About the Role
Hi, we’re Back Market.We’re here to help make tech reliable, affordable, and better than new. We're a global marketplace for refurbished devices, helping lower our collective environmental impact by providing trustworthy, affordable tech with 92% less carbon emissions than new.Yep, you read that right. Turns out refurbished tech is way better for the planet than new. In fact, With every device purchased on Back Market, our positive impact on the planet grows. From our Customer Care representatives to our software engineer, every individual at Back Market cuts the planet — and consumers — a break. Our mission is simple: to do more with what we already have.Are you ready to join us?Back Market is looking for a Director of Cybersecurity & IT to define and lead the next phase of our security and technology operations maturity. Reporting to the VP of Platform Engineering, you will be a strategic leader at the intersection of cybersecurity, IT, risk, compliance, and business growth.You will lead a multi-disciplinary organization through its existing functional managers, creating the clarity, operating rhythm, and investment focus needed to protect Back Market while enabling the company to move quickly. The scope includes cybersecurity strategy and risk management, security operations, governance and compliance, IT operations, IT support, and the corporate technology foundations that keep our people productive and our business resilient. This is a director-level role, not a super-sized operational manager role. You will not be expected to personally own every process or make every technical decision. Your impact will come from setting direction, developing leaders, aligning stakeholders, making sound investment choices, and ensuring that the organization delivers measurable outcomes. You will be the senior voice who makes cybersecurity and IT understandable, actionable, and connected to the business. To know more about our engineering teams:A video of our VP Platform: https://youtu.be/zvTlw4BNNdcOur company purpose: http://bit.ly/3OsScplOur engineering blog: https://bit.ly/3ASJNIDHow we work with the existing teams 💚 The Director sets direction, creates clarity, secures resources, removes organizational obstacles, develops leaders, and ensures that the overall portfolio delivers against agreed outcomes. The functional managers and senior experts retain ownership of day-to-day execution, technical practices, operational processes, and delivery within their domains. The Director creates the conditions for those leaders to succeed and makes sure their work adds up to a coherent company-wide strategy.Your next missions 👇 Set the strategy, roadmap, and investment prioritiesDefine and evolve a multi-year Cybersecurity & IT strategy aligned with Back Market's business goals, risk appetite, technology strategy, and growth plansTranslate that strategy into a focused portfolio of initiatives, with clear outcomes, sequencing, ownership, dependencies, and measures of successOwn the operating rhythm for the full scope: planning, budgeting, program tracking, KPI and SLA reporting, risk reviews, and executive communicationMake pragmatic investment and prioritization recommendations, balancing resilience, customer trust, regulatory expectations, employee experience, and engineering velocityEstablish the governance forums and decision mechanisms needed to keep priorities clear and accountability visible Lead and grow a high-performing leadership organizationLead through the managers and senior individual contributors responsible for Security Operations, Governance Risk & Compliance, IT Operations Engineering, IT Support, and relevant security engineering or product security capabilitiesCoach, challenge, and develop your leaders, helping them grow their scope, judgment, influence, and ability to build strong teams of their ownCreate clear career paths, succession plans, and development opportunities across the organizationBuild a high-trust environment where teams have genuine ownership, collaborate across boundaries, and are encouraged to improve how work gets doneAttract and retain exceptional talent, define what great leadership and execution look like, and continuously raise the bar without creating unnecessary bureaucracyEnsure that responsibilities, decision rights, and interfaces between the teams are explicit, understood, and respected Turn cybersecurity into a business enablerAct as a trusted advisor to the VP of Engineering, CTO, Executive Committee, and senior leaders across the businessExplain complex security, IT, and risk topics in clear business language, including the trade-offs, options, costs, and consequences of different decisionsEngage with Heads of and cross-functional streams across Back Market to advocate for security and resilience in all areas of the businessBuild alignment rather than relying on authority, and help teams adopt secure and resilient ways of working because they understand the rationale and valuePartner with Finance and senior technology leadership on investment cases, budget stewardship, vendor strategy, and the value delivered by the portfolio Steer enterprise cyber risk and trustOwn the cyber risk management process at the strategic level, using the GRC framework as the foundation for security decisions and prioritizationEnsure that material risks, control gaps, exceptions, and remediation plans are visible, understood, and actively managedEscalate critical risks when they exceed the organization's risk appetite or require executive arbitrationSupport security compliance efforts across the organization, ensuring alignment and buy-in from peers and key stakeholders across ISO 27001, PCI DSS, GDPR, NIS2, and contractual partner requirementsPartner with the VP Legal and DPO on the company's data privacy strategy, ensuring privacy and security requirements are considered early in business, product, and technology decisionsRepresent Back Market's security maturity and risk posture to investors, auditors, regulators, strategic partners, and major customersServe as the senior escalation point for major or complex security incidents, ensuring the right executive communication, decision-making, learning, and follow-through without displacing the operational ownership of the incident response teams Enable secure products and resilient technologyPartner with Engineering, Product, and other Bureau of Technology directors to ensure security requirements are integrated into product and feature development from the beginningSponsor and evolve Product Security and secure software development lifecycle practices, including security-by-design, threat modeling, appropriate testing, and pragmatic guardrailsEnsure the security roadmap addresses the most important risks across cloud infrastructure, corporate systems, identity and access, endpoints, applications, data, and third-party servicesSet the expectations for Security Operations across threat intelligence, vulnerability management, security monitoring, incident readiness, risk assessment and project design reviews, fraud support, AI security, and associated SLA and KPI trackingEnsure IT Operations and IT Support provide a reliable, scalable, and high-quality experience for Back Makers across our global offices and remote workforceChampion automation, standardization, and engineering-led approaches that reduce manual work and improve reliability, while leaving day-to-day technical ownership with the appropriate functional teams Build security culture and external credibilityFoster a security-aware culture through clear communication about the evolving threat landscape, key initiatives, practical expectations, and the role every Back Maker plays in protecting the companySponsor awareness, education, and Security Champion programs that make secure behavior accessible and relevant to different audiencesRepresent Back Market in relevant security communities, industry groups, partner forums, and regulatory conversationsBuild trusted relationships with strategic technology partners, auditors, insurers, and external security providersHelp Back Market demonstrate that strong security, responsible technology, and business agility reinforce one anotherYou could be a good fit if you've:A proven track record of building, scaling, and developing organizations that span multiple security and/or IT domains12 to 15+ years of experience across cybersecurity, information security, IT, or related technology leadership roles, including at least 5 years leading managers and multi-team organizationsExperience operating as a strategic partner to a CTO, VP Engineering, executive committee, or equivalent senior leadership groupProven expertise and a solid grasp of the domains listed below: security operations, cyber risk and governance, compliance and assurance, security architecture, product security, cloud security, IT operations, or corporate technologyDemonstrated ability to turn business strategy and risk appetite into a practical security and IT roadmap, investment plan, and operating modelExperience communicating security and technology risk to executive, board-level, investor, partner, audit, and non-technical audiencesA mature, risk-based approach. You understand that perfect security does not exist, and that good leadership means making explicit, informed trade-offs and focusing resources where they have the greatest impactExperience leading through managers and senior experts, with a genuine passion for developing people, building leadership capability, and creating meaningful career pathsStrong understanding of modern cloud, SaaS, identity, endpoint, application, data, and infrastructure security concepts, even if you are not the deepest technical expert in every domainExperience with security-by-design, secure software development lifecycle practices, and effective partnership with Engineering and Product teamsExcellent written and verbal communication in English, with the ability to make complex topics clear, concrete, and compelling. French is a plusThe judgment, calm, and influence required to operate effectively in ambiguity, during incidents, and across competing stakeholder prioritiesGenuine excitement about Back Market's mission and the belief that cybersecurity and IT are essential enablers of sustainable growthNice to haveA recognized certification such as CISSP, CISM, CISA, CRISC, CCSP, or an equivalent professional qualificationExperience with ISO 27001, PCI DSS, GDPR, NIS2, or other relevant European regulatory and assurance frameworksExperience with GCP, Kubernetes, Terraform, modern cloud-native security tooling, or SaaS-first environmentsExperience in marketplace, e-commerce, fintech, or another business with meaningful customer, partner, or regulatory trust requirementsExperience with AI security, fraud prevention, third-party risk, or software supply chain securityExperience working in a fast-growing, international organization with distributedHiring processPhone call with Marie, Technical Talent Acquisition Partner - 45 min Deep-dive interview on cybersecurity and IT strategy with your future manager, the VP of Engineering - 60 min Leadership and management interview with a peer Engineering Director and an Engineering Manager - 60 min Meet your future team - 45 min Stakeholder interview with cross-functional partners, including the CTO and relevant Security and IT leaders - 60 min Cultural and Values interview with a C-level leader from Back Market - 45 min WHY SHOULD YOU JOIN US ? ✌🏼At Back Market, we’re committed to hiring and supporting diverse teams of people from all backgrounds, experiences, and perspectives — it’s one of the reasons we’re such a high-scoring certified B Corp company (93.2).No matter your role and seniority level, you’ll enjoy impact-driven work with hands-on career development in an innovative, driven, and fast-paced environment — with benefits to match, like:- A mission driven work environment where your day to day makes an impact on the planet. Seriously.- Hybrid work environment, with 2 remote days a week and 1 remote work week per quarter, plus 3 flex days.- Employee Resource Groups, including mentorship programs, comprehensive accessibility policies, and cultural competency training.At Back Market, we strive to create a workplace that embodies the world we’re trying to change. We’ve embedded our diversity, equity, and inclusion principles into our DNA — from dedicated staff to employee resource groups to our company values.We know that the perfect background for a role doesn’t mean the perfect fit — we encourage you to apply for a role even if you think you may not have all the qualifications.If reasonable accommodations are needed for the interview process, please do not hesitate to discuss this with the Talent Acquisition Team.Find more English Speaking Jobs in France on Arbeitnow
Requirements
Qualifications
- Experience: 10+ Years
Education Details
Minimum Education
High School