5-7 years of hands-on experience in IT operations and endpoint management
Proven ability to triage security alerts and identify genuine threats
Experience with Google Workspace and similar SaaS tools
Familiarity with phishing investigation techniques and email security tools
Capability to take immediate containment actions during security incidents
Responsibilities
Own the onboarding and offboarding process for accounts and devices
Administer core tools like Google Workspace, Slack, and GitHub
Manage identity and access management (IAM) workflows
Oversee the hardware lifecycle from procurement to secure disposal
Triage security alerts from various security tools
Lead the response to phishing incidents and coordinate communications
Deploy and maintain VPN and Zero Trust security solutions
Benefits
Opportunity to shape the IT and security landscape from the ground up
Collaborative work environment with Engineering and leadership
Ownership of security operations and incident response
Engagement in meaningful security challenges
Potential for professional growth in a dynamic setting
Full Job Description
About the Role
We're hiring our first onsite IT & Security Operations Specialist to own internal IT operations and serve as our first line of security defense. You'll ensure every teammate is securely onboarded with the right access and equipment while proactively triaging security alerts and investigating threats. Reporting to the Head of Engineering, you'll work closely with Engineering and leadership to keep our systems reliable, endpoints healthy, and identity layer secure.
What You'll Do
Own end-to-end onboarding and offboarding: accounts, MFA, device setup, and access removal
Administer core tools including Google Workspace, Slack, GitHub, Notion, and Linear
Manage IAM: least-privilege access, role-based permissions, and joiner/mover/leaver workflows
Oversee hardware lifecycle from ordering and imaging through to secure disposal
Triage and respond to security alerts from email security tooling, EDR, and SaaS audit logs
Lead phishing response: analyze suspicious emails, contain threats, and coordinate user communications
Deploy and maintain VPN and Zero Trust solutions
What We're Looking For
Must-haves:
Hands-on experience with IT operations, endpoint management, and IAM workflows
Proven ability to triage security alerts and distinguish false positives from real incidents
Experience administering Google Workspace and similar SaaS toolsets
Familiarity with phishing investigation and email security tools
Ability to take immediate containment actions: disabling accounts, isolating endpoints, blocking domains
Nice-to-haves:
Experience deploying or managing Zero Trust or VPN solutions
Background working within a SOC or security operations function
This Is For You If...
You find satisfaction in structured ops work and want real security ownership from day one. You want a role where fast, decisive incident response is part of the job description. You thrive working cross-functionally with Engineering and leadership on meaningful security problems.
This Is Not You If...
You prefer deep specialization over a role that blends IT operations and security response. You want a high-volume SOC environment with dedicated tooling and a large security team. Ambiguity in processes frustrates you - we're still building and improving as we go.