You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Early Window: Be the first to open itNo views yetCloses in
Company hidden

Head of InfoSec and IT Ops

  • Remote
  • 6+ years

Salary

Not stated

Similar roles pay $195K - 265K a year · our estimate

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

About the company

The company is the AI platform for enterprise procurement — built for humans and agents working together. By orchestrating procurement across teams, tools, and suppliers with the help of AI agents, companies can secure the resources they need to innovate faster than ever before.

The world’s most influential enterprises trust the company, including T-Mobile, OpenAI, AMD, Mars, Dollar Tree, and more. The company’s team includes product leaders from Apple, Airbnb, and Meta, as well as former procurement leaders from United Health, Sanofi, MGM Resorts, Discover, and NASA.

Best in Business, and LinkedIn Top Startups.

Responsibilities

  • You will build and lead the enterprise security and IT operations system for the company at a pivotal stage of scale. The company operates a mission-critical enterprise SaaS platform, is rapidly expanding operations globally, and is building the governance and controls required for its next phase.
  • You will own a practical, engineering-oriented program spanning enterprise security governance, corporate security, detection and incident response, compliance and customer trust, and reliable employee technology. You will partner closely with Product and Engineering leaders responsible for the platform, and with Business Technology and Internal AI leaders building the systems and automations that run the company.
  • Your first mandate is to make accountability unambiguous: understand the current program, agree boundaries with existing product/infrastructure security leadership, stabilize IT operations, and turn fragmented risks and services into one measurable operating model. You will lead by doing, while hiring and developing the team.
  • Own the enterprise security program. Establish strategy, risk appetite, policies, control framework, roadmap, metrics, executive reporting, and decision rights.
  • Clarify and operate the product/corporate boundary. Partner with Product Security to define who owns application security, cloud/production security, identity engineering, vulnerability management, detection/response, customer trust, and remediation.
  • Lead IT Operations and Engineering. Build a high-quality global service model across support, identity, endpoint, SaaS, collaboration, office/network, automation, asset lifecycle, and resilience. Separate frontline support from systems engineering and drive secure self-service.
  • Build detection and response. Define priority threats and crown jewels, improve telemetry and detection coverage, establish 24/7 response, run incidents and exercises, and ensure corrective actions prevent recurrence.
  • Own GRC, assurance, and customer trust. Maintain and streamline processes for SOC 1, SOC 2, ISO 27001, and IS 42001, prepare for future SOX/public-company controls, manage audits and findings, and enable fast, accurate customer security responses.
  • Secure AI and internal tools. Partner with internal teams to define the risk tolerance, framework, and infrastructure to securely deploy AI and business apps built in-house.
  • Drive EIAM and data protection. Mature joiner/mover/leaver, privileged access, service identities, access reviews, data classification, DLP, encryption/key management, retention/deletion, and sensitive-data controls.
  • Manage third-party and resilience risk. Mature TPRM by risk-tiering vendors, ensuring contractual and operational controls, defining service criticality/RTO/RPO, and maintaining crisis readiness.
  • Build the team and culture. Assess roles and capability gaps, hire selectively, develop leaders, create security/IT champions, and make the safe path the easy path.

Requirements

  • 12+ years across information security, security engineering, IT engineering/operations, risk, or related disciplines, including 5+ years leading teams in a high-growth B2B SaaS company.
  • Experience owning a broad enterprise security program and partnering deeply with Product/Engineering; credible across both corporate and product risk.
  • Demonstrated leadership of major incidents, detection/response, vulnerability management, identity, endpoint/SaaS, cloud and secure SDLC programs.
  • Practical experience with SOC 1/2, ISO 27001, privacy obligations, customer assurance, and audit remediation. SOX/public-company and ISO 42001 experience are valuable.
  • Strong technical judgment: can review architecture, challenge IAM and cloud decisions, understand application/data flows, and distinguish control evidence from real risk reduction.
  • History of scaling IT service delivery and systems engineering through automation, self-service, clear SLOs, and excellent employee experience.
  • Ability to create clear decision rights in a federated environment and influence executives and engineering leaders without relying on hierarchy.
  • Excellent written and incident communication; calm under pressure; high integrity and discretion.
  • AI-forward and hands-on: understands LLM/agent risks, MCP/tool access, prompt injection, data leakage, excessive agency, evaluations, and governance.
  • Experience at a procurement, fintech/payments, enterprise workflow, or data-sensitive SaaS company.
  • CISSP/CISM, cloud security, incident response, ISO lead implementer/auditor, or similar evidence of depth—certifications are not substitutes for outcomes.
  • Experience building an internal audit/SOX readiness program or operating through an IPO.
  • Experience integrating or consolidating security and IT organizations after leadership change.
  • Experience: 5+ years
  • Visa: US citizen/visa only

Where you’d work

Fully remote

You can work from

  • United States

No visa sponsorship

You must already be able to work in the United States

About the company

Company hidden

  • Industry: SaaS

Your chances

Still hiring, not crowded yet, and you'd be among the first.

  • 17 checks run
  • 7 good signs
  • 0 red flags

Still hiring?

11 checks

Actively hiring

In its favour3

  • Still on the company's own careers site, checked 1 h agoModerate evidence
  • Found in the last 48 hours, before the big job boardsModerate evidence
  • The company posted 20 roles in the last 2 weeksSlight evidence

How crowded?

6 checks

Low

In its favour4

  • In its Early Window: not on the big job boards yetStrong evidence
  • Remote within United States onlySlight evidence
  • Only for people already authorized to work in United StatesSlight evidence
1 moreFewer
  • Lead level: far fewer people qualifySlight evidence

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details14 facts · Role, Location, Compensation, Employment, Company
Tech stack
  • LLMs
Seniority
Head of
Type
Full-time
Industry
SaaS
Specialty
Security
Region
United States
Show 8 more factsShow less

Role

Category
DevOps & Infrastructure
Specialty
Security
Seniority
Head of
Experience
5+ years
Tech stack
  • LLMs

Location

Work model
Remote
Region
United States
Remote from
  • United States
Visa sponsorship
Not sponsored
Must already work in
  • United States

Compensation

Salary
Salary by agreement
Pay period
Annual

Employment

Type
Full-time

Company

Industry
SaaS

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Lead Security Engineer

    $240,000 - 260,000 / year

    • Remote · US
    • Lead & Manager
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Operations Engineer

    Salary by agreement

    • Remote · US
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Operations Engineer

    Salary by agreement

    • Hybrid · Dallas
    • Mid-Level
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Security Detection Engineer

    $135,000 - 190,000 / year

    • Remote · US
    • Senior

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason