
Head of IT, Security
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in Arizona.
• Design, develop, and consistently enhance Fullbay’s security program utilizing NIST CSF 2.0 as the governance framework and CIS Controls v8.1 (IG1 to IG2) as the tactical execution guide.
• Oversee Fullbay’s always-on MDR platform and act as the main responder for escalated alerts.
• Investigate, contain, and resolve confirmed security incidents, including participating in an on-call rotation for high-severity escalations.
• Lead SOC 2 readiness initiatives, including control mapping, evidence gathering, gap remediation, and coordination with audit firms for Type I and Type II engagements.
• Manage and configure the security tooling ecosystem, including MDR, MDM, email security, anti-phishing, and security awareness tools.
• Draft, maintain, and enforce information security policies, standards, and procedures.
• Supervise IAM posture across Google Workspace, encompassing passkeys, MFA, SSO, privileged access controls, MDM, and Apple Business Manager configuration.
• Develop and own the incident response strategy and lead post-incident evaluations.
• Maintain a risk register, monitor security risks, and communicate risk posture to the VP of IT and senior leadership.
• Oversee security awareness training, phishing simulations, and compliance-related training cycles.
• Evaluate third-party vendor security posture, maintain a vendor risk inventory, and drive remediation efforts.
• Act as the primary escalation point for company-wide end-user technical support.
• Manage procurement, provisioning, deprovisioning, imaging, configuration, and asset inventory for company devices.
• Oversee user provisioning, licensing, and configuration across Google Workspace and other essential SaaS applications.
• Manage IT onboarding and offboarding processes, including account creation, device setup, access provisioning, and timely access removal.
• Handle IT vendor relationships and contracts, evaluate tools, and manage IT expenditures.
• Comply with confidentiality and regulatory requirements and perform other assigned duties.
• 7-10 years of cumulative experience in IT operations and security, cybersecurity, or information security is required; 10+ years is preferred.
• Proven experience managing and responding to alerts from an MDR/EDR platform, including triage, investigation, and remediation of confirmed incidents, is essential.
• Demonstrated experience leading a compliance or regulatory program (SOC 2, ISO 27001, HIPAA, PCI-DSS, or equivalent) is required.
• Bachelor’s degree in Information Security, Computer Science, Information Systems, or a related field, or equivalent professional experience.
• Practical experience administering Google Workspace, MDM platforms (e.g., NinjaOne, Apple Business Manager), and providing general end-user IT support is mandatory.
• Extensive knowledge of security frameworks, including NIST CSF 2.0 and CIS Controls v8.1.
• Familiarity with MDR/EDR platforms and MDM solutions, with the capability to investigate and respond to escalated alerts.
• Required platform experience includes Google Workspace administration and security configuration, Apple Business Manager (ABM), and NinjaOne endpoint management.
• Preferred platform experience includes Proofpoint email security and Ironscales anti-phishing.
• Solid understanding of IAM concepts, including SSO, MFA, passkeys, and privileged access management.
• Ability to function as a player-coach: design the security program, establish standards, and personally execute tasks.
• Excellent written and verbal communication skills, with the capability to present security risks and program status to executive leadership.
• Experience collaborating cross-functionally with Engineering, Legal, Finance, and business stakeholders.
• Preferred certifications include CISSP, CISM, CISA, CCSP, CompTIA Security+, or CASP+.
• Strong general IT troubleshooting abilities across Mac and Windows environments, networking fundamentals, and common business SaaS applications.
• Familiarity with IT ticketing/helpdesk systems and asset management tools.
• Capacity to meet stated physical demands, including regularly sitting at a desk, using computer and telephone equipment, and lifting/moving up to 10 pounds.
• Competitive salary with performance-based incentives.
• Comprehensive health, dental, and vision insurance packages.
• Flexible working hours and remote work options.
• Opportunities for professional development and continuing education.
• Supportive and inclusive work environment.
Integrity360
Rackspace Technology
Efficient Computer
Presidio
Get handpicked remote jobs straight to your inbox weekly.