Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Lead IT Security Engineer image - Rise Careers
Job details

Lead IT Security Engineer

We Are Redefining How People Approach Their Health


ZOE is the science and nutrition company leading a movement to transform the health of millions.


We exist because the food we eat is making us sick. Most of what we are taught about food is wrong.


ZOE runs the world’s largest nutrition science study to find scientifically proven solutions.

Our randomized controlled trial of ZOE proves that if you eat the right food for your body, you can feel healthier in weeks and be on track for more healthy years.


ZOE can change the way you eat, feel, and live. We host world-leading scientists on our podcast and bring proven science to your plate with Daily30+, our 30+ plant supplement.


Over 100,000 people rely on ZOE Membership, our personalized nutrition program, to make smarter food choices. ZOE Membership turns complex science into clear step-by-step actions, helping you improve your health with every meal.


ZOE means life — and you can change your life with food.


Visit our career page and become a ZOEntist 🚀


About the team

The IT function at ZOE is currently led by our Head of IT, supported by an IT Support Engineer. Together, they ensure the smooth operation of our internal systems and infrastructure. As we scale, security is a top priority, and this role will be instrumental in shaping and implementing our IT security strategy, working closely with teams across ZOE to build a robust security framework. You will partner with the Head of IT for strategic guidance but serve as the hands-on lead for security initiatives.


About the role

We are looking for a Lead IT Security Engineer to own and operationalise our security roadmap, ensuring the protection of our SaaS-based environment, devices, and data. This is a business-critical role and the first dedicated IT security position at ZOE, giving you the opportunity to shape our policies and practices from the ground up. You will collaborate closely with our Engineering, Legal, and IT teams to mitigate key risks (e.g., endpoint security, BYOD, privileged access) and embed a culture of security across the organisation.


What you’ll do…
  • Shape and implement a comprehensive IT security roadmap that aligns with ZOE’s business goals, covering everything from endpoint security and identity/access management to DLP (Data Loss Prevention) and logging/monitoring.
  • Drive security programs around OS and application patch management, disk encryption, and local admin privilege management, ensuring corporate devices and contractor/BYOD setups meet compliance and security standards.
  • Assess, mitigate, and manage security risks across our SaaS ecosystem (over 100 apps), corporate IT systems, and infrastructure. Lead projects such as domain registration migrations, centralised logging/SIEM setup, and endpoint protection rollouts.
  • Develop and enforce security policies and frameworks, covering identity and access management, incident response, vendor security reviews, and data handling.
  • Drive automation and adopt Infrastructure-as-Code (IaC) patterns to ensure security controls and configurations are repeatable, consistent, and easily deployed across our endpoints and cloud resources.
  • Lead security compliance efforts in partnership with the Legal team, and provide technical guidance to the organisation on data privacy regulations (GDPR, DPA, CCPA etc.)
  • Monitor, investigate, and respond to security incidents, performing root cause analysis, implementing proactive measures and taking lead on responding to IT security incidents.
  • Cultivate a security-first culture by delivering ongoing training (e.g., phishing simulations, secure practices) and collaborating with teams on secure SaaS configuration.
  • Evaluate, select, and deploy security tools and technologies (e.g., EDR, MDM solutions), balancing strong security posture with user experience.
  • Own privileged access reviews and work with stakeholders to enforce least privilege across critical applications and data.
  • Stay ahead of evolving security threats and trends, continuously improving our security capabilities and processes.


What We’re looking for…
  • Extensive experience in corporate IT security, cybersecurity, or information security, ideally in a fast-paced, SaaS-based and cloud-based environment.
  • Proven ability to design, implement, and own security strategies independently.
  • Strong understanding of network security, and device management (Mac, Chromebook, or other).
  • Awareness of cloud security practices (AWS, GCP, or Azure).
  • Hands-on expertise in incident response, vulnerability management, endpoint protection (e.g., EDR), and security operations (logging, SIEM).
  • Deep knowledge of security industry best practices and data privacy regulations (GDPR, DPA, CCPA).
  • Experience embedding security culture: phishing training, running security awareness programs (KnowBe4 or similar), and guiding stakeholders on best practices.
  • Ability to communicate security risks and concepts effectively to both technical and non-technical stakeholders, and work autonomously on big initiatives.
  • A proactive, problem-solving mindset: comfortable tackling complex issues like domain migrations, privileged access reviews, and DLP rollout in a single role.
  • Experience working in a remote, international team is a plus.


The experience, skills, and attributes listed above reflect what we believe will contribute to success in this role. If you're passionate about ZOE and the opportunity, but don't meet 100% of the criteria, we still encourage you to apply. We are committed to supporting growth and are happy to offer upskilling opportunities where possible.


Compensation Philosophy

At ZOE, we are committed to offering competitive and equitable compensation that reflects the value of each role and aligns with regional labor market standards. Our approach to compensation goes beyond just base salary — we offer a comprehensive package that includes base pay and stock options, ensuring that every team member is rewarded for their contributions to the company’s growth and success.


We believe that building a thriving team requires not only providing fair and competitive compensation but also fostering an environment where success is shared collectively. Our total compensation package is designed to support the well-being of our employees, recognise their individual contributions, and empower them to grow alongside ZOE.


Benefits & Perks

At ZOE we understand the significant role our benefits play in motivating, inspiring and safeguarding our employees' well-being. Our benefits strategy is thoughtfully designed to echo our mission and values, recognising the diverse needs arising from different life stages of our ZOEntists.


Our approach to benefits takes an inclusive and flexible view of both personal and professional growth. From competitive health insurance and wellness packages to inclusive parental policies, building connection, and tailored professional development programs, we've got you covered.


At ZOE, we continue to build a benefits package that invests in our team members’ long-term personal and professional growth and wellbeing, adding to this list as it evolves.


Equal opportunities

 We are committed to fostering a diverse and inclusive team where every individual can bring their authentic self to work. We believe that this is key to our success and are dedicated to positively impacting the tech industry. As part of our commitment to equal opportunities, we encourage candidates from underrepresented backgrounds to apply. We ensure a respectful and inclusive environment for all and do not discriminate on the basis of race, colour, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, marital status, disability, or age. If you require any accommodations during the interview process, please feel free to inform us, and we will make every effort to support your needs.

Zoe Glassdoor Company Review
4.5 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
Zoe DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Zoe
Zoe CEO photo
Jonathan Wolf
Approve of CEO

Average salary estimate

$100000 / YEARLY (est.)
min
max
$80000K
$120000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Lead IT Security Engineer, Zoe

Are you ready to take your IT security skills to the next level? At ZOE, we're on a mission to redefine how people approach their health, and we need a Lead IT Security Engineer to join our dynamic team! As the first dedicated IT security position, you’ll have the unique opportunity to shape our security roadmap from the ground up. Imagine collaborating with diverse teams across ZOE to tackle security risks and build a robust security culture while working from the comfort of your home in the UK or EU. In this pivotal role, you’ll own and operationalize our security strategy, protect our SaaS-based environment, and ensure the security of our data and devices. You'll be driving initiatives like endpoint security, identity and access management, and data loss prevention. Plus, you’ll evaluate and deploy security tools while staying ahead of evolving threats. If you’re passionate about creating a safer digital environment and working with cutting-edge technologies, then this opportunity at ZOE is exactly what you’re looking for! Come help us turn complex science into actionable steps for healthier living and be part of a team that's making a real difference in people's lives.

Frequently Asked Questions (FAQs) for Lead IT Security Engineer Role at Zoe
What are the responsibilities of a Lead IT Security Engineer at ZOE?

As a Lead IT Security Engineer at ZOE, your key responsibilities include shaping and implementing a comprehensive IT security roadmap, driving security compliance efforts, and leading initiatives in endpoint security, identity management, and data protection. You'll partner closely with various teams to assess and mitigate security risks across our SaaS ecosystem and develop robust security policies. Your role is crucial in embedding a security-first culture across the organization.

Join Rise to see the full answer
What qualifications are needed to become a Lead IT Security Engineer at ZOE?

To become a Lead IT Security Engineer at ZOE, candidates should have extensive experience in corporate IT security, preferably in a SaaS and cloud-based environment. A strong understanding of network security, device management, and cloud security practices (AWS, GCP, or Azure) is essential. Proficiency in incident response, vulnerability management, and security operations is also required. You should be comfortable communicating security risks to both technical and non-technical stakeholders.

Join Rise to see the full answer
Are there opportunities for professional development as a Lead IT Security Engineer at ZOE?

Absolutely! At ZOE, we are committed to fostering a culture of growth and learning. As a Lead IT Security Engineer, you’ll have access to upskilling opportunities and resources that support your professional development. We encourage our team members to continuously develop their skills and stay updated on the latest security trends and technologies.

Join Rise to see the full answer
How does ZOE foster a culture of security within the organization?

ZOE promotes a strong security culture through ongoing training initiatives such as phishing simulations and security awareness programs. As the Lead IT Security Engineer, you'll play a crucial role in delivering these training sessions, guiding staff on best practices, and ensuring that security considerations are integrated into everyday operations across the organization.

Join Rise to see the full answer
Is the Lead IT Security Engineer position at ZOE a remote role?

Yes! The Lead IT Security Engineer position at ZOE is fully remote, allowing you to work comfortably from anywhere in the UK or EU. We embrace the benefits of remote work while fostering collaboration among our international team to ensure our collective mission of helping people transform their health.

Join Rise to see the full answer
Common Interview Questions for Lead IT Security Engineer
What strategies would you implement to enhance IT security at ZOE?

To enhance IT security at ZOE, I would first conduct a comprehensive risk assessment of our current systems and processes. Based on the findings, I would prioritize immediate vulnerabilities while developing a roadmap to implement robust security protocols, employee training, and compliance with privacy regulations such as GDPR.

Join Rise to see the full answer
How do you stay updated on the latest cybersecurity threats?

I stay updated on cybersecurity threats by regularly reading industry publications, participating in webinars, and joining professional security organizations. Additionally, engaging in online forums and connecting with other professionals allows me to share insights and learn about emerging threats and security innovations.

Join Rise to see the full answer
Can you describe your experience with incident response?

In my previous role, I was actively involved in incident response, managing the response to security breaches and conducting root cause analyses. I developed protocols for timely communication and remediation, ensuring minimal disruption to operations while enhancing our overall response strategy.

Join Rise to see the full answer
What is your experience with data protection regulations like GDPR?

I have extensive experience working with data protection regulations, including GDPR. In my past positions, I ensured compliance by implementing data handling policies, conducting regular audits, and training staff on data privacy best practices to safeguard our customers' information.

Join Rise to see the full answer
How would you assess the security of our SaaS applications?

To assess the security of our SaaS applications, I would perform vulnerability scanning and penetration testing, review security configurations, and ensure compliance with industry standards. Additionally, I would engage with vendor security assessments and monitor application security events for ongoing vigilance.

Join Rise to see the full answer
What tools and technologies do you prefer for endpoint protection?

I prefer using EDR solutions for endpoint protection, which provide advanced threat detection and response capabilities. Solutions that integrate with SIEM for centralized logging further enhance visibility and incident management. I also advocate for a mix of automated security controls to simplify deployment across diverse environments.

Join Rise to see the full answer
How do you foster a security-first culture within an organization?

Fostering a security-first culture involves regular training, establishing clear policies, and encouraging open communication regarding security concerns. I believe in making security everyone’s responsibility, so implementing interactive awareness programs and incentivizing secure practices can lead to a more informed workforce.

Join Rise to see the full answer
What do you consider the biggest challenge in IT security today?

One of the biggest challenges in IT security today is the constantly evolving threat landscape. With cybercriminals becoming increasingly sophisticated, organizations must remain vigilant, employing proactive strategies and up-to-date technologies to mitigate risks and respond quickly to new threats.

Join Rise to see the full answer
How would you handle a security breach at ZOE?

In the event of a security breach at ZOE, I would first activate the incident response plan, ensuring that the appropriate teams are notified and the breach is contained. After gathering information, I would communicate transparently with all stakeholders about potential impacts and remediation steps, while conducting a thorough post-incident analysis to prevent future occurrences.

Join Rise to see the full answer
What methods do you use for risk assessment in IT security?

I utilize both qualitative and quantitative methods for risk assessment in IT security. This includes identifying assets, recognizing potential risks, evaluating their impact, and prioritizing them based on likelihood and severity. I also incorporate regular reviews to adapt to any changes in the threat landscape.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 18 hours ago

ZOE seeks a Lead Machine Learning Engineer to innovate and scale AI solutions that transform personal health.

Photo of the Rise User
Zoe Remote UK/EU (Remote)
Posted 4 days ago

Become a vital part of ZOE's mission as a mid-level Full Stack Engineer, contributing to transformative health solutions in a supportive remote environment.

Photo of the Rise User
American Express Remote Phoenix, Arizona, United States
Posted 3 days ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

American Express is looking for a Senior Infrastructure Engineer to lead and innovate within their cloud operations and enhance customer experiences.

Photo of the Rise User
Bosch Group Remote Groenerstraße, 71636 Ludwigsburg, Deutschland
Posted 8 days ago

Join Bosch as a Security Solution Manager and lead innovative cybersecurity solutions for a range of clients.

Photo of the Rise User
Spring Venture Group Hybrid Kansas City, MO, United States
Posted 11 days ago

The Security Engineer will play a critical role in enhancing security measures at Spring Venture Group to protect information assets and ensure system integrity.

Posted 22 hours ago

Join Golden Lighting as a Systems Administrator/IT Support Technician and play a key role in maintaining their IT infrastructure as they innovate in the residential lighting industry.

Photo of the Rise User
CyberArk Hybrid Newton, Massachusetts
Posted 7 days ago

CyberArk is looking for a skilled Cloud Security Architect to lead the design and implementation of advanced security measures in their SaaS offerings.

Archgroup Remote Jersey City, NJ United States of America
Posted 10 days ago

We are looking for a visionary Chief Technology Officer to oversee technology transformation and optimize systems at Arch Insurance Group.

Photo of the Rise User
Posted 7 days ago

Join Rippl as a Contract IT Specialist and support innovative approaches to mental healthcare for seniors.

Photo of the Rise User
SCA Health Hybrid US, Coos County, OR; Oregon State, Myrtle Point, OR
Posted 11 days ago

As a Senior Infrastructure Cloud Engineer at SCA Health, you will architect and manage secure, scalable cloud environments to enhance patient care.

MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 5, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
K
Someone from OH, Cleveland just viewed Webflow/Framer Web Developer (Part time) at Keen
Photo of the Rise User
Someone from OH, Fairfield just viewed Cart Builder at SanMar Employee Board
Photo of the Rise User
Someone from OH, Columbus just viewed Label Machine Operator I - 2nd Shift at Avery Dennison
Photo of the Rise User
Someone from OH, Akron just viewed 3D Vehicle Artist (Unannounced Project) at Wargaming
Photo of the Rise User
9 people applied to GRC Director at Tanium
Photo of the Rise User
Someone from OH, Bowling Green just viewed Associate Designer at Newell Brands
Photo of the Rise User
Someone from OH, Twinsburg just viewed Finishing Operator - Nights at Avery Dennison
Photo of the Rise User
10 people applied to IT Support Intern at SoundCloud
D
Someone from OH, Cleveland just viewed Technical Writer at DevSavant Inc.
S
Someone from OH, Dayton just viewed Inventory Control Associate at SCLogistics
a
Someone from OH, Newark just viewed Billing Follow Up Rep I at aah
Photo of the Rise User
Someone from OH, Columbus just viewed Assistant Merchandising and Inventory Manager at Jushi
Photo of the Rise User
Someone from OH, Akron just viewed Entry Level Communications at Smart Solutions
Photo of the Rise User
Someone from OH, Toledo just viewed Processing Technician at Jushi
Photo of the Rise User
Someone from OH, Greenfield just viewed HR Generalist II at Protolabs
C
Someone from OH, Bowling Green just viewed Field Service Administrator at Cornerstone Building Brands
Photo of the Rise User
Someone from OH, Cleveland just viewed Vice President, Revenue Operations at Docebo
Photo of the Rise User
Someone from OH, Mansfield just viewed Director, Professional Education at Evolus
1
Someone from OH, Cleveland just viewed Copywriter at 1840 & Company
Photo of the Rise User
Someone from OH, Louisville just viewed Communications Manager at Shearer's Foods