368,657open jobs
9,442companies
50,883added this week
Browse all
Salary
$175k – $386k per year (Estimated)
Location
Remote/Hybrid (San Francisco, United States)
Seniority
Architect · 12+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match

Zip

Zip is a digital financial services company headquartered in Sydney, Australia, and was founded in 2013. The company provides buy now, pay later (BNPL) solutions, digital wallets, and credit products that allow consumers to make purchases and pay for them over time through installments. Operating primarily in Australia, New Zealand, and the United States, the firm is listed on the Australian Securities Exchange and partners with thousands of retailers to offer flexible payment options at checkout.

About Zip

Zip is the AI platform for enterprise procurement - built for humans and agents working together. By orchestrating procurement across teams, tools, and suppliers with the help of AI agents, companies can secure the resources they need to innovate faster than ever before.

The world’s most influential enterprises trust Zip, including T-Mobile, OpenAI, AMD, Mars, Dollar Tree, and more. Together they’ve saved over $8 billion and processed over $500 billion in spend. Zip’s team includes product leaders from Apple, Airbnb, and Meta, as well as former procurement leaders from United Health, Sanofi, MGM Resorts, Discover, and NASA.

Backed by Adams Street, Alkeon, BOND, CRV, DST, Tiger Global, and Y Combinator, Zip has raised $371 million, most recently at a $2.2 billion valuation and has been recognized by Forbes Fintech 50, Fast Company's Most Innovative Companies, Inc. Best in Business, and LinkedIn Top Startups.

Your Role

You will build and lead the enterprise security and IT operations system for Zip at a pivotal stage of scale. Zip operates a mission-critical enterprise SaaS platform, is rapidly expanding operations globally, and is building the governance and controls required for its next phase.

You will own a practical, engineering-oriented program spanning enterprise security governance, corporate security, detection and incident response, compliance and customer trust, and reliable employee technology. You will partner closely with Product and Engineering leaders responsible for the platform, and with Business Technology and Internal AI leaders building the systems and automations that run Zip.

Your first mandate is to make accountability unambiguous: understand the current program, agree boundaries with existing product/infrastructure security leadership, stabilize IT operations, and turn fragmented risks and services into one measurable operating model. You will lead by doing, while hiring and developing the team.

What you'll do

  • Own the enterprise security program. Establish strategy, risk appetite, policies, control framework, roadmap, metrics, executive reporting, and decision rights.

  • Clarify and operate the product/corporate boundary. Partner with Product Security to define who owns application security, cloud/production security, identity engineering, vulnerability management, detection/response, customer trust, and remediation.

  • Lead IT Operations and Engineering. Build a high-quality global service model across support, identity, endpoint, SaaS, collaboration, office/network, automation, asset lifecycle, and resilience. Separate frontline support from systems engineering and drive secure self-service.

  • Build detection and response. Define priority threats and crown jewels, improve telemetry and detection coverage, establish 24/7 response, run incidents and exercises, and ensure corrective actions prevent recurrence.

  • Own GRC, assurance, and customer trust. Maintain and streamline processes for SOC 1, SOC 2, ISO 27001, and IS 42001, prepare for future SOX/public-company controls, manage audits and findings, and enable fast, accurate customer security responses.

  • Secure AI and internal tools. Partner with internal teams to define the risk tolerance, framework, and infrastructure to securely deploy AI and business apps built in-house.

  • Drive EIAM and data protection. Mature joiner/mover/leaver, privileged access, service identities, access reviews, data classification, DLP, encryption/key management, retention/deletion, and sensitive-data controls.

  • Manage third-party and resilience risk. Mature TPRM by risk-tiering vendors, ensuring contractual and operational controls, defining service criticality/RTO/RPO, and maintaining crisis readiness.

  • Build the team and culture. Assess roles and capability gaps, hire selectively, develop leaders, create security/IT champions, and make the safe path the easy path.

What we're looking for

  • 12+ years across information security, security engineering, IT engineering/operations, risk, or related disciplines, including 5+ years leading teams in a high-growth B2B SaaS company.

  • Experience owning a broad enterprise security program and partnering deeply with Product/Engineering; credible across both corporate and product risk.

  • Demonstrated leadership of major incidents, detection/response, vulnerability management, identity, endpoint/SaaS, cloud and secure SDLC programs.

  • Practical experience with SOC 1/2, ISO 27001, privacy obligations, customer assurance, and audit remediation. SOX/public-company and ISO 42001 experience are valuable.

  • Strong technical judgment: can review architecture, challenge IAM and cloud decisions, understand application/data flows, and distinguish control evidence from real risk reduction.

  • History of scaling IT service delivery and systems engineering through automation, self-service, clear SLOs, and excellent employee experience.

  • Ability to create clear decision rights in a federated environment and influence executives and engineering leaders without relying on hierarchy.

  • Excellent written and incident communication; calm under pressure; high integrity and discretion.

  • AI-forward and hands-on: understands LLM/agent risks, MCP/tool access, prompt injection, data leakage, excessive agency, evaluations, and governance.

Nice to have

  • Experience at a procurement, fintech/payments, enterprise workflow, or data-sensitive SaaS company.

  • CISSP/CISM, cloud security, incident response, ISO lead implementer/auditor, or similar evidence of depth-certifications are not substitutes for outcomes.

  • Experience building an internal audit/SOX readiness program or operating through an IPO.

  • Experience integrating or consolidating security and IT organizations after leadership change.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,657 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
San Francisco
$87k – $130k per year • In office • Full-Time • 6+ years exp • Murray
Python
TypeScript
JavaScript
Python
Alembic
FastAPI
Pydantic
SQLAlchemy
Databases
PostgreSQL
Redis
AI/ML
Embeddings
LLM
LLM Guardrails
Ollama
RAG
Frontend
React Query
React Router
React.js
Vite
DevOps
AWS
CI/CD
Docker
Docker Compose
IAM
Terraform
Cybersecurity
FedRAMP
NIST 800-53
QA
Pytest
Apply
$122k – $200k per year • In office • Full-Time • 10+ years exp • Charlotte • New York
AI/ML
AI Agents
Context Engineering
Copilot
Hallucination
Human-in-the-Loop
Knowledge Graph
LLM
LLM Guardrails
LLMOps
Prompt Engineering
RAG
DevOps
Azure
CI/CD
GitHub
Kubernetes
Vector
Analytics
A/B Testing
Apply
$145k – $193k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • Chicago • Washington • Denver • Jersey City • Boston
Python
AI/ML
AI Agents
Anomaly Detection
Embeddings
Fine-tuning
Function Calling
Hugging Face
LangChain
LLM
LLM Evaluation
LLM Guardrails
PyTorch
RAG
Red Teaming
Scikit-learn
Vertex AI
DevOps
Azure
GCP
Cybersecurity
Threat Modeling
Apply
$60k – $108k per year • Remote/Hybrid • Full-Time • Bachelor's Degree • United States
PowerShell
Python
DevOps
AWS
Azure
IAM
Splunk
Cybersecurity
Crowdstrike
ISO 27001
Microsoft Defender
Microsoft Entra ID
Microsoft Sentinel
NIST CSF
Qualys Cloud Platform
Apply
Design Engineer 3 hours ago
$63k – $133k per year (Estimated) • In office • Full-Time • Berlin
TypeScript
AI/ML
AI Agents
DevOps
GitHub
Design
Figma
Apply
Remote/Hybrid • Full-Time • 15+ years exp
Apex
Apex
MuleSoft
AI/ML
AI Agents
DevOps
Rest API
Apply
$180k – $324k per year (Estimated) • Remote/Hybrid • Contractor • 8+ years exp • San Francisco
AI/ML
AI Agents
OpenAI
Apply
$78k – $203k per year (Estimated) • Remote/Hybrid • Full-Time • 6+ years exp • London
ABAP
ABAP
SAP BTP
Databases
Databricks
Snowflake
AI/ML
AI Agents
OpenAI
Management
Notion
Apply
$72k – $189k per year (Estimated) • Remote/Hybrid • Full-Time • 6+ years exp • Toronto
ABAP
ABAP
SAP BTP
Databases
Databricks
Snowflake
AI/ML
AI Agents
OpenAI
Management
Notion
Apply
Remote/Hybrid • Internship • Bachelor's Degree • San Francisco
JavaScript
Python
TypeScript
AI/ML
AI Agents
OpenAI
Frontend
GraphQL
React.js
DevOps
AWS
Management
Slack
Apply
$170k – $220k per year • Equity 1–2.8% • In office • Full-Time • 3+ years exp • San Francisco
Python
SQL
Python
Django
AI/ML
AI Agents
Context Engineering
LLM
LLM Evaluation
RAG
Apply
$173k – $314k per year • In office • Full-Time • 12+ years exp • Bachelor's Degree • San Francisco
Apex
JavaScript
Node JS
Python
SQL
TypeScript
Apex
Lightning Web Components
AI/ML
Agentforce
AI Agents
Claude
Claude Code
Copilot
Cursor
LLM
RAG
DevOps
AWS
Azure
CI/CD
Docker
GCP
GitHub
Grafana
gRPC
Kubernetes
New Relic
Prometheus
Splunk
Marketing
Salesforce
QA
Cypress
JMeter
k6
Locust
Playwright
Postman
Rest-Assured
Selenium
Apply
Senior ML Engineer 2 hours ago
$149k – $224k per year • In office • Full-Time • 5+ years exp • Master's Degree • San Francisco • Washington • Palo Alto
Python
Python
pySpark
Databases
Apache Kafka
AI/ML
AI Agents
Agentforce
Airflow
Anomaly Detection
Feature Store
Flink
Ray
Red Teaming
Spark
DevOps
CI/CD
Docker
Kubernetes
Cybersecurity
MITRE ATT&CK
Marketing
Salesforce
Apply
In office • Internship • 1+ year exp • Bachelor's Degree • San Francisco
Go
JavaScript
Ruby
Scala
Apply
$360k – $530k per year • In office • Full-Time • Bachelor's Degree • San Francisco
MATLAB
Python
MATLAB
Simulink
AI/ML
OpenAI
Robotics
Digital Twin
Apply
See all jobs
This is one of many
368,657 more open roles from verified company boards, updated every day.