The opportunity
At Zapier , we build and use automation every day to make work more efficient, creative, and human. So if you’re using AI tools while applying here - that’s great!
What you'll do
You are a pragmatic, engineering-oriented SaaS security leader who thinks: like an engineer. You bring a hypothesis-driven, systems-thinking approach to security, and you are comfortable operating in ambiguity. You have led security teams for SaaS product companies on modern tech stacks that ship quickly and safely. You've gone deep in at least one security discipline (Application/Product Security, Infrastructure Security, Detection & Response, etc.) and broad across the others. You're fluent in modern cloud and identity threat models, supply chain risk, and secure-by-default infrastructure. You make decisions using business context and data as inputs, not dogma.
You are an AI-era security leader who helps Zapier stay ahead of what AI: makes possible — for our product and for our adversaries . You stay on the bleeding edge of what AI enables for defense and for attack. You turn that into guidance for executives and direction for Product and Engineering: what to build, what to avoid, and how trust and security show up in the product. You spot opportunities as well as risks — where stronger posture, transparency, or product choices can win enterprise trust. You have an opinion on how to secure agentic systems, MCP-style integrations, and AI features that touch customer data, and you help shape the roadmap — not only review what ships.
You look around corners: on risks and opportunities. You maintain a clear, prioritized view of what could hurt us and what we should pursue next, with impact and likelihood explained in plain language. You surface blind spots early and drive intentional decisions — mitigate, invest, or accept risk with eyes open. You don't default to reactive plans or comprehensive lists without a headline narrative of what keeps you up at night and what we're doing about it.
You drive change across the company, not only inside Security. You are strong: in change management: influencing executives, partnering with Build and IT, and shifting how the company works — policies, golden paths, technical enforcement, procurement, how teams ship and use AI — without defaulting to "security said no." You make the right thing easier than the risky thing, and you tee up leadership decisions when change requires company-wide support.
You are a strong partner to Enterprise Governance on shaping the product .: You work with Governance, Product, and GTM so enterprise-grade security and trust are designed in — controls, data and agent boundaries, AI-specific diligence, and what we can credibly commit to in contracts — not bolted on after ship.
You have executive presence internally and externally . Inside Zapier, you: are a calm, credible leader for your team and a trusted peer to the executive team — clear narratives, crisp tradeoffs, judgment under ambiguity. Outside Zapier, you are comfortable and effective with customers, prospects, CISOs, auditors, regulators, and analysts. You partner with Sales, CS, Legal, and Product Marketing to unblock and accelerate enterprise deals. You understand what it means to be a critical vendor and a subprocessor, and you build a program that can withstand that level of scrutiny.
What they're looking for
- You lead with risk management, executive communication, and visibility. You: can run a real risk program — identify, quantify, prioritize, communicate, and drive down risk across the company, not just within Security. You are the executive translator: you take complex technical risk and make it land with the executive team. You know how Zapier's operating model creates risk (speed, autonomy, broad tool access, AI experimentation, employee enablement) and how to mitigate that risk without breaking what makes the company effective. You force intentional risk acceptance where needed — leadership understands the tradeoff and chooses it with eyes open. You drive visibility — narratives, risk reports, and pre-reads — so leaders can make good decisions quickly.
- You bring deep expertise in detection, response, and incident management. You: have run modern detection & response and incident response programs end-to-end: detection engineering, triage, command, communications (internal, customer, regulator), forensics, root cause, and durable remediation. That includes product security incident response — running a bug bounty program at scale, ingesting and triaging external researcher reports, treating critical findings as incidents, and driving systemic fixes back into the product. You can stand up calmly in a high-severity incident at 2am, run the room, and own the customer narrative the next morning.
- You manage diverse, high-performing, growth-mindset engineering: organizations. You are an empathetic leader who values diversity and fosters psychological safety, inclusivity, and belonging. You forecast staffing needs, make hard staffing calls, and assess performance equitably across diverse people and functions. You manage managers, tech leads, and senior ICs, and you coach teams to be successfully autonomous. You give and receive feedback well, both inside and outside your org.
- You can develop and deliver on an aligned security vision, strategy, and: roadmap . You build a multi-year vision for security that aligns with and enables the company strategy — including our AI strategy and our enterprise GTM motion. You define measurable outcomes, track them, and hold yourself and your team accountable. You ruthlessly prioritize, raise risks early, and communicate tradeoffs clearly. You earn a broader mandate over time — including a path to Chief Security Officer — through outcomes, presence, and trust with leadership.