Security & IT Manager
New
P
PasitoSecurity compliance
Work from anywhere in Latin America, Strong overlap with U.S. business hours.Full-TimeManager
Salary70,000 - 90,000 USD per year
Apply NowOpens the employer's application page
Job Details
- Languages
- Excellent written and verbal English communication.
- Experience
- 5+ years in security, IT, or GRC
- Required Skills
- HIPAA
Requirements
- Have 5+ years of experience in security, IT, or GRC.
- Have personally owned at least one full SOC 2 Type II cycle end to end.
- Have hands-on experience running IT operations at a startup or growth-stage company.
- Have experience with identity and access management, SSO, MDM, and SaaS administration.
- Have operated a compliance automation platform in production, such as Vanta, Drata, or Secureframe.
- Be able to read penetration-test reports, assess severity, and work credibly with engineers on remediation.
- Have strong project-management skills, including keeping cross-functional work moving with clear owners and deadlines.
- Have excellent written and verbal English communication skills.
- Be highly organized and deadline-driven.
- Be based in Latin America, with strong overlap with U.S. business hours.
- Nice to have: CISA, CISSP, or ISO 27001 Lead Auditor certification.
- Nice to have: Healthcare, HIPAA, or benefits/insurance industry experience.
- Nice to have: Experience at an early- or growth-stage B2B SaaS company selling to enterprise or regulated buyers.
Responsibilities
- Direct IT operations, including domain management, Google Workspace, and the broader platform portfolio.
- Oversee identity and permission governance, onboarding and offboarding, and organizational hardware through the MDM solution.
- Operate Vanta, manage SOC 2 Type II audits, maintain HIPAA alignment, and coordinate annual penetration testing.
- Evaluate third-party vendors and subprocessors, manage related DPAs and BAAs, and maintain policies, risk reviews, training, and trust resources.
- Establish AI risk governance models and monitor third-party artificial intelligence platform integration.
- Partner with legal advisors and leadership to identify, assess, and communicate security and compliance risks.
- Coordinate vulnerability, audit-item, and testing-finding remediation with software engineering teams.
- Lead cross-functional operational security projects and manage roadmaps, dependencies, and deliverables.
- Complete SIG, CAIQ, and custom client security questionnaires, coordinating complex queries with technical leads.
- Coordinate security-adjacent personnel operations with HR, including background verifications, policy sign-offs, training, and lifecycle checklists.
View Full Description & ApplyYou'll be redirected to the employer's site