Zip
Head of InfoSec and IT Ops
Part remote, part office, you need to live within commuting distance of a named location.
Hybrid · San Francisco
Employer listed it 5 weeks ago · Found 6h ago
Been open since 5 weeks ago, still being checked, but it has been live a while.
Salary
Not stated
Location
Hybrid · San Francisco
Timezone
Not stated
Contract
Full-time
Experience
Lead
Category
Software
This employer didn't state pay. Jobs like this usually pay around $200k–$275k a year, a typical range taken from 597 lead-level software roles on Nomaders that do state pay. It's a guide, not an offer.
Remote flexibility
Hybrid
This role is only partly remote, the employer expects time in the office around San Francisco, Hybrid, so you need to live within commuting distance.
What the employer says
- Source listing states candidate location: "San Francisco, Hybrid"
- Listing mentions "Hybrid"
What Nomaders makes of it
- Not suitable if you plan to move between countries
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
About Zip
Zip is the AI platform for enterprise procurement — built for humans and agents working together. By orchestrating procurement across teams, tools, and suppliers with the help of AI agents, companies can secure the resources they need to innovate faster than ever before. The world’s most influential enterprises trust Zip, including T-Mobile, OpenAI, AMD, Mars, Dollar Tree, and more. Together they’ve saved over $8 billion and processed over $500 billion in spend. Zip’s team includes product leaders from Apple, Airbnb, and Meta, as well as former procurement leaders from United Health, Sanofi, MGM Resorts, Discover, and NASA. Backed by Adams Street, Alkeon, BOND, CRV, DST, Tiger Global, and Y Combinator, Zip has raised $371 million, most recently at a $2.2 billion valuation and has been recognized by Forbes Fintech 50, Fast Company's Most Innovative Companies, Inc. Best in Business, and LinkedIn Top Startups.
Your Role
You will build and lead the enterprise security and IT operations system for Zip at a pivotal stage of scale. Zip operates a mission-critical enterprise SaaS platform, is rapidly expanding operations globally, and is building the governance and controls required for its next phase.
You will own a practical, engineering-oriented program spanning enterprise security governance, corporate security, detection and incident response, compliance and customer trust, and reliable employee technology. You will partner closely with Product and Engineering leaders responsible for the platform, and with Business Technology and Internal AI leaders building the systems and automations that run Zip.
Your first mandate is to make accountability unambiguous: understand the current program, agree boundaries with existing product/infrastructure security leadership, stabilize IT operations, and turn fragmented risks and services into one measurable operating model. You will lead by doing, while hiring and developing the team.
What you'll do
Own the enterprise security program. Establish strategy, risk appetite, policies, control framework, roadmap, metrics, executive reporting, and decision rights.
Clarify and operate the product/corporate boundary. Partner with Product Security to define who owns application security, cloud/production security, identity engineering, vulnerability management, detection/response, customer trust, and remediation.
Lead IT Operations and Engineering. Build a high-quality global service model across support, identity, endpoint, SaaS, collaboration, office/network, automation, asset lifecycle, and resilience. Separate frontline support from systems engineering and drive secure self-service.
Build detection and response. Define priority threats and crown jewels, improve telemetry and detection coverage, establish 24/7 response, run incidents and exercises, and ensure corrective actions prevent recurrence.
Own GRC, assurance, and customer trust. Maintain and streamline processes for SOC 1, SOC 2, ISO 27001, and IS 42001, prepare for future SOX/public-company controls, manage audits and findings, and enable fast, accurate customer security responses.
Secure AI and internal tools. Partner with internal teams to define the risk tolerance, framework, and infrastructure to securely deploy AI and business apps built in-house.
Drive EIAM and data protection. Mature joiner/mover/leaver, privileged access, service identities, access reviews, data classification, DLP, encryption/key management, retention/deletion, and sensitive-data controls.
Manage third-party and resilience risk. Mature TPRM by risk-tiering vendors, ensuring contractual and operational controls, defining service criticality/RTO/RPO, and maintaining crisis readiness.
Build the team and culture. Assess roles and capability gaps, hire selectively, develop leaders, create security/IT champions, and make the safe path the easy path.
What we're looking for
12+ years across information security, security engineering, IT engineering/operations, risk, or related disciplines, including 5+ years leading teams in a high-growth B2B SaaS company.
Experience owning a broad enterprise security program and partnering deeply with Product/Engineering; credible across both corporate and product risk.
Demonstrated leadership of major incidents, detection/response, vulnerability management, identity, endpoint/SaaS, cloud and secure SDLC programs.
Practical experience with SOC 1/2, ISO 27001, privacy obligations, customer assurance, and audit remediation. SOX/public-company and ISO 42001 experience are valuable.
Strong technical judgment: can review architecture, challenge IAM and cloud decisions, understand application/data flows, and distinguish control evidence from real risk reduction.
History of scaling IT service delivery and systems engineering through automation, self-service, clear SLOs, and excellent employee experience.
Ability to create clear decision rights in a federated environment and influence executives and engineering leaders without relying on hierarchy.
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
No benefits package published with this listing. Ask about it at first interview.
How to apply
- 1Check the flexibility label above, hybrid, matches where you plan to live and work.
- 2Tailor your CV to the role at Zip, mentioning your remote working experience.
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 6h ago. Last checked today. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
Typically $200k to $275k per year · You'll be taken to the employer's careers page.