About this Associate Director, Cybersecurity, Privacy & IT role at Dr. Squatch
Why We Exist and What We Do:
At Dr. Squatch (www.drsquatch.com), we’re raising the bar on men’s personal care with our line of natural, high-performance products. We’re on a high-growth, fast-moving ride, continually introducing new product categories, launching into retailers nationwide, and growing internationally. We have been recognized and certified by Great Place to Work® multiple times, and we achieved status as a certified B Corp in 2023. We are looking for passionate, talented people who want to join us in our mission to inspire and educate men to be happier and healthier!
About the Role:
Dr. Squatch is looking for an Associate Director of Cybersecurity, Privacy & IT to lead three connected functions: our security program, our privacy compliance program, and the internal technology our employees use every day. You'll own the strategy, and the team for all three.
As part of Unilever, we now operate against a global control framework, and a meaningful share of this role is integration work: mapping our controls to enterprise standards, participating in assessment and reporting cycles, aligning identity, endpoint, and third-party risk practices, and translating between a global program and a business that still runs at startup speed. Doing that well, protecting the company without slowing it down, is the core challenge of the job.
This role will also continue to drive the security strategy and represent Dr. Squatch in enterprise-level security and privacy governance. You'll sit on the Technology leadership team alongside data engineering, analytics, and business systems, partner closely with eCommerce, marketing, and legal, and present directly to our executive team on risk, incidents, and investment decisions.
This role reports to the Sr. Director, Data & Technology.
This is a full-time, hybrid role based in Marina Del Rey, CA.
The anticipated base compensation range for this role will be $190,000 to $215,000. Compensation will be commensurate with the candidate's experience and local market rates.
What You'll Do:
- Cybersecurity program
- Maintain the cybersecurity risk register: identify risks to our data and systems, assess likelihood and impact, and prioritize what gets addressed first.
- Own the multi-year security roadmap.
- Evaluate, select, implement, and operate security tooling across endpoint, email, identity, cloud, and application layers.
- Monitor and triage vulnerabilities and emerging threats; drive remediation to completion with the teams that own the systems.
- Manage our MDR and incident response partners, and own the incident response plan, including tabletop exercises and post-incident reviews.
- Run security awareness training and phishing simulation for employees and contractors.
- IT and identity
- Lead the IT function and manage the IT Manager by setting priorities and service expectations, and actively developing them toward broader ownership of IT operations over time.
- Own identity and access management end to end via SSO, MFA, provisioning and deprovisioning, and periodic access reviews across our SaaS estate.
- Own endpoint management and device lifecycle, from procurement through secure decommissioning.
- Set the standard for IT support responsiveness and make sure onboarding and offboarding are fast, complete, and auditable.
- Own SaaS governance: what tools we use, who approves them, how they're reviewed for security, and what happens to the data in them.
- Privacy and data protection
- Own our privacy compliance program across CCPA/CPRA, other US state privacy laws, and UK and EU GDPR.
- Run consumer rights request intake and fulfillment with Customer Support, and keep the process defensible as volume grows.
- Maintain data mapping, records of processing, retention schedules, and privacy notices; partner with Legal and outside counsel on assessments and filings.
- Advise Marketing and eComm on consent management, cookies, pixels, and data sharing with ad and analytics partners.
- Own third-party and vendor risk review, including DPAs and security assessments for new tools.
- Enterprise integration and governance
- Serve as our point of contact for Unilever security, privacy, and IT governance workstreams.
- Map our controls to enterprise standards, close identified gaps, and manage the reporting and assessment cadence.
- Lead our part of systems and identity integration projects, negotiating sequencing and exceptions where a global standard doesn't fit a DTC business.
- Prepare Dr. Squatch for audits and control testing, and own the evidence.
- AI governance
- Own acceptable use, data handling, and review standards for AI tools across the company.
- Assess AI vendors for security and privacy risk before adoption, and keep an inventory of what's in use and what data it touches.
- Partner with the Data team so governance enables adoption rather than blocking it.
About You:
- 8–12 years across cybersecurity, IT, and/or privacy, including end-to-end ownership of a security program rather than a single function within one.
- Demonstrated experience applying a security and risk framework, such as NIST CSF, CIS Controls, ISO 27001, or SOC 2, in a real environment, not just on paper.
- Hands-on depth in a cloud-first, SaaS-first stack: identity (Okta or equivalent), endpoint management, email security, logging and detection.
- Working knowledge of CCPA/CPRA and GDPR, and experience operationalizing them, not only interpreting them.
- Direct people management experience, including developing a more junior manager or engineer into greater scope. You'll inherit a capable IT Manager whose growth is part of your job.
- Judgment about where to spend limited resources, and the communication skills to explain that tradeoff to executives in business terms, and to hold the line when the answer is no.
- Comfort taking a vague problem and turning it into a specific, sequenced plan.
- You get things done without perfect resources, and you act with urgency.
- You play to win. You hold high standards, take ownership, and stay invested in the outcome.
- Team first. You're humble, you help outside your own wheelhouse, and you're good to work with when something is on fire.
- You can hold a security line and stay a partner to the business at the same time.
Nice to Have:
- Experience at a company operating inside a larger parent organization, or through an acquisition integration.
- Ecommerce or DTC background, and familiarity with Shopify, ad platform data flows, and consumer data at scale.
- CISSP, CISM, CIPP/US, or CIPP/E.
#LI-TC1 #LI-FULLTIME #LI-HYBRID
Who We Are:
Our core values come naturally and make us a better, more whole, and unique team. We are Bold & Innovative - we are creative, rethink how things are done, and find a way. We Play to Win - we have high standards, we encourage ownership of work, we are scrappy, we act with urgency, and we invest in the outcome of our work. We are Team Squatch - we are humble, help others outside our own wheelhouse, stay positive, have fun, and have approachable and transparent leadership.
We offer a competitive salary in a growth-focused & collaborative team environment. Benefits include medical, dental, vision, 401k with Squatch match, and PTO. We also have great perks like healthy snacks, frequent company events, and of course, free products!
For Applicants with Disabilities. Reasonable accommodation will be made so that qualified applicants with disabilities may participate in the application process. If you need any accommodations during the hiring process, please let us know when you submit your application and we'll do our very best to adjust as needed.
For Information regarding Data Privacy, please review https://privacy.drsquatch.com/.
Unsolicited Resume Policy. Dr. Squatch (“DRSQ”) employs an internal Talent Acquisition department. Exceptionally, DRSQ may choose to supplement that internal team with support from temporary staffing agencies, placement services, and/or recruiting agencies ("Agency"). Agencies are hereby specifically directed NOT to contact DRSQ employees directly in an attempt to present candidates. DRSQ’s Talent Acquisition team is responsible for all candidate presentations to our hiring managers.
To protect the interests of all parties, Dr. Squatch will not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to DRSQ, including unsolicited resumes sent to a DRSQ email address or mailing address, directly to DRSQ employees, or to DRSQ’s resume database will be considered property of Dr. Squatch.
DRSQ will not pay a placement, service or other fee for any placement resulting from the receipt of an unsolicited resume. This also includes partial resumes, LinkedIn profiles, general candidate profiles, and/or candidate details or information. DRSQ will consider any candidate for whom an Agency has submitted an unsolicited resume to have been referred by the Agency free of any charges or fees.
DRSQ’s Talent Acquisition team must provide advance written approval to an Agency to submit resumes and/or profiles for a specific job-opening, and the approval must be in conjunction with a valid fully executed staffing, placement or other service agreement. DRSQ will not pay a fee to any Agency that does not have a fully executed agreement in place prior to submission, receipt and placement of candidates.