Head of InfoSec and IT Ops
Zip · San Francisco
About this role
**Head of InfoSec and IT Ops** **About Zip** Zip is the AI platform for enterprise procurement built for humans and agents working together. Trusted by T-Mobile, OpenAI, AMD, Mars, Dollar Tree, and more—collectively saving over $8 billion and processing $500 billion+ in spend. Backed by top-tier investors including Y Combinator, Tiger Global, and others at a $2.2B valuation. **Your Role** Build and lead enterprise security and IT operations at a pivotal scale stage. Own a comprehensive program spanning governance, corporate security, detection/incident response, compliance, and employee technology. Partner closely with Product, Engineering, and Business Technology leaders. **Key Responsibilities** • Establish enterprise security strategy, risk framework, policies, and metrics • Define product/corporate security boundaries and accountability • Lead global IT Operations across support, identity, endpoint, SaaS, and infrastructure • Build detection and response capabilities with 24/7 incident management • Own GRC, assurance (SOC 1/2, ISO 27001, IS 42001), and customer trust • Secure AI and internal tools deployment • Mature identity, access, and data protection programs • Manage third-party and resilience risk • Build and develop high-performing team **What We're Looking For** • 12+ years in information security, security engineering, IT operations, or related disciplines • 5+ years leading teams in high-growth B2B SaaS • Broad enterprise security program ownership with Product/Engineering partnership • Major incident leadership, detection/response, vulnerability management, identity, and cloud security experience • SOC 1/2, ISO 27001, privacy, and audit remediation expertise • Strong technical judgment and architecture review capability • IT service delivery scaling through automation and self-service • Clear communication and executive influence skills • AI-forward mindset with LLM/agent risk understanding **Nice to Have** • Procurement, fintech, or data-sensitive SaaS background • CISSP/CISM or cloud security certifications • Internal audit/SOX readiness or IPO experience • Security/IT organization integration experience
Listing freshness
CronJobs last confirmed this listing 17h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.