Head of IT & Security
Job description
About the role
Cin7 stands as a leading force in the global inventory management space, recognized as the NZ Hi-Tech Company of the Year 2023. We are a fast-growing global software company dedicated to empowering modern-day product sellers. Our platform processes millions of sales orders monthly, enabling sellers to manage inventory at scale and distribute products across numerous sales channels worldwide. Our mission is clear: to become the dominant Inventory Management Software brand globally. We seek a motivated and driven individual to join this ambitious journey. At Cin7, our core philosophy centers on making powerful products accessible to everyone. We pride ourselves on delivering Inventory Management and Supply Chain software that allows medium to large product businesses to thrive in a fiercely competitive digital landscape. Our technology connects over 500 systems, centrally managing inventory across multiple locations and channels to facilitate receiving, selling, and shipping stock efficiently. We value diversity profoundly and foster an environment where people are at the heart of everything. Our hiring, recruitment, and promotion practices are founded on equality, respecting individuals regardless of race, color, religion, sex, sexual orientation, gender identity or expression, national origin, pregnancy or maternity, veteran status, or any other protected status. We are committed to building a safe, comfortable, and authentic work environment that encourages individualism. Here is a detailed look at your responsibilities.
Key facts
What you'll do
You will architect and oversee the end-to-end security strategy aligned with our global business objectives, ensuring all technology initiatives support our mission of inventory management dominance. You will own the complete lifecycle management of our global workforce technology, orchestrating the seamless onboarding and offboarding of all staff and contractors while ensuring the efficient provisioning and de-provisioning of equipment and system access. Hardware and corporate assets will fall under your direct stewardship, requiring you to manage the entire procurement lifecycle, inventory, distribution, and maintenance with rigorous oversight. Network operations across our office locations will be your responsibility, encompassing the design, management, and maintenance of networking, Wi-Fi, and connectivity infrastructure to guarantee uninterrupted business continuity. Identity and Access Management forms a critical pillar of your role; you will own the corporate identity architecture, directing access control lists and managing all protocols related to identity verification and access security. This includes oversight of single sign-on and multi-factor authentication frameworks to maintain the highest standards of access control. Strategic vendor relationships will be managed by you, covering billing, renewals, new vendor onboarding, selection, and ongoing optimization to ensure we derive maximum value from our technology investments. You will architect, deploy, and maintain Microsoft Intune device policies, ensuring compliance baselines and application deployment within our fully cloud-first environment to support our distributed workforce. Collaboration with RevOps, Data, and Platform teams will be essential to understand and own the technical architecture for all corporate system integrations, ensuring data flows seamlessly and securely. Security governance will be a primary focus, and you will lead, coordinate, and execute continuous SOC 2 compliance audits, finance-related security audits, and comprehensive reviews of third-party partners. You will act as the primary technical point of contact for highly rigorous partner audits, including those from entities like Amazon, as well as integration compliance programs with platforms such as QuickBooks, Google, and Xero. Policy architecture is another key duty; you will draft, implement, and maintain the complete lifecycle of all corporate information security policies, standards, and procedures, working in close collaboration with People & Culture and Senior Leadership. The governance of AI security is increasingly vital; you will establish robust frameworks, acceptable use policies, and technical controls to ensure the secure implementation and use of AI within our ecosystem. Operational oversight of our enterprise security stack is crucial, and you will own and optimize our security tooling, directly managing relationships and configurations with core vendors such as Wiz for cloud security and CrowdStrike for endpoint protection. Vulnerability and penetration testing programs will be scoped, organized, and managed by you, ensuring the rapid remediation of identified vulnerabilities across the entire technology landscape. You will serve as the definitive escalation point for security tickets and questionnaires originating from customers, prospects, sales teams, engineering, and customer support concerning product security and platform integrity. Coordination with external legal counsel regarding data privacy laws, security incident response readiness, and compliance liabilities is also a critical responsibility, requiring proactive management and clear communication. Building and deploying an upgraded internal security awareness training and education program will be your responsibility, aimed at elevating the company's overall security posture and fostering a culture of security mindfulness.
Requirements
You possess 5 or more years of experience leading IT operations or a security function, demonstrating a proven track record in complex environments. This experience must include meaningful experience directing information security work through a team, rather than executing tasks solo, ideally within a scaling SaaS or technology organization operating across multiple jurisdictions. You demonstrate people leadership capabilities and a growth mindset, with the ability to effectively manage and develop technical specialists to foster a high-performing team environment. You are accountable for owning a SOC 2 or equivalent compliance program, capable of directing a team through audit preparation, control design, and remediation, while representing the program credibly to auditors, partners, and executives with confidence and clarity. You hold working knowledge of AI governance frameworks and security controls sufficient to set policy direction and evaluate technical recommendations related to emerging technologies. The ability to direct a security tooling strategy for areas such as cloud posture management and endpoint detection is essential for maintaining a robust security architecture. You have experience overseeing third-party penetration testing programs, possessing the judgment to prioritize findings and hold engineering teams accountable for remediation timelines and effective risk mitigation. You are comfortable acting as the escalation point for external-facing security situations, handling high-pressure scenarios with professionalism and diligence. You possess proven stakeholder management skills at the senior leadership level, with the ability to translate technical risk into clear business context and drive strategic decision-making across executive sponsors. You exhibit strong judgment and discretion when handling sensitive information and complex security matters, ensuring confidentiality and integrity at all times. You communicate effectively, both verbally and in writing, enabling you to articulate complex technical concepts to diverse audiences across the organization. You are a collaborative team player, working effectively with global, cross-functional partners to achieve shared security and operational objectives.
Nice to have
Experience with inventory or ecommerce platforms is a distinct advantage given our core market focus.
Practical notes
This role is based in Auckland, New Zealand.
Full-Time engagement.
No relocation support or visa sponsorship is available for this role.
Candidates must be legally authorized to work in New Zealand.
Travel is not required for this position.
This role does not offer compensation above the defined market rate.