SlipstreamJobsFresh Startup & VC-Backed Jobs

Director of Cybersecurity & IT

Back Market - Paris, France - Hybrid - posted 2026-09-07

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Back Market is a global marketplace for refurbished devices, operating with a mission to make tech reliable, affordable, and sustainable. The company is seeking a Director of Cybersecurity & IT to lead the next phase of security and technology operations maturity, reporting to the VP of Platform Engineering. This is a strategic director-level role focused on setting direction, developing leaders, and aligning stakeholders rather than personally executing every technical decision. You will lead a multi-disciplinary organization spanning cybersecurity strategy and risk management, security operations, governance and compliance, IT operations, IT support, and corporate technology foundations. Key responsibilities include: **Strategy & Investment**: Define and evolve a multi-year Cybersecurity & IT strategy aligned with business goals and growth plans. Translate strategy into a focused portfolio of initiatives with clear outcomes, sequencing, and success measures. Own the operating rhythm including planning, budgeting, program tracking, KPI/SLA reporting, and executive communication. Make pragmatic investment recommendations balancing resilience, customer trust, regulatory expectations, and engineering velocity. **Leadership & Organization**: Lead through functional managers and senior individual contributors responsible for Security Operations, Governance Risk & Compliance, IT Operations Engineering, IT Support, and security/product security capabilities. Coach and develop leaders, create clear career paths and succession plans, build a high-trust environment with genuine ownership, and attract/retain exceptional talent. **Business Enablement**: Act as trusted advisor to VP of Engineering, CTO, and Executive Committee. Explain complex security and IT topics in clear business language, including trade-offs and consequences. Engage cross-functionally to advocate for security and resilience. Build alignment through influence rather than authority. **Enterprise Risk & Compliance**: Own cyber risk management at strategic level using GRC framework. Ensure material risks, control gaps, and remediation plans are visible and actively managed. Support compliance efforts across ISO 27001, PCI DSS, GDPR, NIS2, and contractual requirements. Partner with VP Legal and DPO on data privacy strategy. Represent security maturity to investors, auditors, regulators, and customers. Serve as senior escalation point for major security incidents. **Secure Products & Resilient Technology**: Partner with Engineering and Product to integrate security requirements from the beginning. Sponsor Product Security and secure software development lifecycle practices. Ensure security roadmap addresses risks across cloud infrastructure, corporate systems, identity and access, endpoints, applications, data, and third-party services. Set expectations for Security Operations including threat intelligence, vulnerability management, security monitoring, and incident readiness. Ensure IT Operations provides reliable, scalable experience globally. **Security Culture**: Foster security-aware culture through clear communication about threat landscape and key initiatives. Sponsor awareness and Security Champion programs. Represent Back Market in security communities and industry groups. Build relationships with technology partners, auditors, and insurers. **Requirements**: - 12 to 15+ years of experience across cybersecurity, information security, IT, or related technology leadership roles, including at least 5 years leading managers and multi-team organizations - Proven track record of building, scaling, and developing organizations spanning multiple security and/or IT domains - Experience operating as strategic partner to CTO, VP Engineering, executive committee, or equivalent senior leadership - Proven expertise across security operations, cyber risk and governance, compliance and assurance, security architecture, product security, cloud security, IT operations, or corporate technology - Demonstrated ability to turn business strategy and risk appetite into practical security and IT roadmap, investment plan, and operating model - Experience communicating security and technology risk to executive, board-level, investor, partner, audit, and non-technical audiences - Mature, risk-based approach with understanding that perfect security does not exist and good leadership means making explicit, informed trade-offs - Experience leading through managers and senior experts with passion for developing people and building leadership capability - Strong understanding of modern cloud, SaaS, identity, endpoint, application, data, and infrastructure security concepts - Experience with security-by-design and secure software development lifecycle practices - Excellent written and verbal communication in English; French is a plus - Judgment, calm, and influence to operate effectively in ambiguity, during incidents, and across competing stakeholder priorities - Genuine excitement about Back Market's mission and belief that cybersecurity and IT are essential enablers of sustainable growth **Nice to have**: - Recognized certification such as CISSP, CISM, CISA, CRISC, CCSP, or equivalent - Experience with ISO 27001, PCI DSS, GDPR, NIS2, or other European regulatory frameworks - Experience with GCP, Kubernetes, Terraform, modern cloud-native security tooling, or SaaS-first environments - Experience in marketplace, e-commerce, fintech, or business with meaningful customer, partner, or regulatory trust requirements - Experience with AI security, fraud prevention, third-party risk, or software supply chain security - Experience in fast-growing, international organization with distributed workforce

Similar roles