Head of IT & Security

Posted Yesterday
Easy Apply
Be an Early Applicant
Auckland, NZL
Hybrid
160K-195K Annually
Senior level
Cloud • eCommerce • Logistics • Software
Cin7 is passionate about reducing the cost, time and effort of selling products.
The Role
Lead corporate IT operations and cybersecurity as a hands-on head of IT/CISO hybrid. Manage device lifecycle, networking, identity, vendor relationships, Intune endpoint policies, SOC 2 audits, partner and penetration testing, security tooling (Wiz, CrowdStrike), AI security governance, policy architecture, incident escalation, and cross-functional security advisory.
Summary Generated by Built In
NZ Hi-Tech Company of the Year 2023, Cin7 is a fast-growing global software company that provides solutions for modern-day product sellers. We help these sellers keep track of their inventory at scale, and help them sell their products across multiple sales channels around the world.
 
Cin7 is expanding very quickly with a mission to become the leading Inventory Management Software brand in the world, and we are looking for a motivated and driven individual to join the team.

How you'll make an impact:
 
This is a dual-focused leadership role responsible for the strategic direction, daily operations, and continuous improvement of the organization’s corporate IT setup and comprehensive cybersecurity posture. This individual will act as the organizational head of IT while simultaneously executing CISO-style functionalities. The role demands a hands-on technical leader capable of managing day-to-day IT lifecycles while defending the business against modern threats, managing compliance audits, and architecting forward-looking AI security governance.

Here's what you'll do:

    Core IT Operations Management (Day-to-Day)

  • Lifecycle Management: Oversee the end-to-end onboarding and offboarding processes for all global staff, contractors, consultants ensuring seamless provisioning and de-provisioning of equipment and access.

  • Hardware & Asset Management: Manage procurement, inventory lifecycle, distribution, and maintenance of all corporate hardware. 

  • Network Operations: Design, manage, and maintain networking, Wi-Fi, and connectivity infrastructure across office locations. 

  • Identity & Access Management: Own the corporate identity architecture, access control lists, single sign-on and multi-factor authentication protocols. 

  • Vendor Management: Manage vendor relationships, including, billing, renewals, new vendor onboarding, selection and optimisation. 

  • Endpoint Management: Architect, deploy, and maintain Microsoft Intune device policies, compliance baselines, and application deployment for a fully cloud-first environment.

  • Working with RevOps, Data and Platform teams: Understanding the technical requirements for all integrations for corporate systems, owning the architecture of said integrations.

  • Strategic Security Governance & Compliance (CISO-Style Functionality)

  • Audit Ownership: Lead, coordinate, and successfully execute continuous SOC 2 compliance audits, finance-related security audits, and third-party partner reviews. 

  • High-Stakes Partner Audits: Act as the primary technical point of contact for highly rigorous partner audits (e.g., Amazon) as well as integration compliance programs (QuickBooks, Google, Xero). 

  • Policy Architecture: Draft, implement, and maintain the lifecycle of all corporate information security policies, standards, and procedures in close collaboration with People & Culture and the SLT. 

  • AI Security & Governance: Establish frameworks, acceptable use policies, and technical controls governing the secure implementation and use of AI. 

  • Security Operations, Threat Management & Response

  • Tooling & Architecture: Own and optimize the enterprise security stack, directly managing relationships and configurations with core vendors such as Wiz (cloud security) and CrowdStrike (endpoint protection). 

  • Vulnerability & Penetration Testing: Scope, organize, and manage annual third-party penetration testing initiatives, ensuring rapid remediation of identified vulnerabilities. 

  • Cross-Functional Advisory: Serve as the definitive escalation point for security tickets and questionnaires originating from customers, prospects, sales teams, engineering, and customer support regarding product security and platform integrity. 

  • Legal Liaison: Coordinate with external legal counsel regarding data privacy laws, security incident response readiness, and compliance liabilities. 

  • Security Culture: Build, deploy, and monitor an upgraded internal security awareness training and education program to elevate the company's baseline security posture.

Here's what you'll bring:

  • 5+ years leading IT operations or a Security function, including meaningful experience directing information security work through a team rather than executing it solo, ideally in a scaling SaaS or tech organization operating across multiple jurisdictions.

  • People leadership experience and a growth mindset, with the ability to manage and develop technical specialists

  • Accountable ownership of a SOC 2 (or equivalent) compliance program and the  ability to direct a team through audit prep, control design, and remediation, and to represent the program credibly to auditors, partners, and executives

  • Working knowledge of AI governance and security controls sufficient to set policy direction and evaluate technical recommendations from the security team

  • Ability to direct a security tooling strategy (e.g., cloud security posture management, EDR) 

  • Experience overseeing (not necessarily personally running) third-party penetration testing programs, with the judgment to prioritize findings and hold engineering accountable for remediation timelines

  • Comfort acting as the escalation point for external-facing security situations

  • Proven stakeholder management at senior leadership level, with the ability to translate technical risk into business terms

  • Strong vendor and budget management.

In return, we offer:

  • Hybrid Working Environment - 3 days work from home per week
  • Option to work 30 days every six months fully remote from anywhere in the world
  • Celebrate your birthday with a paid day off
  • A Global Wellness Day celebrated companywide, providing you a dedicated holiday to focus on your own wellbeing.
  • Fully paid health insurance 
  • Monthly Social Fridays drinks and food on us
  • Discounted gym membership as well as discounts at some local eateries etc
  • Recruitment referral bonus
  • Relaxed dress code
  • Modern office in Grafton complete with pool table, table tennis, PS5, Coffee machines etc

Why Cin7?
 
At Cin7, we make great products available to everyone. Every month, millions of sales orders flow through our platform reducing the cost, effort and time for product sellers so they can quickly get products to customers and build their brands without worrying about their operations. We pride ourselves on providing Inventory Management and Supply Chain software to help medium-large product businesses thrive in a highly competitive, digital world. Cin7 centrally manages inventory across multiple locations and channels, connecting 500+ systems to support receiving, selling and shipping stock.
 
We value diversity at Cin7, and bring people into the heart of everything we do.  We hire, recruit, and promote without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, pregnancy or maternity, veteran status or any other status protected by applicable law. We understand the importance of creating a safe and comfortable work environment and encourage individualism and authenticity in every member of our team.

Skills Required

  • 5+ years leading IT operations or a security function, ideally in scaling SaaS or multi-jurisdiction tech organizations
  • People leadership experience with ability to manage and develop technical specialists
  • Accountable ownership of a SOC 2 (or equivalent) compliance program including audit prep, control design, and remediation
  • Working knowledge of AI governance and security controls to set policy direction and evaluate technical recommendations
  • Ability to direct a security tooling strategy (cloud security posture management, EDR) and manage related vendor relationships
  • Experience overseeing third-party penetration testing programs and prioritizing remediation with engineering
  • Comfort acting as the escalation point for external-facing security incidents and partner audits
  • Proven stakeholder management at senior leadership level with ability to translate technical risk into business terms
  • Strong vendor and budget management experience

What the Team is Saying

Ajoy
Michelle
Jean
Carrie
Shawn

Cin7 Compensation & Benefits Highlights

  • Healthcare Strength Multiple U.S. medical plan options, dental, vision that’s effectively no‑cost for U.S. employees, FSAs/HSAs, mental‑health resources via TriNet, and company‑paid life and disability insurance are described. This breadth points to strong core coverage for U.S. roles.
  • Retirement Support A 401(k) through Transamerica with a company match of 50% on employee contributions up to 6% of base pay is outlined. This provides a clear, meaningful employer-backed savings mechanism.
  • Leave & Time Off Breadth Flexible or unlimited PTO, paid holidays and sick time, a birthday day off, wellness days, and paid volunteer time are included, alongside hybrid/remote work norms. These elements indicate generous time‑off flexibility for many roles.

Cin7 Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Denver, CO
276 Employees
Year Founded: 2012

What We Do

Cin7 connects your channels, inventory and accounting together. It dramatically reduces the cost of selling products across multiple channels, and opens up exciting new opportunities for product sellers. We're built on innovation, trust & collaboration, and a passion to see our customers thrive.

Why Work With Us

Cin7 is collaborative to the core. We’ve built a culture of open communication, continuous learning, and social activity to foster individual career development in a fun, team-centered environment. We love to promote from within: growing together, we can provide the best technology for product companies to sell to more customers in more places.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Cin7 Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Workplace policies vary by region, but we do allow flexibility in each location.

Typical time on-site: Not Specified
HQCin7 US Office
United Kingdom
Cin7 India Office
Cin7 New Zealand Office
Cin7 Sri Lanka Office
Cin7 Czechia Office
Learn more

Similar Jobs

Cin7 Logo Cin7

Customer Success Manager

Cloud • eCommerce • Logistics • Software
Easy Apply
Hybrid
Auckland, NZL
276 Employees

Cin7 Logo Cin7

Onboarding Specialist

Cloud • eCommerce • Logistics • Software
Easy Apply
Hybrid
Auckland, NZL
276 Employees
65K-75K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account