Sr. Director, Security
Zapier $308.4K - $462.6K/year Posted 4 days ago
About the role
Zapier is looking for a Sr. Director of Security (Head of Security) to lead its Security organization. This is the company's most senior security leadership role, with room for scope and recognition to grow. Zapier is an AI-forward company building on frontier models, and a critical vendor, in many cases a subprocessor, for thousands of enterprise customers who route sensitive data, credentials, and business-critical workflows through it every day. You will operate both strategically and hands-on: setting direction while going deep enough technically to audit plans, challenge assumptions, and drive strong security decisions for an AI-native SaaS platform.
Responsibilities
- Lead a team of Application Security, Infrastructure Security, Detection & Response, and GRC engineers, managing managers, tech leads, and senior ICs.
- Set the vision, strategy, and roadmap for security at an AI-native SaaS company, including how to secure AI features, agentic workflows, and integrations with frontier models.
- Own and evolve the risk management program: identify and quantify enterprise risk, drive mitigation, report crisply to the executive team, and force intentional risk acceptance where appropriate.
- Be Zapier's security voice internally and externally: lead customer security reviews and executive briefings, support go-to-market in enterprise deals, and engage with auditors, regulators, and the security community.
- Partner with Product, Engineering, and Enterprise Governance to shape trust features, control design, and AI and agent boundaries, not only review at ship time.
- Lead a high-functioning Detection & Response program, including product security incident response, bug bounty triage, customer communications, root cause, and systemic fixes.
- Drive company-wide security change: standards, golden paths, technical gates, vendor and procurement patterns, and workforce AI use.
Qualifications
- A pragmatic, engineering-oriented SaaS security leader who has led security teams for product companies on modern stacks that ship quickly and safely.
- Depth in at least one security discipline (AppSec, Infrastructure Security, Detection & Response) and breadth across the others, with fluency in modern cloud and identity threat models, supply chain risk, and secure-by-default infrastructure.
- An informed opinion on securing agentic systems, MCP-style integrations, and AI features that touch customer data.
- Executive presence with customers, CISOs, auditors, regulators, and analysts, and an understanding of what it means to be a critical vendor and subprocessor.
- End-to-end experience running modern detection, response, and incident management programs, including bug bounty at scale, and the calm to run the room in a high-severity incident.
- A record of building diverse, high-performing engineering organizations and delivering on a multi-year security vision aligned with company strategy.
Skills
How to apply
Apply directly on the employer's application page. Your application goes straight to them.
Republished listing
This opportunity was discovered on Zapier's public careers page and is republished here for discovery purposes. Applications are handled by the employer.
Zapier team? Claim this listing or ask us to remove it.