SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 120,000 - 120,000 / annual
Zen Educate is seeking an IT Operations & Security Lead to own the company's internal IT systems and security infrastructure as it scales from ~600 employees across the UK and US. You will report directly to the CTO and be the first dedicated hire to consolidate IT and security responsibilities currently spread across multiple roles.
The role focuses on building scalable, automated systems rather than managing ticket queues. Key responsibilities include:
**Identity & Access Management**: Own Google Workspace, SSO, MFA, groups, permissions and least-privilege principles. Build workflows to automate access provisioning when employees join, move teams, or leave—replacing manual checklists.
**SaaS Governance & Vendor Management**: Create a definitive inventory of all software and services (what's used, who owns it, access levels, costs, renewal dates). Work with teams to improve purchasing, renewal and retirement processes, addressing issues like duplicate licenses and unused seats.
**Security Policies & Controls**: Define and implement IT and security policies that translate into working processes, technical controls and training. Establish access reviews, vulnerability management, external testing, incident response and secure reporting mechanisms.
**Compliance & Assurance**: Build reusable trust processes for security questionnaires, audit evidence, Cyber Essentials certification and future compliance requirements. Work closely with Legal and Data Protection advisors on privacy intersections.
**Device Fleet Management**: Establish secure, proportionate approaches to both company-owned and personal devices. Ensure devices are encrypted, patched, accounted for and provisioned remotely. Maintain visibility into critical vulnerabilities and enforce 14-day patching windows.
**Incident Response**: Extend the company's established product incident process to corporate IT and security. Own clear ownership, communication, decision recording and root-cause resolution when issues occur.
You will not own product/platform security (that sits with the Foundations Lead and Engineering) or the broader employee lifecycle (People Team handles that), though you'll coordinate on company-wide initiatives and automate supporting systems.
The role is hands-on and varied: you might discuss security posture with leadership in the morning and fix an access workflow in the afternoon. The company values building systems over clearing queues, using proven tools for obvious problems while experimenting with new approaches (including AI) where mature solutions don't exist. Security should enable the business, not create unnecessary friction—this requires judgment about meaningful vs. theoretical risks.
You'll be a visible, approachable go-to person who builds confidence in the company's security posture and follows problems through to completion. The role is new, so part of the job is defining what it looks like as Zen grows.
**Requirements**
You should have:
- Experience as the second or third person in an IT, Corporate IT or Security Operations team while a company grew from a few hundred to much larger scale
- Real hands-on depth in identity and access management, endpoint management and automation
- Working grasp of SaaS governance, vendor and license management, audits and certification, incident response and data protection
- Deep knowledge of security principles and controls—you should understand why controls work well enough to learn any system yourself
- Business mindset: ability to apply security proportionally to Zen's stage, distinguishing which risks actually matter
- Experience taking manual, messy or poorly-defined processes and scaling them into reliable systems
- Ability to communicate confidently at every level of the business
- Strong async communication and remote collaboration habits
- Understanding of how frontline teams actually work, not just how systems are configured
The company cares more about what you've actually improved than whether your CV lists every specific tool. Principles over product knowledge is the hiring philosophy.