling sensitive customer data, including DLP, data retention, and privacy frameworks - Experience leading IT operations for an entire company, covering equipment, access, and tooling - In-depth knowledge of security frameworks (SOC 2, ISO 27001, NIST) and global privacy regulations (GDPR, CCPA) - Comfort with ambiguity and building without an established playbook - Clear communication skills with both technical peers and non-technical leaders; ability to explain risk to engineers and executives - Experience negotiating data protection agreements and security exhibits in vendor and customer contracts - Understanding of AI security and governance, including data retention commitments, access/permissioning for AI agents and integrations, and risk acceptance for AI tooling - Track record of working closely with product and engineering teams to translate security and compliance goals into reality Nice-to-Haves: - Experience owning DevOps and/or security engineering functions within a larger engineering organization - Track record of consolidating previously siloed security, compliance, and IT teams - Knowledge of privacy and data residency frameworks for international customer bases - Experience managing distributed or hybrid teams

Similar roles