About the Role
Zip is seeking an individual to build and lead the enterprise security and IT operations system at a pivotal stage of scale. This role involves owning a practical, engineering-oriented program spanning enterprise security governance, corporate security, detection and incident response, compliance and customer trust, and reliable employee technology. You will partner closely with Product and Engineering leaders, as well as Business Technology and Internal AI leaders.
Responsibilities
- Own the enterprise security program, establishing strategy, risk appetite, policies, control framework, roadmap, metrics, executive reporting, and decision rights.
- Clarify and operate the product/corporate boundary, partnering with Product Security to define ownership of application security, cloud/production security, identity engineering, vulnerability management, detection/response, customer trust, and remediation.
- Lead IT Operations and Engineering, building a high-quality global service model across support, identity, endpoint, SaaS, collaboration, office/network, automation, asset lifecycle, and resilience.
- Build detection and response capabilities, defining priority threats, improving telemetry and detection coverage, establishing 24/7 response, running incidents and exercises, and ensuring corrective actions prevent recurrence.
- Own GRC, assurance, and customer trust, maintaining and streamlining processes for SOC 1, SOC 2, ISO 27001, and IS 42001, preparing for future SOX/public-company controls, managing audits and findings, and enabling fast, accurate customer security responses.
- Secure AI and internal tools by partnering with internal teams to define risk tolerance, framework, and infrastructure for securely deploying AI and business apps.
- Drive EIAM and data protection by maturing joiner/mover/leaver processes, privileged access, service identities, access reviews, data classification, DLP, encryption/key management, retention/deletion, and sensitive-data controls.
- Manage third-party and resilience risk by maturing TPRM, defining service criticality/RTO/RPO, and maintaining crisis readiness.
- Build the team and culture by assessing roles and capability gaps, hiring selectively, developing leaders, creating security/IT champions, and making the safe path the easy path.
Requirements
- 12+ years across information security, security engineering, IT engineering/operations, risk, or related disciplines.
- 5+ years leading teams in a high-growth B2B SaaS company.
- Experience owning a broad enterprise security program and partnering deeply with Product/Engineering.
- Credibility across both corporate and product risk.
- Demonstrated leadership of major incidents, detection/response, vulnerability management, identity, endpoint/SaaS, cloud and secure SDLC programs.
- Practical experience with SOC 1/2, ISO 27001, privacy obligations, customer assurance, and audit remediation.
- Strong technical judgment to review architecture, challenge IAM and cloud decisions, understand application/data flows, and distinguish control evidence from real risk reduction.
- History of scaling IT service delivery and systems engineering through automation, self-service, clear SLOs, and excellent employee experience.
- Ability to create clear decision rights in a federated environment and influence executives and engineering leaders without relying on hierarchy.
- Excellent written and incident communication; calm under pressure; high integrity and discretion.
- AI-forward and hands-on understanding of LLM/agent risks, MCP/tool access, prompt injection, data leakage, excessive agency, evaluations, and governance.
Skills
- Information Security
- Security Engineering
- IT Engineering
- IT Operations
- Risk Management
- B2B SaaS
- Enterprise Security Program Management
- Product Security Partnership
- Corporate Risk Management
- Incident Leadership
- Detection and Response
- Vulnerability Management
- Identity Management
- Endpoint Security
- SaaS Security
- Cloud Security
- Secure SDLC
- GRC
- SOC 1
- SOC 2
- ISO 27001
- Privacy Obligations
- Customer Assurance
- Audit Remediation
- SOX Compliance
- ISO 42001
- Technical Judgment
- Architecture Review
- IAM
- Cloud Decision Making
- Application Security
- Data Flow Analysis
- IT Service Delivery Scaling
- Systems Engineering Scaling
- Automation
- Self-Service Models
- SLOs
- Employee Experience
- Decision Rights Clarity
- Executive Influence
- Engineering Leadership Influence
- Written Communication
- Incident Communication
- AI Security
- LLM Risk Management
- Agent Risk Management
- Prompt Injection Mitigation
- Data Leakage Prevention
- Excessive Agency Control
- AI Evaluation
- AI Governance
- Procurement Technology
- Fintech
- Payments
- Enterprise Workflow
- Data Sensitivity
- CISSP
- CISM
- Cloud Security Certifications
- Incident Response Certifications
- ISO Lead Implementer
- ISO Auditor
- Internal Audit
- SOX Readiness
- IPO Readiness
- Security Organization Integration
- IT Organization Integration
Experience Level
- 12+ years of experience
- 5+ years of leadership experience
About the Company
- Zip is the AI platform for enterprise procurement, built for humans and agents working together.
- Zip orchestrates procurement across teams, tools, and suppliers with the help of AI agents, enabling companies to secure resources for faster innovation.
- Trusted by enterprises like T-Mobile, OpenAI, AMD, Mars, and Dollar Tree, Zip has helped save over $8 billion and process over $500 billion in spend.
- The Zip team comprises product leaders from Apple, Airbnb, and Meta, and former procurement leaders from United Health, Sanofi, MGM Resorts, Discover, and NASA.
- Zip is backed by investors including Adams Street, Alkeon, BOND, CRV, DST, Tiger Global, and Y Combinator.
- The company has raised $371 million, most recently at a $2.2 billion valuation.
- Zip has received recognition from Forbes Fintech 50, Fast Company's Most Innovative Companies, Inc. Best in Business, and LinkedIn Top Startups.
