Head of IT, Security

Posted 3 days ago

This is a fully remote position, open to applicants in Arizona.

📋 Description

• Design, develop, and consistently enhance Fullbay’s security program utilizing NIST CSF 2.0 as the governance framework and CIS Controls v8.1 (IG1 to IG2) as the tactical execution guide.

• Oversee Fullbay’s always-on MDR platform and act as the main responder for escalated alerts.

• Investigate, contain, and resolve confirmed security incidents, including participating in an on-call rotation for high-severity escalations.

• Lead SOC 2 readiness initiatives, including control mapping, evidence gathering, gap remediation, and coordination with audit firms for Type I and Type II engagements.

• Manage and configure the security tooling ecosystem, including MDR, MDM, email security, anti-phishing, and security awareness tools.

• Draft, maintain, and enforce information security policies, standards, and procedures.

• Supervise IAM posture across Google Workspace, encompassing passkeys, MFA, SSO, privileged access controls, MDM, and Apple Business Manager configuration.

• Develop and own the incident response strategy and lead post-incident evaluations.

• Maintain a risk register, monitor security risks, and communicate risk posture to the VP of IT and senior leadership.

• Oversee security awareness training, phishing simulations, and compliance-related training cycles.

• Evaluate third-party vendor security posture, maintain a vendor risk inventory, and drive remediation efforts.

• Act as the primary escalation point for company-wide end-user technical support.

• Manage procurement, provisioning, deprovisioning, imaging, configuration, and asset inventory for company devices.

• Oversee user provisioning, licensing, and configuration across Google Workspace and other essential SaaS applications.

• Manage IT onboarding and offboarding processes, including account creation, device setup, access provisioning, and timely access removal.

• Handle IT vendor relationships and contracts, evaluate tools, and manage IT expenditures.

• Comply with confidentiality and regulatory requirements and perform other assigned duties.


⛳️ Requirements

• 7-10 years of cumulative experience in IT operations and security, cybersecurity, or information security is required; 10+ years is preferred.

• Proven experience managing and responding to alerts from an MDR/EDR platform, including triage, investigation, and remediation of confirmed incidents, is essential.

• Demonstrated experience leading a compliance or regulatory program (SOC 2, ISO 27001, HIPAA, PCI-DSS, or equivalent) is required.

• Bachelor’s degree in Information Security, Computer Science, Information Systems, or a related field, or equivalent professional experience.

• Practical experience administering Google Workspace, MDM platforms (e.g., NinjaOne, Apple Business Manager), and providing general end-user IT support is mandatory.

• Extensive knowledge of security frameworks, including NIST CSF 2.0 and CIS Controls v8.1.

• Familiarity with MDR/EDR platforms and MDM solutions, with the capability to investigate and respond to escalated alerts.

• Required platform experience includes Google Workspace administration and security configuration, Apple Business Manager (ABM), and NinjaOne endpoint management.

• Preferred platform experience includes Proofpoint email security and Ironscales anti-phishing.

• Solid understanding of IAM concepts, including SSO, MFA, passkeys, and privileged access management.

• Ability to function as a player-coach: design the security program, establish standards, and personally execute tasks.

• Excellent written and verbal communication skills, with the capability to present security risks and program status to executive leadership.

• Experience collaborating cross-functionally with Engineering, Legal, Finance, and business stakeholders.

• Preferred certifications include CISSP, CISM, CISA, CCSP, CompTIA Security+, or CASP+.

• Strong general IT troubleshooting abilities across Mac and Windows environments, networking fundamentals, and common business SaaS applications.

• Familiarity with IT ticketing/helpdesk systems and asset management tools.

• Capacity to meet stated physical demands, including regularly sitting at a desk, using computer and telephone equipment, and lifting/moving up to 10 pounds.


🏝️ Benefits

• Competitive salary with performance-based incentives.

• Comprehensive health, dental, and vision insurance packages.

• Flexible working hours and remote work options.

• Opportunities for professional development and continuing education.

• Supportive and inclusive work environment.

People also viewed

Integrity36010 hours ago

Security Engineer

UA flagUkraine OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Rackspace Technology10 hours ago

Security Engineer IV

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$119.6k – $175.4k/year
ApplyView job
Efficient Computer10 hours ago

Director of Information Security

US flagCalifornia, +2 more statesFull-timeCybersecurity / Security Engineer$180k – $230k/year
ApplyView job
Presidio10 hours ago

Senior Director, Cybersecurity Advisory Services

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Presidio10 hours ago

Senior Director, Cybersecurity Advisory Services

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
XBOX10 hours ago

Senior Security Engineer

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$102.8k – $190.2k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers