Quick Overview
Job Description
Zenoti provides an all-in-one, cloud-based software solution for the beauty and wellness industry. Our solution allows users to seamlessly manage every aspect of the business in a comprehensive mobile solution: online appointment bookings, POS, CRM, employee management, inventory management, built-in marketing programs and more. Zenoti helps clients streamline their systems and reduce costs, while simultaneously improving customer retention and spending. Our platform is engineered for reliability and scale and harnesses the power of enterprise-level technology for businesses of all sizes
Zenoti powers more than 30,000 salons, spas, medspas and fitness studios in over 50 countries. This includes a vast portfolio of global brands, such as European Wax Center, Hand & Stone, Massage Heights, Rush Hair & Beauty, Sono Bello, Profile by Sanford, Hair Cuttery, CorePower Yoga and TONI&GUY.
Our recent accomplishments include surpassing a $1 billion unicorn valuation, being named Next Tech Titan by GeekWire, raising an $80 million investment from TPG, ranking as the 316th fastest-growing company in North America on Deloitte’s 2020 Technology Fast 500™. We are also proud to be recognized as a Great Place to Work CertifiedTM for 2021-2022 as this reaffirms our commitment to empowering people to feel good and find their greatness. To learn more about Zenoti visit: https://www.zenoti.com
Lead Reliability Engineer - Network and Security
What you'll be doing
You will build and operate the security controls that protect Zenoti's cloud estate, while partnering closely with InfoSec, Platform, and Engineering to enforce these controls.
- Own network architecture and connectivity. Design, build, and run the network backbone of a distributed, multi-tenant SaaS estate: vWAN/hub-spoke, ExpressRoute/VPN, cross-cloud (AWS↔Azure) connectivity, private endpoints, DNS, routing, and segmentation, engineered for redundancy and tested failover.
- Secure the edge and perimeter. Run the WAF, DDoS protection, Front Door/CDN, firewalls, and egress control, with no single points of failure, and keep network visibility high through flow analytics and cross-cloud path monitoring.
- Automate everything that repeats. Treat network and security as code: secure-by-default Terraform modules, IaC scanning gates, drift detection, policy-as-code (OPA, Azure Policy, SCPs), automated evidence collection, and certificate and secrets lifecycle automation.
- Operate detection, response, and resilience. Lead detection engineering, SIEM tuning, and incident command with RCA-to-control feedback loops, plus DR and ransomware-recovery architecture with failover runbooks tested on a schedule.
- Keep us continuously compliant. Maintain a control registry mapped to SOC 2, PCI-DSS, HIPAA, and regional privacy laws, and govern identity, PKI, and encryption in line with InfoSec policy.
- Be the architecture authority and set direction. Run design reviews and readiness assessments for new platforms and tools, manage risk-acceptance workflows, own the roadmap, mentor engineers, and give leadership clear, metric-anchored risk reporting.
What you'll bring
- 8+ years designing and operating infrastructure in Azure (primary) and AWS, with deep expertise in both network and security.
- Deep cloud networking: vWAN/hub-spoke, ExpressRoute/VPN (IPSec), BGP and routing, DNS, load balancing, private connectivity, and firewall and WAF management, including diagnosing complex cross-cloud connectivity issues.
- Security fundamentals: TLS/PKI, IAM, SIEM, threat analysis, and EDR and vulnerability/patch management across Windows and Linux.
- Strong automation skills: production IaC (Terraform preferred; ARM/Bicep/Ansible a plus), CI/CD pipeline integration, and scripting in Python, PowerShell, or Bash to eliminate manual toil.
- Multi-tenant SaaS architecture: tenant isolation, blast-radius thinking, and data residency across regions, including GDPR and regional laws.
- Workload and data security: Kubernetes (AKS/EKS) hardening, encryption and key management, and SQL Server and PaaS datastore hardening.
- Brownfield pragmatism: migrating legacy estates to secure baselines without outages, through phased adoption.
- Solid command of SOC 2, PCI-DSS, and HIPAA audits, including customer security questionnaires.
- Clear written communication: ADRs, and translating risk into business terms for leadership and auditors.
- Ability to influence through technical depth in a fast-paced, scaling SaaS environment.
Nice to have: AZ-500/SC-100, AWS Security Specialty, CISSP/CCSP, CKS.
Zenoti provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.