Head of InfoSec and IT Ops

Zip
San Francisco
Workplace: HybridFull timeFunction: CybersecuritySkills: ["Leadership","Technical judgment","Incident communication","Calm under pressure","Integrity"]

Build and lead Zip’s enterprise security and IT operations program as the company scales its mission-critical enterprise SaaS. Own security governance, detection and incident response, compliance, and customer trust (SOC 1/2, ISO 27001, IS 42001). Stabilize and globalize IT operations and engineering, mature identity and data protection, and strengthen third-party and resilience risk management while hiring, developing, and shaping a high-trust security/IT culture.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Zip
Zip
1 day ago

Head of InfoSec and IT Ops

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 7 hours agoStatus: Live

Job Summary

Build and lead Zip’s enterprise security and IT operations program as the company scales its mission-critical enterprise SaaS. Own security governance, detection and incident response, compliance, and customer trust (SOC 1/2, ISO 27001, IS 42001). Stabilize and globalize IT operations and engineering, mature identity and data protection, and strengthen third-party and resilience risk management while hiring, developing, and shaping a high-trust security/IT culture.
Location: San Francisco
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Sr. Director level

Key Responsibilities

  • •Own Zip’s enterprise security program, setting strategy, risk appetite, policies, control framework, roadmap, metrics, executive reporting, and decision rights.
  • •Clarify and operate the boundary between product security and corporate security, including application security, cloud/production security, identity engineering, vulnerability management, and remediation.
  • •Lead IT operations and engineering by building a global service model across support, identity, endpoint, SaaS, collaboration, office/network, automation, asset lifecycle, and resilience.
  • •Build detection and response by defining priority threats, improving telemetry, establishing 24/7 response, running incidents and exercises, and ensuring corrective actions prevent recurrence.
  • •Own GRC, assurance, and customer trust by maintaining SOC 1/2, ISO 27001, and IS 42001 processes, managing audits and findings, and enabling fast security responses.

Key Requirements

  • •12+ years across information security, security engineering, and IT engineering/operations, including 5+ years leading teams in a high-growth B2B SaaS environment.
  • •Experience owning a broad enterprise security program and partnering deeply with Product and Engineering across both corporate and product risk.
  • •Demonstrated leadership of major incidents and detection/response, vulnerability management, identity, endpoint/SaaS, cloud, and secure SDLC programs.
  • •Practical experience with SOC 1/2, ISO 27001, privacy obligations, customer assurance, and audit remediation (SOX/public-company and ISO 42001 are valuable).
  • •Strong technical judgment to review architecture, challenge IAM and cloud decisions, and distinguish control evidence from real risk reduction.
Experience:B2B SaaSEnterprise securityHigh-growth
Skills:LeadershipTechnical judgmentIncident communicationCalm under pressureIntegrity
Certifications:CISSPCISM

Company Brief

Zip
Provides buy-now-pay-later (BNPL) and digital payment solutions for consumers and merchants across multiple markets, enabling flexible payments, consumer credit, and merchant financing services.
Industry: Lending
Company Size: Enterprise (1,001+ employees)
Revenue: USD 250M to 500M
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Sydney, Australia
Founded: 2013
WebsiteLinkedIn