Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Fullbay

Head of IT, Security

Fullbay

. Design, build, and continuously improve Fullbay’s security program using NIST CSF 2.0 as the governance architecture and CIS Controls v8.1 (IG1 to IG2) as the tactical execution roadmap .

Posted 10/2/2026full-timeRemote • Arizona • United StatesLead💰 $151,466 - $185,545 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in designing and managing security programs using NIST CSF 2.0 and CIS Controls v8.1, with a strong focus on compliance frameworks such as SOC 2 and ISO 27001. Proficient in Google Workspace administration, incident response, and security awareness training.

Highest-signal resume keywords
NIST CSF 2.0CIS Controls v8.1SOC 2 ComplianceGoogle Workspace AdministrationIncident Response Management

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
MDR/EDR Platform ManagementIAM ConceptsSecurity Policy DevelopmentRisk AssessmentIT Troubleshooting
Soft Skills
Strong Communication SkillsCross-Functional CollaborationPlayer-Coach Leadership
Tools & Technologies
Google WorkspaceApple Business ManagerNinjaOneProofpointIronscales
Certifications & Qualifications
CISSPCISMCISACCSPCompTIA Security+
Industry Keywords
Information SecurityCybersecurityCompliance RegulationsSecurity Awareness TrainingVendor Risk Management

Tech Stack

Tools & technologies
Cyber Security

About the role

Key responsibilities & impact
  • Design, build, and continuously improve Fullbay’s security program using NIST CSF 2.0 as the governance architecture and CIS Controls v8.1 (IG1 to IG2) as the tactical execution roadmap
  • Manage Fullbay’s always-on MDR platform and serve as the primary responder for escalated alerts
  • Investigate, contain, and remediate confirmed security incidents, including participation in an on-call rotation for high-severity escalations
  • Lead SOC 2 readiness activities, including control mapping, evidence collection, gap remediation, and audit firm coordination for Type I and Type II engagements
  • Own and configure the security tooling stack, including MDR, MDM, email security, anti-phishing, and security awareness tools
  • Author, maintain, and enforce information security policies, standards, and procedures
  • Oversee IAM posture across Google Workspace, including passkeys, MFA, SSO, privileged access controls, MDM, and Apple Business Manager configuration
  • Develop and own the incident response plan and lead post-incident reviews
  • Maintain a risk register, track security risks, and communicate risk posture to the VP of IT and senior leadership
  • Oversee security awareness training, phishing simulations, and compliance-based training cycles
  • Assess third-party vendor security posture, maintain a vendor risk inventory, and drive remediation
  • Serve as the primary escalation point for company-wide end-user technical support
  • Own procurement, provisioning, deprovisioning, imaging, configuration, and asset inventory for company devices
  • Manage user provisioning, licensing, and configuration across Google Workspace and other core SaaS applications
  • Own IT onboarding and offboarding, including account creation, device setup, access provisioning, and timely access removal
  • Manage IT vendor relationships and contracts, evaluate tools, and control IT spend
  • Adhere to confidentiality and compliance regulations and perform other duties as assigned

Requirements

What you’ll need
  • 7-10 years of combined experience across IT operations and security, cybersecurity, or information security required; 10+ years preferred
  • Experience managing and responding to alerts from an MDR/EDR platform, including triage, investigation, and remediation of confirmed incidents, required
  • Demonstrated experience owning a compliance or regulatory program (SOC 2, ISO 27001, HIPAA, PCI-DSS, or equivalent) required
  • Bachelor’s degree in Information Security, Computer Science, Information Systems, or a related field, or equivalent work experience
  • Hands-on experience administering Google Workspace, MDM platforms (e.g., NinjaOne, Apple Business Manager), and providing general end-user IT support required
  • Deep knowledge of security frameworks including NIST CSF 2.0 and CIS Controls v8.1
  • Working knowledge of MDR/EDR platforms and MDM solutions, with the ability to investigate and respond to escalated alerts
  • Required platform experience: Google Workspace administration and security configuration, Apple Business Manager (ABM), NinjaOne endpoint management
  • Preferred platform experience: Proofpoint email security, Ironscales anti-phishing
  • Strong understanding of IAM concepts including SSO, MFA, passkeys, and privileged access management
  • Ability to operate as a player-coach: design the security program, set the standards, and personally execute the work
  • Strong written and verbal communication skills with the ability to present security risk and program status to executive leadership
  • Experience working cross-functionally with Engineering, Legal, Finance, and business stakeholders
  • Preferred certifications: CISSP, CISM, CISA, CCSP, CompTIA Security+, or CASP+
  • Strong general IT troubleshooting skills across Mac and Windows environments, networking fundamentals, and common business SaaS applications
  • Experience with IT ticketing/helpdesk systems and asset management tools
  • Ability to meet stated physical demands, including regularly sitting at a desk, using computer and telephone equipment, and lifting/moving up to 10 pounds