Director of Cybersecurity & IT

Backmarket · via Arbeitnow ·

TypeFull-time job
LocationParis
Posted2 hours ago
Hi, we’re Back Market.
We’re here to help make tech reliable, affordable, and better than new. We're a global marketplace for refurbished devices, helping lower our collective environmental impact by providing trustworthy, affordable tech with 92% less carbon emissions than new.
Yep, you read that right. Turns out refurbished tech is way better for the planet than new. In fact, With every device purchased on Back Market, our positive impact on the planet grows. From our Customer Care representatives to our software engineer, every individual at Back Market cuts the planet — and consumers — a break. Our mission is simple: to do more with what we already have.
Are you ready to join us?
Back Market is looking for a Director of Cybersecurity & IT to define and lead the next phase of our security and technology operations maturity. Reporting to the VP of Platform Engineering, you will be a strategic leader at the intersection of cybersecurity, IT, risk, compliance, and business growth.
You will lead a multi-disciplinary organization through its existing functional managers, creating the clarity, operating rhythm, and investment focus needed to protect Back Market while enabling the company to move quickly. The scope includes cybersecurity strategy and risk management, security operations, governance and compliance, IT operations, IT support, and the corporate technology foundations that keep our people productive and our business resilient.
 
This is a director-level role, not a super-sized operational manager role. You will not be expected to personally own every process or make every technical decision. Your impact will come from setting direction, developing leaders, aligning stakeholders, making sound investment choices, and ensuring that the organization delivers measurable outcomes. You will be the senior voice who makes cybersecurity and IT understandable, actionable, and connected to the business.
 
To know more about our engineering teams:
A video of our VP Platform: https://youtu.be/zvTlw4BNNdc

Our company purpose: http://bit.ly/3OsScpl

Our engineering blog: https://bit.ly/3ASJNID

How we work with the existing teams 💚
 
The Director sets direction, creates clarity, secures resources, removes organizational obstacles, develops leaders, and ensures that the overall portfolio delivers against agreed outcomes. The functional managers and senior experts retain ownership of day-to-day execution, technical practices, operational processes, and delivery within their domains. The Director creates the conditions for those leaders to succeed and makes sure their work adds up to a coherent company-wide strategy.

Your next missions 👇
 
Set the strategy, roadmap, and investment priorities
Define and evolve a multi-year Cybersecurity & IT strategy aligned with Back Market's business goals, risk appetite, technology strategy, and growth plans

Translate that strategy into a focused portfolio of initiatives, with clear outcomes, sequencing, ownership, dependencies, and measures of success

Own the operating rhythm for the full scope: planning, budgeting, program tracking, KPI and SLA reporting, risk reviews, and executive communication

Make pragmatic investment and prioritization recommendations, balancing resilience, customer trust, regulatory expectations, employee experience, and engineering velocity

Establish the governance forums and decision mechanisms needed to keep priorities clear and accountability visible

 
Lead and grow a high-performing leadership organization
Lead through the managers and senior individual contributors responsible for Security Operations, Governance Risk & Compliance, IT Operations Engineering, IT Support, and relevant security engineering or product security capabilities

Coach, challenge, and develop your leaders, helping them grow their scope, judgment, influence, and ability to build strong teams of their own

Create clear career paths, succession plans, and development opportunities across the organization

Build a high-trust environment where teams have genuine ownership, collaborate across boundaries, and are encouraged to improve how work gets done

Attract and retain exceptional talent, define what great leadership and execution look like, and continuously raise the bar without creating unnecessary bureaucracy

Ensure that responsibilities, decision rights, and interfaces between the teams are explicit, understood, and respected

 
Turn cybersecurity into a business enabler
Act as a trusted advisor to the VP of Engineering, CTO, Executive Committee, and senior leaders across the business

Explain complex security, IT, and risk topics in clear business language, including the trade-offs, options, costs, and consequences of different decisions

Engage with Heads of and cross-functional streams across Back Market to advocate for security and resilience in all areas of the business

Build alignment rather than relying on authority, and help teams adopt secure and resilient ways of working because they understand the rationale and value

Partner with Finance and senior technology leadership on investment cases, budget stewardship, vendor strategy, and the value delivered by the portfolio

 
Steer enterprise cyber risk and trust
Own the cyber risk management process at the strategic level, using the GRC framework as the foundation for security decisions and prioritization

Ensure that material risks, control gaps, exceptions, and remediation plans are visible, understood, and actively managed

Escalate critical risks when they exceed the organization's risk appetite or require executive arbitration

Support security compliance efforts across the organization, ensuring alignment and buy-in from peers and key stakeholders across ISO 27001, PCI DSS, GDPR, NIS2, and contractual partner requirements

Partner with the VP Legal and DPO on the company's data privacy strategy, ensuring privacy and security requirements are considered early in business, product, and technology decisions

Represent Back Market's security maturity and risk posture to investors, auditors, regulators, strategic partners, and major customers

Serve as the senior escalation point for major or complex security incidents, ensuring the right executive communication, decision-making, learning, and follow-through without displacing the operational ownership of the incident response teams

 
Enable secure products and resilient technology
Partner with Engineering, Product, and other Bureau of Technology directors to ensure security requirements are integrated into product and feature development from the beginning

Sponsor and evolve Product Security and secure software development lifecycle practices, including security-by-design, threat modeling, appropriate testing, and pragmatic guardrails

Ensure the security roadmap addresses the most important risks across cloud infrastructure, corporate systems, identity and access, endpoints, applications, data, and third-party services

Set the expectations for Security Operations across threat intelligence, vulnerability management, security monitoring, incident readiness, risk assessment and project design reviews, fraud support, AI security, and associated SLA and KPI tracking

Ensure IT Operations and IT Support provide a reliable, scalable, and high-quality experience for Back Makers across our global offices and remote workforce

Champion automation, standardization, and engineering-led approaches that reduce manual work and improve reliability, while leaving day-to-day technical ownership with the appropriate functional teams

 
Build security culture and external credibility
Foster a security-aware culture through clear communication about the evolving threat landscape, key initiatives, practical expectations, and the role every Back Maker plays in protecting the company

Sponsor awareness, education, and Security Champion programs that make secure behavior accessible and relevant to different audiences

Represent Back Market in relevant security communities, industry groups, partner forums, and regulatory conversations

Build trusted relationships with strategic technology partners, auditors, insurers, and external security providers

Help Back Market demonstrate that strong security, responsible technology, and business agility reinforce one another

You could be a good fit if you've:
A proven track record of building, scaling, and developing organizations that span multiple security and/or IT domains

12 to 15+ years of experience across cybersecurity, information security, IT, or related technology leadership roles, including at least 5 years leading managers and multi-team organizations

Experience operating as a strategic partner to a CTO, VP Engineering, executive committee, or equivalent senior leadership group

Proven expertise and a solid grasp of the domains listed below: security operations, cyber risk and governance, compliance and assurance, security architecture, product security, cloud security, IT operations, or corporate technology

Demonstrated ability to turn business strategy and risk appetite into a practical security and IT roadmap, investment plan, and operating model

Experience communicating security and technology risk to executive, board-level, investor, partner, audit, and non-technical audiences

A mature, risk-based approach. You understand that perfect security does not exist, and that good leadership means making explicit, informed trade-offs and focusing resources where they have the greatest impact

Experience leading through managers and senior experts, with a genuine passion for developing people, building leadership capability, and creating meaningful career paths

Strong understanding of modern cloud, SaaS, identity, endpoint, application, data, and infrastructure security concepts, even if you are not the deepest technical expert in every domain

Experience with security-by-design, secure software development lifecycle practices, and effective partnership with Engineering and Product teams

Excellent written and verbal communication in English, with the ability to make complex topics clear, concrete, and compelling. French is a plus

The judgment, calm, and influence required to operate effectively in ambiguity, during incidents, and across competing stakeholder priorities

Genuine excitement about Back Market's mission and the belief that cybersecurity and IT are essential enablers of sustainable growth

Nice to have

A recognized certification such as CISSP, CISM, CISA, CRISC, CCSP, or an equivalent professional qualification

Experience with ISO 27001, PCI DSS, GDPR, NIS2, or other relevant European regulatory and assurance frameworks

Experience with GCP, Kubernetes, Terraform, modern cloud-native security tooling, or SaaS-first environments

Experience in marketplace, e-commerce, fintech, or another business with meaningful customer, partner, or regulatory trust requirements

Experience with AI security, fraud prevention, third-party risk, or software supply chain security

Experience working in a fast-growing, international organization with distributed

Hiring process
Phone call with Marie, Technical Talent Acquisition Partner - 45 min

Deep-dive interview on cybersecurity and IT strategy with your future manager, the VP of Engineering - 60 min

Leadership and management interview with a peer Engineering Director and an Engineering Manager - 60 min

Meet your future team - 45 min

Stakeholder interview with cross-functional partners, including the CTO and relevant Security and IT leaders - 60 min

Cultural and Values interview with a C-level leader from Back Market - 45 min

WHY SHOULD YOU JOIN US ? ✌🏼
At Back Market, we’re committed to hiring and supporting diverse teams of people from all backgrounds, experiences, and perspectives — it’s one of the reasons we’re such a high-scoring certified B Corp company (93.2).
No matter your role and seniority level, you’ll enjoy impact-driven work with hands-on career development in an innovative, driven, and fast-paced environment — with benefits to match, like:
- A mission driven work environment where your day to day makes an impact on the planet. Seriously.
- Hybrid work environment, with 2 remote days a week and 1 remote work week per quarter, plus 3 flex days.
- Employee Resource Groups, including mentorship programs, comprehensive accessibility policies, and cultural competency training.
At Back Market, we strive to create a workplace that embodies the world we’re trying to change. We’ve embedded our diversity, equity, and inclusion principles into our DNA — from dedicated staff to employee resource groups to our company values.
We know that the perfect background for a role doesn’t mean the perfect fit — we encourage you to apply for a role even if you think you may not have all the qualifications.
If reasonable accommodations are needed for the interview process, please do not hesitate to discuss this with the Talent Acquisition Team.
Find Jobs in France on Arbeitnow
bureau of technology
Apply on Arbeitnow →

Job sourced from Arbeitnow. Applications happen directly on the original platform — we never collect your data.