FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in managing security, IT, and compliance programs, with a focus on SOC 2 Type II audits, identity and access management, and risk governance. Proven ability to lead cross-functional projects and maintain organizational security posture while fostering a security-focused culture.
Highest-signal resume keywords
SOC 2 Type II Audit ManagementIdentity And Access ManagementVanta OperationsProject ManagementHIPAA Compliance
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security Program ManagementAccess ProvisioningPenetration TestingMDM ManagementSaaS AdministrationRole-Based ControlsLeast-Privilege ArchitectureRisk AssessmentTechnical RemediationAudit Trail Maintenance
Soft Skills
Excellent CommunicationHighly OrganizedDeadline-Driven
Tools & Technologies
Google WorkspaceVantaDrataSecureframeMDM Solutions
Certifications & Qualifications
CISACISSPISO 27001 Lead Auditor
Industry Keywords
HealthcareHIPAAGRCB2B SaaSRegulated Buyers
About the role
Key responsibilities & impact- Own Pasito’s security, IT, and compliance program end to end
- Direct domain management, Google Workspace, and the broader platform portfolio
- Oversee SSO, MFA, role-based controls, least-privilege architecture, and quarterly access reviews
- Lead onboarding and offboarding, including access provisioning and revocation
- Manage organizational hardware through MDM, including enrollment, encryption, patching, endpoint protection, and inventory
- Serve as the primary contact for internal IT issues and access requests
- Maintain daily Vanta operations and audit trails
- Manage the annual SOC 2 Type II audit and external auditor relationships
- Ensure HIPAA alignment, BAAs, and operational policies
- Facilitate annual penetration testing through remediation and client package preparation
- Assess third-party vendor and subprocessor security risk and manage DPAs and BAAs
- Drive policy updates, risk reviews, security training, and trust-resource maintenance
- Establish AI security risk governance and monitor third-party AI integrations
- Partner with legal and leadership on security and compliance risks
- Maintain the organizational risk log and report security posture to leadership
- Partner with engineering to remediate vulnerabilities, audit items, and testing findings
- Lead cross-functional operational security projects, roadmaps, dependencies, and deliverables
- Manage sales security responses, including SIG, CAIQ, and client questionnaires
- Coordinate with HR on background checks, policy sign-offs, security training, and lifecycle checklists
- Foster a practical, security-focused culture
Requirements
What you’ll need- 5+ years in security, IT, or GRC
- Personally owned at least one full SOC 2 Type II cycle end to end
- Hands-on startup or growth-stage IT operations experience
- Experience with identity and access management, SSO, MDM, and SaaS administration
- Production experience operating Vanta, Drata, or Secureframe
- Technical ability to read penetration-test reports, assess severity, and work with engineers on remediation
- Strong project-management skills
- Excellent written and verbal English communication
- Highly organized and deadline-driven
- Based in Latin America with strong overlap with U.S. business hours
- CISA, CISSP, or ISO 27001 Lead Auditor certification is a plus
- Healthcare, HIPAA, or benefits/insurance industry experience is a plus
- Experience at an early- or growth-stage B2B SaaS company serving enterprise or regulated buyers is a plus
Benefits
Comp & perks- Competitive compensation, salary benchmarked to your market and paid in USD
- Remote work from anywhere in Latin America
- Learning and development budget for certifications, courses, books, or conferences
- Annual in-person team offsites
- Strategic visibility and close collaboration with leadership, HR, legal, and sales
- Ownership of building the security, IT, and compliance function from the ground up
- Growth opportunities as the company scales
- PTO