Skip to content
← Back to job listings

Senior Security Director

Zapier · United States

External listingfull-time22 days ago

About The Role

Join Zapier, an AI-forward company on a mission to enhance productivity through automation and AI. As the Senior Director of Security, you will lead the security strategy for our AI-native SaaS platform, protecting millions of customers and driving security as a competitive advantage. You will manage a team of security engineers, collaborate with executives across various departments, and shape the future of security at Zapier.

  • Establecer y entregar la estrategia de seguridad para una plataforma SaaS nativa de IA, incluyendo cómo asegurar las características de IA y los flujos de trabajo.
  • Dirigir un equipo de ingenieros de seguridad en diversas áreas, incluyendo la seguridad de aplicaciones, la seguridad de infraestructura, la detección y respuesta, y la gobernanza, riesgo y cumplimiento.
  • Colaborar estrechamente con ejecutivos y otros departamentos para hacer de la seguridad una ventaja competitiva en la forma en que Zapier construye, vende y opera.
  • You can stand up calmly in a high-severity incident at 2am, run the room, and own the customer narrative the next morning
  • You earn a broader mandate over time — including a path to Chief Security Officer — through outcomes, presence, and trust with leadership
  • You drive visibility — narratives, risk reports, and pre-reads — so leaders can make good decisions quickly
  • You forecast staffing needs, make hard staffing calls, and assess performance equitably across diverse people and functions
  • You maintain a clear, prioritized view of what could hurt us and what we should pursue next, with impact and likelihood explained in plain language
  • You bring a hypothesis-driven, systems-thinking approach to security, and you are comfortable operating in ambiguity
  • You manage managers, tech leads, and senior ICs, and you coach teams to be successfully autonomous
  • You are strong in change management: influencing executives, partnering with Build and IT, and shifting how the company works — policies, golden paths, technical enforcement, procurement, how teams ship and use AI — without defaulting to "security said no
  • You have executive presence internally and externally
  • You spot opportunities as well as risks — where stronger posture, transparency, or product choices can win enterprise trust
  • You make decisions using business context and data as inputs, not dogma
  • You build relationships across Product, Engineering, Enterprise Governance, Legal, GTM, Finance, People, and Risk
  • You can run a real risk program — identify, quantify, prioritize, communicate, and drive down risk across the company, not just within Security
  • You are a pragmatic, engineering-oriented SaaS security leader who thinks like an engineer
  • Inside Zapier, you are a calm, credible leader for your team and a trusted peer to the executive team — clear narratives, crisp tradeoffs, judgment under ambiguity
  • ) and broad across the others
  • You surface blind spots early and drive intentional decisions — mitigate, invest, or accept risk with eyes open
  • You work with Governance, Product, and GTM so enterprise-grade security and trust are designed in — controls, data and agent boundaries, AI-specific diligence, and what we can credibly commit to in contracts — not bolted on after ship
  • You give and receive feedback well, both inside and outside your org
  • You partner with Sales, CS, Legal, and Product Marketing to unblock and accelerate enterprise deals
  • You've gone deep in at least one security discipline (Application/Product Security, Infrastructure Security, Detection & Response, etc
  • You know how Zapier's operating model creates risk (speed, autonomy, broad tool access, AI experimentation, employee enablement) and how to mitigate that risk without breaking what makes the company effective
  • That includes product security incident response — running a bug bounty program at scale, ingesting and triaging external researcher reports, treating critical findings as incidents, and driving systemic fixes back into the product
  • You bring deep expertise in detection, response, and incident management
  • You are an AI-era security leader who helps Zapier stay ahead of what AI makes possible — for our product and for our adversaries
  • You build a multi-year vision for security that aligns with and enables the company strategy — including our AI strategy and our enterprise GTM motion
  • You ruthlessly prioritize, raise risks early, and communicate tradeoffs clearly
  • " You make the right thing easier than the risky thing, and you tee up leadership decisions when change requires company-wide support
  • You force intentional risk acceptance where needed — leadership understands the tradeoff and chooses it with eyes open
  • Outside Zapier, you are comfortable and effective with customers, prospects, CISOs, auditors, regulators, and analysts
  • You turn that into guidance for executives and direction for Product and Engineering: what to build, what to avoid, and how trust and security show up in the product
  • You have an opinion on how to secure agentic systems, MCP-style integrations, and AI features that touch customer data, and you help shape the roadmap — not only review what ships
  • You partner with Product Management on security and trust features that help us win and retain upmarket customers
  • You understand what it means to be a critical vendor and a subprocessor, and you build a program that can withstand that level of scrutiny
  • You stay on the bleeding edge of what AI enables for defense and for attack
  • You build strong partnerships and are an excellent communicator
  • You look around corners — on risks and opportunities
  • You are an empathetic leader who values diversity and fosters psychological safety, inclusivity, and belonging
  • You are the executive translator: you take complex technical risk and make it land with the executive team
  • You're fluent in modern cloud and identity threat models, supply chain risk, and secure-by-default infrastructure
  • You manage diverse, high-performing, growth-mindset engineering organizations
  • You can develop and deliver on an aligned security vision, strategy, and roadmap
  • You have led security teams for SaaS product companies on modern tech stacks that ship quickly and safely
  • You define measurable outcomes, track them, and hold yourself and your team accountable
  • You have run modern detection & response and incident response programs end-to-end: detection engineering, triage, command, communications (internal, customer, regulator), forensics, root cause, and durable remediation
  • You drive change across the company, not only inside Security
  • You don't default to reactive plans or comprehensive lists without a headline narrative of what keeps you up at night and what we're doing about it
  • You are a strong partner to Enterprise Governance on shaping the product
  • You lead with risk management, executive communication, and visibility
  • You communicate clearly in writing and verbally, tailor your message to any audience from engineer to Board member, and use storytelling that doesn't lose the "why." You use modern practices and selective automation to scale the org — triage, evidence, questionnaires, access reviews, IR — as leverage, not as a substitute for judgment, corner-looking, or change leadership

This is an external listing. JobSpring does not represent or verify the employer. Report this listing