Jobs and Careers
RE

Senior Director of Information Security

Rent the Runway
United Statesfull_timeVerifiedPosted 6 Jun 2025
💰 $240,000/yr($184,000/yr$240,000/yr)

About the role

About Us:

Rent the Runway (RTR)  is transforming the way we get dressed by pioneering the world’s first Closet in the Cloud. Founded in 2009, RTR has disrupted the $2.4 trillion fashion industry by inspiring women with a more joyful, sustainable and financially-savvy way to feel their best every day. As the ultimate destination for circular fashion, the brand now offers infinite points of access to its shared closet via a fully customizable subscription to fashion, one-time rental or ownership. RTR offers designer apparel and accessories from hundreds of brand partners and has built in-house proprietary technology and a one-of-a-kind reverse logistics operation. Under CEO and Co-Founder Jennifer Hyman’s leadership, RTR has been named to CNBC’s “Disruptor 50” five times in ten years, and has been placed on Fast Company’s Most Innovative Companies list multiple times, while Hyman herself has been named to the “TIME 100” most influential people in the world and as one of People magazine’s “Women Changing the World.”

About the Job:

RTR is seeking a highly motivated and experienced Senior Director of Information Security to lead our information security program, protecting both corporate and customer assets. This role is crucial in establishing and maintaining a robust security posture, adhering to NIST best practices, and ensuring compliance with relevant regulations. The Director will oversee all Information Security efforts including Governance, Risk, and Compliance (GRC), Fraud Prevention, and Privacy compliance initiatives, playing a key role in safeguarding our data and maintaining customer trust.

You will report to the VP, CISO and work collaboratively with the other members of RTR’s teams. You will work from Rent the Runway’s Brooklyn headquarters Monday - Thursday.

What You’ll Do:

  • Strategic Leadership: Develop, implement, and maintain a comprehensive information security strategy aligned with RTR's business objectives, risk tolerance, and industry best practices.
  • NIST Framework Implementation: Direct the implementation and ongoing management of the NIST Cybersecurity Framework, ensuring that security controls and processes are effectively applied and continuously improved.
  • Governance, Risk, and Compliance (GRC):
    • Establish and maintain a robust GRC program, including the development and enforcement of security policies, standards, and procedures.
    • Oversee risk assessments, vulnerability management, and security audits to identify and mitigate potential threats and ensure compliance with internal and external requirements.
    • Manage security and privacy awareness training programs to promote a security- and privacy-conscious culture.
  • Fraud Prevention: Develop and implement effective strategies, systems, and controls to prevent, detect, and respond to fraudulent e-commerce activities, protecting RTR's assets and customers.
  • PCI-DSS Compliance: Oversee Payment Card Industry Data Security Standard (PCI-DSS) compliance to ensure secure handling of payment card information.
  • Privacy Compliance: Build and manage technical and operational aspects of RTR’s privacy compliance program; partner with Legal and other teams to establish policies and procedures to safeguard personal data; partner with Product, Engineering, and Marketing teams to implement privacy by design principles. 
  • Incident Response: Lead the development, implementation, and execution of the incident response plan, including the investigation, containment, and remediation of security incidents.
  • Security Architecture: Collaborate with IT and engineering teams to integrate security best practices into the design, development, and deployment of systems and applications.
  • Application Security: Drive the implementation of secure software development lifecycle (SSDLC) practices and conduct regular application security assessments (e.g., SAST, DAST, penetration testing).
  • Cloud Datacenter Security: Oversee the security of cloud environments and datacenter infrastructure, ensuring robust controls, configurations, and monitoring are in place.
  • Vendor Security: Manage third-party vendor security risks by establishing and enforcing security requirements, conducting assessments, and monitoring compliance.
  • Team Management: Build, mentor, and lead a high-performing information security team, fostering a collaborative and results-oriented environment.
  • Communication and Reporting: Provide regular updates to senior management on the organization's security posture, risks, and compliance efforts.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Rent the Runway

View company profile →