Head of IT & Security

Fullbay • $125K — $150K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7-10 years of experience in IT operations and security; 10+ years preferred.
  • Experience managing alerts from an MDR/EDR platform, including incident triage and remediation.
  • Proven track record in owning compliance programs like SOC 2, ISO 27001, or HIPAA.
  • Bachelor's degree in Information Security, Computer Science, or related field, or equivalent experience.
  • Hands-on experience with Google Workspace and MDM platforms.

Responsibilities

  • Design and build Fullbay's security program using NIST CSF 2.0 and CIS Controls v8.1.
  • Manage the MDR platform for automated threat detection and serve as primary responder for escalated alerts.
  • Lead SOC 2 readiness activities, including control mapping and audit coordination.
  • Oversee and configure security tools, ensuring they meet Fullbay standards.
  • Develop and enforce information security policies and procedures across the organization.
  • Maintain IAM posture, including MFA and privileged access controls.
  • Own the incident response plan and lead post-incident reviews.
  • Communicate risk posture to senior leadership and maintain a risk register.

Benefits

  • Flexible work environment with opportunities for remote work.
  • Professional development and training opportunities.
  • Health and wellness programs.
  • Generous PTO and holiday schedule.
  • Collaborative and innovative company culture.
Full Job Description
Head of IT & Security

Position Overview:

Fullbay's Security and IT Manager owns two functions that are usually split across two people: the security program that keeps Fullbay's systems, people, and customer data safe, and the IT operations that keep the business running day to day. Reporting to the VP of IT, this role designs the security and IT program from the ground up and owns its execution end-to-end - there's no existing playbook to inherit and no separate team to hand the work to.

This role is well-suited to someone who has built a security program before, not just operated inside one - someone comfortable being the primary responder when an MDR alert escalates, the person who leads SOC 2 through an actual audit, and the same person who's also the company's escalation point when someone's laptop won't image. This is a player-coach role: you set the standards, and you personally execute the work.

Success here looks like passing SOC 2 audits with no major findings, on schedule; security incidents that get triaged, contained, and resolved fast enough that they stay incidents, not breaches; IT support that doesn't make employees wait, with devices provisioned before day one and tickets closed without a saga; and a risk posture leadership can see clearly at any time, not just when an audit forces the question.

The Right Wrench for the Job

A shop's most dangerous moments are never the ones people see coming. The person who wires the electrical panel, checks the fire suppression, and makes sure the alarm actually calls someone when it goes off isn't thinking about any one repair - they're thinking about what keeps the whole building standing. This role does that for Fullbay's systems and data, and then still picks up the phone when someone's laptop won't turn on.

You're the right fit if you've built a security program from a blank page before - not just operated inside one someone else designed - and you know the difference between a control that looks good on paper and one that actually holds up when an auditor or an attacker tests it. You can walk into a SOC 2 evidence review in the morning, triage a real MDR alert at noon, and still be the person who gets a new hire's laptop imaged and ready before their first day.

This isn't the role for someone who wants to own strategy and hand off the keyboard. If your instinct is to write the policy and let someone else enforce it, this isn't your shop. But if you're the kind of person who'll design the program, defend it to an auditor, and still crawl under the desk to fix a network cable - we'd like to talk.

Primary Duties & Responsibilities:
  • Security Program Ownership: Design, build, and continuously improve Fullbay's security program using NIST CSF 2.0 as the governance architecture and CIS Controls v8.1 (IG1 to IG2) as the tactical execution roadmap.
  • Security Operations Oversight: Manage Fullbay's always-on MDR platform, which provides automated threat detection and triage across endpoints and cloud environments. Serve as the primary responder for escalated alerts requiring human judgment, and lead investigation, containment, and remediation for confirmed incidents, including participation in an on-call rotation for high-severity escalations.
  • SOC 2 Readiness and Audit Management: Lead all SOC 2 readiness activities including control mapping, evidence collection, gap remediation, and audit firm coordination for Type I and Type II engagements.
  • Tool and Platform Governance: Own and configure Fullbay's security tooling stack, including the MDR platform, MDM, email security, anti-phishing, and security awareness training. Tune and maintain tools to Fullbay standards, and evaluate new tools or vendors as needed.
  • Policy and Standards Development: Author, maintain, and enforce information security policies, standards, and procedures across the organization. Ensure policies align with regulatory requirements and audit frameworks.
  • Identity and Access Management: Oversee IAM posture across Google Workspace, including passkeys, MFA, SSO, and privileged access controls, including MDM and Apple Business Manager configuration.
  • Incident Response: Develop and own the incident response plan. Serve as the primary responder for security events escalated by the MDR platform or identified through other internal monitoring. Lead response activities and post-incident reviews.
  • Risk Management: Maintain a risk register. Identify, assess, and track security risks across people, process, and technology. Communicate risk posture to the VP of IT and senior leadership.
  • Security Awareness: Oversee the security awareness training program, including phishing simulations and compliance-based training cycles.
  • Vendor and Third-Party Risk: Assess security posture of third-party vendors and new software applications. Maintain a vendor risk inventory and drive remediation for identified gaps.
  • End-User IT Support: Serve as the primary escalation point for company-wide technical support, resolving hardware, software, network, and account issues for employees across the organization.
  • Device & Asset Lifecycle Management: Own procurement, provisioning, and deprovisioning of company devices, coordinating imaging and configuration through Apple Business Manager and NinjaOne, and maintaining an accurate IT asset inventory.
  • SaaS Application Administration: Manage user provisioning, licensing, and configuration across Fullbay's core SaaS applications, including Google Workspace and other business tools, ensuring accounts are created, modified, and deactivated promptly.
  • Onboarding & Offboarding: Own the IT components of employee onboarding and offboarding, including account creation, device setup, access provisioning, and timely access removal.
  • IT Vendor & Procurement Management: Manage relationships and contracts with IT vendors and service providers, evaluate new tools, and control IT spend.
  • Adheres to all confidentiality and compliance regulations.
  • Performs other duties as assigned.

Minimum Education & Work Experience:
  • 7-10 years of combined experience across IT operations and security, cybersecurity, or information security required; 10+ years preferred.
  • Experience managing and responding to alerts from an MDR/EDR platform, including triage, investigation, and remediation of confirmed incidents, required.
  • Demonstrated experience owning a compliance or regulatory program (SOC 2, ISO 27001, HIPAA, PCI-DSS, or equivalent) required.
  • SOC 2 audit experience (Type I or Type II) strongly preferred.
  • Bachelor's degree in Information Security, Computer Science, Information Systems, or a related field, or equivalent work experience.
  • Hands-on experience administering Google Workspace, MDM platforms (e.g., NinjaOne, Apple Business Manager), and providing general end-user IT support required.

Key Skills and Qualifications:
  • Deep knowledge of security frameworks including NIST CSF 2.0 and CIS Controls v8.1.
  • Working knowledge of MDR/EDR platforms and MDM solutions, with the ability to investigate and respond to escalated alerts.
  • Required platform experience: Google Workspace administration and security configuration, Apple Business Manager (ABM), NinjaOne endpoint management.
  • Preferred platform experience: Proofpoint email security, Ironscales anti-phishing.
  • Strong understanding of IAM concepts including SSO, MFA, passkeys, and privileged access management.
  • Ability to operate as a player-coach: design the security program, set the standards, and personally execute the work.
  • Strong written and verbal communication skills with the ability to present security risk and program status to executive leadership.
  • Experience working cross-functionally with Engineering, Legal, Finance, and business stakeholders.
  • Preferred certifications: CISSP, CISM, CISA, CCSP, CompTIA Security+, or CASP+.
  • Strong general IT troubleshooting skills across Mac and Windows environments, networking fundamentals, and common business SaaS applications.
  • Experience with IT ticketing/helpdesk systems and asset management tools.

Physical Demands and Work Environment:

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions
  • Regularly required to sit at a desk in front of a computer and use hands to finger, handle, or feel objects, tools, or controls (including a computer keyboard and operating a telephone), lift and/or move up to 10 pounds.
  • Frequently requires the use of hands and arms for reaching, as well as the ability to walk and communicate effectively through speaking and listening.
  • Specific vision abilities required by this position include close vision, color vision, and the ability to adjust focus.
  • Noise level in the work environment is usually moderate.
  • Type on a computer keyboard and look at a computer monitor, and operate a cell phone or a computer-based phone

About Fullbay

Fullbay is a cloud-based software solution for heavy-duty truck repair shops. The platform provides tools for managing repair orders, inventory, invoicing, and more. Fullbay's customers include independent repair shops, dealerships, and fleets.
Learn more about Fullbay
Size
50 employees
Industry
Net Income
-$1 million
Founded
2015
5 Year Trend
+30%
Revenue
$5 million

Similar Jobs

More Jobs at Fullbay

  • Lead Data Engineer
    $120K — $145K *
    Phoenix, AZ 85032 (Maricopa County)
    Information Technology
    In-Person
  • Head of IT & Security
    $125K — $150K *
    Phoenix, AZ 85032 (Maricopa County)
    Information Technology
    In-Person
  • Paid Media Manager
    $80K — $95K *
    Phoenix, AZ 85032 (Maricopa County)
    Enterprise Technology
    In-Person

More Information Technology Jobs

Find similar Head of IT & Security jobs: