IT Manager
Owns corporate security architecture and automation across identity, compliance, endpoint protection, SaaS, and internal IT systems. The role requires 5+ years of security engineering experience, deep IdP design expertise, audit control ownership, and a track record of impactful automation.
About the job
Responsibilities
Identity & Access Management
- Own Okta and Pave's access-management model, including role and group architecture, lifecycle automation, SSO/SCIM, and the exception process.
- Keep the RBAC model current and consistently enforced, using automation to prevent drift.
Compliance Operations
- Own SOC 2 Type II and ISO 27001 controls affecting corporate IT from end to end.
- Automate evidence collection and user access reviews.
Endpoint & SaaS Security
- Own endpoint protection (MDM/EDR) across a five-location, approximately 175-person company.
- Run SaaS vendor security reviews and build shadow-IT visibility.
- Feed IT-controlled data sources into the SIEM.
Automation & AI
- Engineer away manual IT toil, including laptop setup, onboarding and offboarding provisioning, and access requests, using APIs, workflow tooling, and AI agents.
- Build governance for employee-built internal applications, including detection, automated review checks, and sensible sharing models.
Partnership
- Design the systems operated day to day by Pave's helpdesk.
- Serve as the design counterpart who makes the helpdesk team stronger and more self-sufficient.
Requirements
- 5+ years of hands-on corporate or enterprise security or IT security engineering experience at a multi-office company.
- Okta or equivalent identity-provider administration at the design level; experience building an access model rather than only operating one.
- Experience operating within SOC 2 and/or ISO 27001, including ownership of controls that passed audits.
- Hands-on ownership of MDM/EDR and a Google Workspace-class SaaS estate.
- A track record of shipping automations with concrete before-and-after impact.
- Demonstrated, specific use of AI tooling in personal workflows.
Nice-to-Haves
- Previous management experience.
- Experience progressing from IT/helpdesk into security, or a similar path.
- Experience with Okta, GCP, Iru, SentinelOne, or Claude Code.
- Vendor security review and third-party risk experience.
- Background at a 150–500-person B2B SaaS company handling sensitive data.
- Networking fundamentals.
Compensation & Benefits
- Targeted cash compensation: $220,000+ base, plus equity.
- Meaningful equity.
- Medical, dental, and vision coverage for employees and families.
- Flexible, unlimited PTO and the ability to work from anywhere in the world for up to one month.
- Lunch and dinner stipends and stocked kitchens.
- Quarterly education stipend.
- Robust parental leave.
- Commuter stipend.
Skills
Okta, RBAC, SSO, SCIM, SOC 2, ISO 27001, MDM, Edr, Google Workspace, SIEM, GCP, Sentinelone, Claude Code, AI Agents, Networking
Similar jobs
Security Engineering jobsThe Security Engineer will track advanced adversaries targeting frontier AI infrastructure, build intelligence pipelines, conduct threat hunts, and create production detections. The role requires hands-on malware and infrastructure analysis, production programming, and close collaboration with detection and incident response teams.
This role builds and improves infrastructure security controls across cloud, operating system, Kubernetes, network, and CI/CD environments. It requires cloud security expertise, programming and Infrastructure as Code proficiency, threat-modeling experience, and the ability to lead infrastructure containment during security incidents.
The Red Team Specialist evaluates AI models for cyber capabilities, safeguard failures, and agentic-system abuse risks. The role combines hands-on security testing, automated evaluation infrastructure, risk assessment, and cross-functional communication.
Build and operate trust and safety systems that detect and mitigate abuse at internet scale. The role combines security engineering, large-scale data analysis, and applied LLM techniques, requiring 5+ years of relevant experience and strong Python and JavaScript/TypeScript skills.
Leads and develops a security incident response team while driving automation, AI-assisted workflows, operational maturity, and response strategy. The role requires 5+ years of incident response experience, people leadership, technical depth, and calm management of high-severity incidents.