Back Market

Director of Cybersecurity & IT

Back Market Paris, Ile-de-France, France

Internet Marketplace Platforms · 501-1,000 employees

23 h ago
Remote security Principal (10+ yrs) Full-time France
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Director of Cybersecurity & IT will define and lead the company's security and technology operations strategy, reporting to the VP of Platform Engineering. This role involves managing a multi-disciplinary organization to ensure business resilience, regulatory compliance, and effective risk management.

What they look for

Cybersecurity strategy IT operations Risk management Governance and compliance Leadership Cloud security Product security Stakeholder management Budget stewardship Incident response Strategic planning Team development Data privacy Vendor strategy Security architecture

Requirements

Candidates must have 12 to 15+ years of experience in cybersecurity or IT leadership, with at least 5 years of experience managing teams. Proven expertise in security operations, risk management, and strategic planning is essential for this director-level position.

Benefits

Hybrid work environment Mentorship programs Accessibility policies Cultural competency training Mission-driven work environment

Full description

Hi, we’re Back Market.

We’re here to help make tech reliable, affordable, and better than new. We're a global marketplace for refurbished devices, helping lower our collective environmental impact by providing trustworthy, affordable tech with 92% less carbon emissions than new.

Yep, you read that right. Turns out refurbished tech is way better for the planet than new. In fact, With every device purchased on Back Market, our positive impact on the planet grows. From our Customer Care representatives to our software engineer, every individual at Back Market cuts the planet — and consumers — a break. Our mission is simple: to do more with what we already have.

Are you ready to join us?

Back Market is looking for a Director of Cybersecurity & IT to define and lead the next phase of our security and technology operations maturity. Reporting to the VP of Platform Engineering, you will be a strategic leader at the intersection of cybersecurity, IT, risk, compliance, and business growth.

You will lead a multi-disciplinary organization through its existing functional managers, creating the clarity, operating rhythm, and investment focus needed to protect Back Market while enabling the company to move quickly. The scope includes cybersecurity strategy and risk management, security operations, governance and compliance, IT operations, IT support, and the corporate technology foundations that keep our people productive and our business resilient.

 

This is a director-level role, not a super-sized operational manager role. You will not be expected to personally own every process or make every technical decision. Your impact will come from setting direction, developing leaders, aligning stakeholders, making sound investment choices, and ensuring that the organization delivers measurable outcomes. You will be the senior voice who makes cybersecurity and IT understandable, actionable, and connected to the business.

 

To know more about our engineering teams:

  • A video of our VP Platform: https://youtu.be/zvTlw4BNNdc
  • Our company purpose: http://bit.ly/3OsScpl
  • Our engineering blog: https://bit.ly/3ASJNID

How we work with the existing teams 💚

 

The Director sets direction, creates clarity, secures resources, removes organizational obstacles, develops leaders, and ensures that the overall portfolio delivers against agreed outcomes. The functional managers and senior experts retain ownership of day-to-day execution, technical practices, operational processes, and delivery within their domains. The Director creates the conditions for those leaders to succeed and makes sure their work adds up to a coherent company-wide strategy.

Your next missions 👇

 

Set the strategy, roadmap, and investment priorities

  • Define and evolve a multi-year Cybersecurity & IT strategy aligned with Back Market's business goals, risk appetite, technology strategy, and growth plans
  • Translate that strategy into a focused portfolio of initiatives, with clear outcomes, sequencing, ownership, dependencies, and measures of success
  • Own the operating rhythm for the full scope: planning, budgeting, program tracking, KPI and SLA reporting, risk reviews, and executive communication
  • Make pragmatic investment and prioritization recommendations, balancing resilience, customer trust, regulatory expectations, employee experience, and engineering velocity
  • Establish the governance forums and decision mechanisms needed to keep priorities clear and accountability visible

 

Lead and grow a high-performing leadership organization

  • Lead through the managers and senior individual contributors responsible for Security Operations, Governance Risk & Compliance, IT Operations Engineering, IT Support, and relevant security engineering or product security capabilities
  • Coach, challenge, and develop your leaders, helping them grow their scope, judgment, influence, and ability to build strong teams of their own
  • Create clear career paths, succession plans, and development opportunities across the organization
  • Build a high-trust environment where teams have genuine ownership, collaborate across boundaries, and are encouraged to improve how work gets done
  • Attract and retain exceptional talent, define what great leadership and execution look like, and continuously raise the bar without creating unnecessary bureaucracy
  • Ensure that responsibilities, decision rights, and interfaces between the teams are explicit, understood, and respected

 

Turn cybersecurity into a business enabler

  • Act as a trusted advisor to the VP of Engineering, CTO, Executive Committee, and senior leaders across the business
  • Explain complex security, IT, and risk topics in clear business language, including the trade-offs, options, costs, and consequences of different decisions
  • Engage with Heads of and cross-functional streams across Back Market to advocate for security and resilience in all areas of the business
  • Build alignment rather than relying on authority, and help teams adopt secure and resilient ways of working because they understand the rationale and value
  • Partner with Finance and senior technology leadership on investment cases, budget stewardship, vendor strategy, and the value delivered by the portfolio

 

Steer enterprise cyber risk and trust

  • Own the cyber risk management process at the strategic level, using the GRC framework as the foundation for security decisions and prioritization
  • Ensure that material risks, control gaps, exceptions, and remediation plans are visible, understood, and actively managed
  • Escalate critical risks when they exceed the organization's risk appetite or require executive arbitration
  • Support security compliance efforts across the organization, ensuring alignment and buy-in from peers and key stakeholders across ISO 27001, PCI DSS, GDPR, NIS2, and contractual partner requirements
  • Partner with the VP Legal and DPO on the company's data privacy strategy, ensuring privacy and security requirements are considered early in business, product, and technology decisions
  • Represent Back Market's security maturity and risk posture to investors, auditors, regulators, strategic partners, and major customers
  • Serve as the senior escalation point for major or complex security incidents, ensuring the right executive communication, decision-making, learning, and follow-through without displacing the operational ownership of the incident response teams

 

Enable secure products and resilient technology

  • Partner with Engineering, Product, and other Bureau of Technology directors to ensure security requirements are integrated into product and feature development from the beginning
  • Sponsor and evolve Product Security and secure software development lifecycle practices, including security-by-design, threat modeling, appropriate testing, and pragmatic guardrails
  • Ensure the security roadmap addresses the most important risks across cloud infrastructure, corporate systems, identity and access, endpoints, applications, data, and third-party services
  • Set the expectations for Security Operations across threat intelligence, vulnerability management, security monitoring, incident readiness, risk assessment and project design reviews, fraud support, AI security, and associated SLA and KPI tracking
  • Ensure IT Operations and IT Support provide a reliable, scalable, and high-quality experience for Back Makers across our global offices and remote workforce
  • Champion automation, standardization, and engineering-led approaches that reduce manual work and improve reliability, while leaving day-to-day technical ownership with the appropriate functional teams

 

Build security culture and external credibility

  • Foster a security-aware culture through clear communication about the evolving threat landscape, key initiatives, practical expectations, and the role every Back Maker plays in protecting the company
  • Sponsor awareness, education, and Security Champion programs that make secure behavior accessible and relevant to different audiences
  • Represent Back Market in relevant security communities, industry groups, partner forums, and regulatory conversations
  • Build trusted relationships with strategic technology partners, auditors, insurers, and external security providers
  • Help Back Market demonstrate that strong security, responsible technology, and business agility reinforce one another

You could be a good fit if you've:

  • A proven track record of building, scaling, and developing organizations that span multiple security and/or IT domains
  • 12 to 15+ years of experience across cybersecurity, information security, IT, or related technology leadership roles, including at least 5 years leading managers and multi-team organizations
  • Experience operating as a strategic partner to a CTO, VP Engineering, executive committee, or equivalent senior leadership group
  • Proven expertise and a solid grasp of the domains listed below: security operations, cyber risk and governance, compliance and assurance, security architecture, product security, cloud security, IT operations, or corporate technology
  • Demonstrated ability to turn business strategy and risk appetite into a practical security and IT roadmap, investment plan, and operating model
  • Experience communicating security and technology risk to executive, board-level, investor, partner, audit, and non-technical audiences
  • A mature, risk-based approach. You understand that perfect security does not exist, and that good leadership means making explicit, informed trade-offs and focusing resources where they have the greatest impact
  • Experience leading through managers and senior experts, with a genuine passion for developing people, building leadership capability, and creating meaningful career paths
  • Strong understanding of modern cloud, SaaS, identity, endpoint, application, data, and infrastructure security concepts, even if you are not the deepest technical expert in every domain
  • Experience with security-by-design, secure software development lifecycle practices, and effective partnership with Engineering and Product teams
  • Excellent written and verbal communication in English, with the ability to make complex topics clear, concrete, and compelling. French is a plus
  • The judgment, calm, and influence required to operate effectively in ambiguity, during incidents, and across competing stakeholder priorities
  • Genuine excitement about Back Market's mission and the belief that cybersecurity and IT are essential enablers of sustainable growth

Nice to have

  • A recognized certification such as CISSP, CISM, CISA, CRISC, CCSP, or an equivalent professional qualification
  • Experience with ISO 27001, PCI DSS, GDPR, NIS2, or other relevant European regulatory and assurance frameworks
  • Experience with GCP, Kubernetes, Terraform, modern cloud-native security tooling, or SaaS-first environments
  • Experience in marketplace, e-commerce, fintech, or another business with meaningful customer, partner, or regulatory trust requirements
  • Experience with AI security, fraud prevention, third-party risk, or software supply chain security
  • Experience working in a fast-growing, international organization with distributed

Hiring process

  • Phone call with Marie, Technical Talent Acquisition Partner - 45 min
  • Deep-dive interview on cybersecurity and IT strategy with your future manager, the VP of Engineering - 60 min
  • Leadership and management interview with a peer Engineering Director and an Engineering Manager - 60 min
  • Meet your future team - 45 min
  • Stakeholder interview with cross-functional partners, including the CTO and relevant Security and IT leaders - 60 min
  • Cultural and Values interview with a C-level leader from Back Market - 45 min

WHY SHOULD YOU JOIN US ? ✌🏼

At Back Market, we’re committed to hiring and supporting diverse teams of people from all backgrounds, experiences, and perspectives — it’s one of the reasons we’re such a high-scoring certified B Corp company (93.2).

No matter your role and seniority level, you’ll enjoy impact-driven work with hands-on career development in an innovative, driven, and fast-paced environment — with benefits to match, like:

- A mission driven work environment where your day to day makes an impact on the planet. Seriously.

- Hybrid work environment, with 2 remote days a week and 1 remote work week per quarter, plus 3 flex days.

- Employee Resource Groups, including mentorship programs, comprehensive accessibility policies, and cultural competency training.

At Back Market, we strive to create a workplace that embodies the world we’re trying to change. We’ve embedded our diversity, equity, and inclusion principles into our DNA — from dedicated staff to employee resource groups to our company values.

We know that the perfect background for a role doesn’t mean the perfect fit — we encourage you to apply for a role even if you think you may not have all the qualifications.

If reasonable accommodations are needed for the interview process, please do not hesitate to discuss this with the Talent Acquisition Team.

Similar roles