
Security & IT Manager
Posted 20 hours ago

Posted 20 hours ago
This is a fully remote position, open to applicants in Latin America.
• Oversee Pasito’s comprehensive security, IT, and compliance program from start to finish.
• Manage domain administration, Google Workspace, and the wider platform portfolio.
• Supervise SSO, MFA, role-based access controls, least-privilege architecture, and conduct quarterly access reviews.
• Lead the processes for onboarding and offboarding, including managing access provisioning and revocation.
• Administer organizational hardware through MDM, encompassing enrollment, encryption, patching, endpoint protection, and inventory management.
• Act as the main point of contact for internal IT-related issues and access requests.
• Ensure smooth daily operations of Vanta and maintain audit trails.
• Oversee the annual SOC 2 Type II audit and manage relationships with external auditors.
• Guarantee HIPAA compliance, manage BAAs, and uphold operational policies.
• Coordinate annual penetration testing, including remediation efforts and preparation of client packages.
• Evaluate security risks associated with third-party vendors and subprocessors, and manage DPAs and BAAs.
• Propel updates to policies, conduct risk reviews, provide security training, and maintain trust resources.
• Establish governance for AI security risks and monitor third-party AI integrations.
• Collaborate with legal and leadership teams to address security and compliance risks.
• Maintain an organizational risk log and report on security posture to leadership.
• Work closely with engineering to address vulnerabilities, audit findings, and testing results.
• Lead cross-functional operational security projects, including roadmaps, dependencies, and deliverables.
• Manage security responses for sales operations, including SIG, CAIQ, and client questionnaires.
• Work with HR on background checks, policy acknowledgments, security training, and lifecycle checklists.
• Cultivate a practical, security-oriented culture within the organization.
• A minimum of 5 years of experience in security, IT, or GRC.
• Proven experience managing at least one complete SOC 2 Type II cycle from start to finish.
• Practical experience in IT operations within startup or growth-stage environments.
• Familiarity with identity and access management, SSO, MDM, and SaaS administration.
• Hands-on experience with Vanta, Drata, or Secureframe in a production setting.
• Technical proficiency in interpreting penetration-test reports, evaluating severity, and collaborating with engineers on remediation.
• Strong project management capabilities.
• Exceptional written and verbal communication skills in English.
• Highly organized with a strong focus on meeting deadlines.
• Located in Latin America with significant availability during U.S. business hours.
• Certifications such as CISA, CISSP, or ISO 27001 Lead Auditor are advantageous.
• Experience in the healthcare, HIPAA, or benefits/insurance sectors is a plus.
• Background in an early- or growth-stage B2B SaaS organization catering to enterprise or regulated markets is a plus.
• Competitive compensation, with salary benchmarks aligned to your market, paid in USD.
• Flexibility to work remotely from anywhere in Latin America.
• Budget for learning and development, covering certifications, courses, books, or conferences.
• Annual team offsites for in-person collaboration.
• Strategic visibility and close collaboration with leadership, HR, legal, and sales teams.
• Opportunity to build the security, IT, and compliance function from the ground up.
• Potential for growth as the company expands.
• Paid time off (PTO).
Nadia Care
Corelion
Tenthpin
Get handpicked remote jobs straight to your inbox weekly.