Skip to content
← Back to job listings

VP, Chief Information Security Officer

Commerce.com US, Inc. · Austin, TX, United States

CybersecurityExternal listingfull-timeabout 1 hour ago

About The Role

Welcome to the Agentic Commerce Era

At Commerce, our mission is to empower businesses to innovate, grow, and thrive with our open, AI-driven commerce ecosystem. As the parent company of BigCommerce , Feedonomics , and Makeswift , we connect the tools and systems that power growth, enabling businesses to unlock the full potential of their data, deliver seamless and personalized experiences across every channel, and adapt swiftly to an ever-changing market. We believe in harnessing AI responsibly to unlock new possibilities, and we’re looking for individuals who use it intentionally to solve problems, accelerate outcomes, and expand what’s possible in their role. Our purpose is to help businesses confidently solve complex commerce challenges so they can build smarter, adapt faster, and grow on their own terms. If you want to be part of a team of bold builders, sharp thinkers, and technical trailblazers who shape the future of commerce, this is the place for you.

As VP, Chief Information Security Officer , you will be responsible for Commerce’s overall information security, compliance, and cyber risk program across our SaaS platform, product offerings, and corporate systems. You will lead a talented team of information security, governance, risk, and compliance professionals based in multiple locations, working closely with teams across the company to build and scale a world class information security and compliance program. You will interact directly with security teams within our merchant, prospective customer, and partner communities to collaborate on solutions to shared trust, risk, and security challenges.

The right candidate will be a collaborative and forward thinking technology leader with a strong point of view on security in a complex, advanced SaaS environment. Speaking with partners, customers, executives, and board members with comfort and clarity is as important to success as developing a strong roadmap for platform, product, corporate, and compliance security.

What You’ll Do

  • Define and lead Commerce’s cybersecurity and GRC strategy, including policies, standards, and programs that protect corporate and customer digital assets, reduce business risk, and support effective governance and compliance
  • Oversee security investigations and incident response, including impact analysis, executive updates, post incident recommendations, and plans to avoid similar issues in the future
  • Direct and approve the design of security systems, identity and access policies, and GRC procedures that support a secure, scalable SaaS environment
  • Maintain a current understanding of the cyber threat landscape, including relevant risks to SaaS platforms, cloud environments, ecommerce, and the broader technology industry
  • Translate threat, regulatory, and customer requirements into actionable plans that protect the business and support growth
  • Ensure compliance with applicable laws, regulations, customer commitments, and industry frameworks
  • Schedule and oversee periodic security audits, compliance assessments, certifications, and customer assurance activities
  • Oversee identity and access management, third party risk management, vulnerability management, secure configuration practices, and security awareness programs
  • Ensure cybersecurity and GRC policies and procedures are communicated clearly to employees and that compliance expectations are understood and enforced.
  • Oversee teams, employees, contractors, and vendors involved in cybersecurity and GRC, including hiring, performance management, mentoring, and team development
  • Continuously update the cybersecurity and GRC strategy to incorporate new technology, evolving threats, customer expectations, and business priorities.
  • Brief the executive team and board on security posture, key risks, incidents, program maturity, and investment priorities
  • Communicate security best practices and business relevant risks across the company, beyond security and IT, to strengthen shared ownership of security

Who You Are

  • Proven background leading information security within SaaS or platform oriented global companies
  • Strong understanding of current and emerging technologies for security in a cloud based, microservices based environment
  • Expansive experience with compliance frameworks such as SOX, PCI, GDPR, CCPA, SOC 2, and ISO 27001, and their application as both a service provider and a customer
  • Familiarity and comfort with modern DevOps processes as well as distributed cloud environments such as GCP and AWS
  • Experience partnering with Product, Engineering, Legal, Privacy, Sales, IT, and executive leadership to align security priorities with business objectives
  • Ability to communicate cyber risk, security posture, and investment tradeoffs clearly to executives, board members, customers, auditors, and technical teams
  • History of building and growing collaborative security and compliance teams that cross functional teams value working with
  • Experience with corporate cybersecurity in a distributed, cloud first environment

Work Where You Thrive

For candidates based in the Austin or Atlanta metro area, the position follows a hybrid work model with three days per week in the office, balancing focused individual work with meaningful in-person collaboration.

#LI-REMOTE

#LI-GC1

(Pay Transparency Range: $240,000.00 - $305,000.00)

Compensation Transparency

The national base salary range for this role is posted above in this job post.

Final compensation will be determined based on factors such as relevant experience, skills, qualifications and geographic location. We also consider internal equity to help ensure fair and consistent pay practices across our teams.

Where applicable, this role may also be eligible for variable compensation (such as bonus or commission), equity, and benefits in accordance with local policies. Details will be shared during the hiring process. We are committed to equitable and transparent pay practices that align to market data, internal equity, and individual contribution.

Inclusion and Belonging

At Commerce, we believe that celebrating the unique histories, perspectives and abilities of every employee makes a difference for our company, our customers and our community. We are an equal opportunity employer and the inclusive atmosphere we build together will make room for every person to contribute, grow and thrive.

We are committed to creating an inclusive and accessible hiring experience for all candidates. If you require accommodations or adjustments at any stage of the recruitment process, please let us know and we will work with you to meet your needs.

Learn more about the Commerce team, culture and benefits at https://www.commerce.com/careers/

Protect Yourself Against Hiring Scams: Our Corporate Disclaimer

Commerce, along with many other employers, has become the subject of fraudulent job offers to hopeful prospective job seekers.

Be advised

Commerce does not offer jobs to individuals who do not go through our formal hiring process.

Commerce will never

  • require payment of recruitment fees from candidates;
  • request personally identifiable information through unsanctioned websites or applications;
  • attempt to solicit money from you as part of the hiring process or as part of an employment offer;
  • solicit money to complete visa requirements as part of a job offer.

If you receive unsolicited offers of employment from Commerce, we urge you to be extremely cautious and avoid engaging or responding.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing