Head of InfoSec and IT Ops
Build and lead enterprise security and IT operations for a scaling SaaS platform
You will build and lead the enterprise security and IT operations system for Zip at a pivotal stage of scale. This includes owning the enterprise security program, clarifying product/corporate security boundaries, and leading IT Operations and Engineering to build a high-quality global service model. You will partner closely with Product, Engineering, Business Technology, and Internal AI leaders to stabilize operations and turn fragmented risk...
Why This Role?
Direct access to founders and real impact from day one at a $2.2B-valued AI procurement platform
Key Responsibilities
- Own the enterprise security program by establishing strategy, risk appetite, policies, control framework, roadmap, metrics, and executive re
- Clarify and operate the product/corporate security boundary by partnering with Product Security to define ownership of application, cloud, i
- Lead IT Operations and Engineering to build a high-quality global service model supporting employee technology and internal systems
- Stabilize IT operations and turn fragmented risks and services into one measurable operating model by agreeing boundaries with existing secu
- Lead by doing while hiring and developing the security and IT team to support rapid global expansion
Requirements
- Experience building and leading enterprise security programs
- Background in IT operations and engineering at scale
- Ability to partner with Product, Engineering, and Business Technology leaders
- Experience defining security boundaries and control frameworks
- Track record of stabilizing operations and creating measurable security models
Required Skills
Indonesia Context
- Working Hours Overlap:
- Flexible — work your own hours
View Original Description from Ashby Job Boards
Original description from Ashby Job Boards
ABOUT ZIP Zip is the AI platform for enterprise procurement — built for humans and agents working together. By orchestrating procurement across teams, tools, and suppliers with the help of AI agents, companies can secure the resources they need to innovate faster than ever before. The world’s most influential enterprises trust Zip, including T-Mobile, OpenAI, AMD, Mars, Dollar Tree, and more. Together they’ve saved over $8 billion and processed over $500 billion in spend. Zip’s team includes product leaders from Apple, Airbnb, and Meta, as well as former procurement leaders from United Health, Sanofi, MGM Resorts, Discover, and NASA. Backed by Adams Street, Alkeon, BOND, CRV, DST, Tiger Global, and Y Combinator, Zip has raised $371 million, most recently at a $2.2 billion valuation and has been recognized by Forbes Fintech 50, Fast Company's Most Innovative Companies, Inc. Best in Business, and LinkedIn Top Startups. YOUR ROLE You will build and lead the enterprise security and IT operations system for Zip at a pivotal stage of scale. Zip operates a mission-critical enterprise SaaS platform, is rapidly expanding operations globally, and is building the governance and controls required for its next phase. You will own a practical, engineering-oriented program spanning enterprise security governance, corporate security, detection and incident response, compliance and customer trust, and reliable employee technology. You will partner closely with Product and Engineering leaders responsible for the platform, and with Business Technology and Internal AI leaders building the systems and automations that run Zip. Your first mandate is to make accountability unambiguous: understand the current program, agree boundaries with existing product/infrastructure security leadership, stabilize IT operations, and turn fragmented risks and services into one measurable operating model. You will lead by doing, while hiring and developing the team. WHAT YOU'LL DO - Own the enterprise security program. Establish strategy, risk appetite, policies, control framework, roadmap, metrics, executive reporting, and decision rights. - Clarify and operate the product/corporate boundary. Partner with Product Security to define who owns application security, cloud/production security, identity engineering, vulnerability management, detection/response, customer trust, and remediation. - Lead IT Operations and Engineering. Build a high-quality global service model across support, identity, endpoint, SaaS, collaboration, office/network, automation, asset lifecycle, and resilience. Separate frontline support from systems engineering and drive secure self-service. - Build detection and response. Define priority threats and crown jewels, improve telemetry and detection coverage, establish 24/7 response, run incidents and exercises, and ensure corrective actions prevent recurrence. - Own GRC, assurance, and customer trust. Maintain and streamline processes for SOC 1, SOC 2, ISO 27001, and IS 42001, prepare for future SOX/public-company controls, manage audits and findings, and enable fast, accurate customer security responses. - Secure AI and internal tools. Partner with internal teams to define the risk tolerance, framework, and infrastructure to securely deploy AI and business apps built in-house. - Drive EIAM and data protection. Mature joiner/mover/leaver, privileged access, service identities, access reviews, data classification, DLP, encryption/key management, retention/deletion, and sensitive-data controls. - Manage third-party and resilience risk. Mature TPRM by risk-tiering vendors, ensuring contractual and operational controls, defining service criticality/RTO/RPO, and maintaining crisis readiness. - Build the team and culture. Assess roles and capability gaps, hire selectively, develop leaders, create security/IT champions, and make the safe path the easy path. WHAT WE'RE LOOKING FOR - 12+ years across information security, security engineering, IT engineering/operations, risk, or related disciplines, including 5+ years leading teams in a high-growth B2B SaaS company. - Experience owning a broad enterprise security program and partnering deeply with Product/Engineering; credible across both corporate and product risk. - Demonstrated leadership of major incidents, detection/response, vulnerability management, identity, endpoint/SaaS, cloud and secure SDLC programs. - Practical experience with SOC 1/2, ISO 27001, privacy obligations, customer assurance, and audit remediation. SOX/public-company and ISO 42001 experience are valuable. - Strong technical judgment: can review architecture, challenge IAM and cloud decisions, understand application/data flows, and distinguish control evidence from real risk reduction. - History of scaling IT service delivery and systems engineering through automation, self-service, clear SLOs, and excellent employee experience. - Ability to create clear decision rights in a federated environment and influence executives and engineering leaders without relying on hierarchy. - Excellent written and incident communication; calm under pressure; high integrity and discretion. - AI-forward and hands-on: understands LLM/agent risks, MCP/tool access, prompt injection, data leakage, excessive agency, evaluations, and governance. NICE TO HAVE - Experience at a procurement, fintech/payments, enterprise workflow, or data-sensitive SaaS company. - CISSP/CISM, cloud security, incident response, ISO lead implementer/auditor, or similar evidence of depth—certifications are not substitutes for outcomes. - Experience building an internal audit/SOX readiness program or operating through an IPO. - Experience integrating or consolidating security and IT organizations after leadership change.
Hiring at Zip
Zip has 28 other active roles on LokerDollar and has been hiring here since Jul 23, 2026 — across IT & Systems Administration, Sales & Business Development, Engineering, Operations.
- Strategic Account Executive - East
- Senior Solution Engineer (Pre-Sales)
- Human Resources Business Partner, GTM
Openness not stated by employer — check the listing
Frequently asked questions
- Is Head of InfoSec and IT Ops at Zip a remote job?
- This role is based in Remote. See the listing for remote/onsite details.
- What type of employment is Head of InfoSec and IT Ops at Zip?
- This is a full time position.
- How do I apply?
- Click the "Apply" button on this page to go to the official application at Zip.
Explore related
Market data & reports
Salary & skill-demand research built from our own listings data.
- Indonesia IT Jobs vs Global Remote (2026)Primary analysis of 2,049 listings: methodology, classification rules, downloadable datasets.
- AI-Skill Demand: Indonesia vs Global Remote (2026)10,000+ postings, taxonomy-first classifier, Wilson CIs, pre-registered before analysis.
- Remote ≠ Remote: The Skills That Open Global Work to Indonesians (2026)12,891 remote listings: the highest-paid coding skills are the most geo-locked for Indonesia-based applicants. CC BY 4.0 aggregate dataset.
- Indonesia Hiring Report: Tech vs Non-TechJob demand by field from aggregate open-job counts — never individual listings.
- Indonesia Salary BenchmarkAggregate salary ranges across roles, with open methodology and dataset.
- Indonesian Remote Work Salary & Demand IndexHow much of the global remote job corpus is open to Indonesia, and what it pays (USD) by role.
- Indonesia Quarterly Labor Market ReportLayoffs, funding, salaries & skills per quarter — open aggregates.
- Remote Market Reports by RoleAuto-generated per role family — skills, seniority, companies, salary.
- Global Remote Salary BenchmarkAnnual salary by role & currency, plus the share of listings open worldwide.
From the blog
- 5 Global Remote Job Openings 2026Explore 5 remote job opportunities from top companies like Neo Financial, TELUS Health, and IDG. Learn about salaries, required skills, and what to expect.
- Are Graduates Ready for the AI Era? RemoteIs the workforce ready for the AI shift? We break down the latest remote opportunities, salary benchmarks, and the skills that actually matter right now.
- What's Trending in Remote Jobs August 2026Analysis of the latest remote job trends: in-demand skills, salary ranges, and their impact on job seekers worldwide.