other
Posted May 27Sr. Director, Security
at Zapier
Remote
Responsibilities
- - Own and evolve our risk management program: identify and quantify enterprise risk (including risks created by how we operate), drive mitigation, report crisply to the executive team, and drive intentional risk acceptance where appropriate.
Requirements
- So if you’re using AI tools while applying here - that’s great! We just ask that you use them responsibly and transparently.
- Check out our guidance on How to Collaborate with AI During Zapier’s Hiring Process https://zapier.com/l/jobs/ai-at-zapier, including how to use AI tools like ChatGPT, Claude, Gemini, or others during our hiring process - and when not to.
- Zapier is an AI-forward company building AI-enabled products on top of frontier models, and a new generation of more capable, more autonomous models is reshaping both the products we ship and the threats we defend against.
- As Sr. Director of Security at Zapier, you will operate strategically and hands-on: setting direction while also going deep enough technically to audit plans, challenge assumptions, and help drive strong security decisions for an AI-native SaaS platform that sits in the middle of our customers' most important workflows.
- You're fluent in modern cloud and identity threat models, supply chain risk, and secure-by-default infrastructure.
- You make decisions using business context and data as inputs, not dogma. - You are an AI-era security leader who helps Zapier stay ahead of what AI makes possible — for our product and for our adversaries.
- You stay on the bleeding edge of what AI enables for defense and for attack.
- You have an opinion on how to secure agentic systems, MCP-style integrations, and AI features that touch customer data, and you help shape the roadmap — not only review what ships. - You look around corners — on risks and opportunities.
- You are strong in change management: influencing executives, partnering with Build and IT, and shifting how the company works — policies, golden paths, technical enforcement, procurement, how teams ship and use AI — without defaulting to "security said no." You make the right thing easier than the risky thing, and you tee up leadership decisions when change requires company-wide support. - You are a strong partner to Enterprise Governance on shaping the product.
- You work with Governance, Product, and GTM so enterprise-grade security and trust are designed in — controls, data and agent boundaries, AI-specific diligence, and what we can credibly commit to in contracts — not bolted on after ship. - You have executive presence internally and externally.
- You know how Zapier's operating model creates risk (speed, autonomy, broad tool access, AI experimentation, employee enablement) and how to mitigate that risk without breaking what makes the company effective.
- You build relationships across Product, Engineering, Enterprise Governance, Legal, GTM, Finance, People, and Risk.
- Things You'll Do Zapier is a fast-growing, remote-first, AI-forward company.
- You'll work across many parts of the org, but here's a representative slice: - Protect millions of customers — and increasingly, large enterprises — from having their API credentials, data, and AI-driven workflows compromised or put at risk.
- - Set the vision, strategy, and roadmap for security at an AI-native SaaS company, including how we secure AI features, agentic workflows, and integrations with frontier models.
- - Be Zapier's security voice internally and externally: lead customer security reviews and executive briefings, support GTM in enterprise deals, respond to subprocessor and AI-specific due diligence, and engage with auditors, regulators, and the security community.
- - Partner with Product, Engineering, and Enterprise Governance to advise and shape what we build for enterprise customers — trust features, control design, AI/agent boundaries, and enterprise commitments — not only review at ship time.
- - Lead company-wide security change — standards, golden paths, technical gates, vendor and procurement patterns, workforce AI use — with clear ownership, enforcement, and adoption.
- - Partner with Engineering and Product to embed security and AI safety into how we build, ship, and operate — secure SDLC, threat modeling for AI features, evals as controls, MCP/tool permission scoping, and continuous assurance.
- - Stay on the bleeding edge of AI, frontier models, and the evolving threat landscape (including AI-enabled adversaries) and translate that into how Zapier defends itself, shapes its product, and advises the company.
- - Recruit, interview, hire, and onboard top talent — and raise the bar for what an AI-era security org looks like.
Benefits
- You will partner closely with executives, Enterprise Governance, GTM, Product, Engineering, Legal, and Risk to make security a competitive advantage — not a tax — on how Zapier builds, ships, sells, and operates.
- That includes product security incident response — running a bug bounty program at scale, ingesting and triaging external researcher reports, treating critical findings as incidents, and driving systemic fixes back into the product.
- You give and receive feedback well, both inside and outside your org. - You can develop and deliver on an aligned security vision, strategy, and roadmap.
- You build a multi-year vision for security that aligns with and enables the company strategy — including our AI strategy and our enterprise GTM motion.
Contact
- AI AT ZAPIER At Zapier https://zapier.com/about, we build and use automation every day to make work more efficient, creative, and human.
- Check out this resource https://docs.google.com/spreadsheets/d/1_lXQvKwuU4xXEbye7EW_En8iv1ZIMlQNmT7B2Mzbo24/edit?gid=0#gid=0 for a list of countries where we currently cannot have Zapiens permanently working.
Additional details
- Location: North America We’re looking for a Sr. Director of Security (Head of Security) to lead the Security organization at Zapier.
- This is our most senior security leadership role, with room for scope and recognition to grow, depending on the impact of the leader we hire.
- We are a critical vendor — and in many cases a subprocessor — for thousands of enterprise customers who route sensitive data, credentials, and business-critical workflows through us every day.
- You will lead a team of Application Security (Product Security), Infrastructure Security, Detection & Response, and GRC engineers.
- About You - You are a pragmatic, engineering-oriented SaaS security leader who thinks like an engineer.
- You bring a hypothesis-driven, systems-thinking approach to security, and you are comfortable operating in ambiguity.
- You have led security teams for SaaS product companies on modern tech stacks that ship quickly and safely.
- You turn that into guidance for executives and direction for Product and Engineering: what to build, what to avoid, and how trust and security show up in the product.
- You spot opportunities as well as risks — where stronger posture, transparency, or product choices can win enterprise trust.
- You maintain a clear, prioritized view of what could hurt us and what we should pursue next, with impact and likelihood explained in plain language.