Manager of Security & IT
EngineeringSecurity
2 views0 saves0 applied
Quick Summary
Key Responsibilities
Security Leadership & Incident Response Lead Fabric's security program across application security, security operations, identity and access management, endpoint security, cloud security,
Requirements Summary
set the program and do the work. This is not a del
Technical Tools
EngineeringSecurity
About the Role
~1 min readScaling security in a regulated environment requires a leader who sets the high-level strategy and actively builds alongside their team rather than leading from a distance. As the Manager of Security and IT, you run security operations and own corporate IT for a healthcare technology company handling PHI at scale. You partner closely with the compliance program owner to uphold HIPAA and SOC2 standards, serving as the influential voice on what security investments matter and what can wait. This is a highly hands-on role where you do not just delegate; you influence policy, run identity, own the endpoint program, lead incident response, and review vendors.
Building and scaling this program starts with managing and mentoring a tight-knit team. Leadership here goes beyond standard management to cultivating a culture of technical innovation. You bring an engineering mindset to IT operations by developing custom AI tools, agents, and automation pipelines that bypass standard vendor limitations. More importantly, you serve as a technical mentor, coaching your team to build their own AI competencies so they can architect internal tools that multiply the entire department's impact.
Responsibilities
~1 min readAs the Manager of Security and IT, you operate as a hands-on leader. Your primary responsibilities include:
Security Leadership & Incident Response
- →Lead Fabric's security program across application security, security operations, identity and access management, endpoint security, cloud security, and vendor security.
- →Own incident response end-to-end, covering detection, triage, response, post-mortems, and the structural improvements that follow.
- →Lead customer security questionnaire responses and vendor security reviews, acting as a credible authority who can speak to a CISO at a health system and earn their trust.
- →Set security policies and standards that engineering, product, and operations can practically follow.
- →Represent security in executive conversations about risk, investment, and technical tradeoffs.
Corporate IT & AI Automation
- →Own corporate IT operations, including the identity platform (Okta or equivalent), MDM, endpoint management, helpdesk, hardware, and SaaS provisioning.
- →Build and deploy custom AI tools, agents, and automated workflows to scale IT and security operations, moving beyond standard vendor defaults.
Team Leadership & Compliance
- →Manage and mentor a team of three direct reports, helping them grow their careers and empowering them to integrate AI into their daily workflows.
- →Partner with the owner of our compliance program to feed evidence, implement controls, and operationalize SOC2, HITRUST, and HIPAA requirements without bottlenecking either side.
- You bring seasoned security expertise, combining proven leadership experience with an extensive, hands-on background across security operations.
- You have actually run corporate IT, not just had it report to you. You know what good identity hygiene looks like, you have debugged endpoint issues yourself, and you have handled an offboarding crisis at 9 p.m.
- You can do both: set the program and do the work. This is not a delegate-everything role at this stage.
- You think identity-first. Most security failures route through identity, and you build defenses with that as the starting assumption.
- You have worked in healthcare or another regulated industry where the rules genuinely matter and audits are part of the rhythm.
- You can talk to engineers without losing them and to executives without confusing them.
- You are a passionate AI practitioner who has proven experience building custom AI workflows, agents, and automation tools to solve complex security and IT challenges.
- You want a pure CISO seat where you set policy and someone else implements. We are too early for a delegate-everything role.
- You have not actually run corporate IT before. Reporting to you is not the same as having done the work.
- You are uncomfortable being the security and IT person. This is a dual-hat role and stays that way until we are larger.
- You need a fully built program. We have foundations but not maturity; you will be building.
- You prefer strictly out-of-the-box vendor configurations over engineering custom AI-driven automation.
Requirements
~1 min read- 7+ years of security experience with at least 2 years in a security leadership or management role.
- Direct experience managing corporate IT operations, including identity, endpoint, MDM, SaaS provisioning, and the helpdesk.
- Proven application security or cloud security background. You will partner closely with our Application Security Engineer and must possess the technical depth to lead them, not just manage them.
- Experience operating in a healthcare or highly regulated industry environment handling PHI under HIPAA.
- Working knowledge of SOC2 and HIPAA frameworks, with HITRUST familiarity as a plus.
- Management experience overseeing 1 to 3 direct reports, ideally including building a function from a small base and actively guiding career development.
- Proven track record of building and deploying custom AI tools, agents, or automated workflows to streamline IT and security operations.
Nice to Have
~1 min read- Hands-on experience with Okta or another modern IAM/SSO platform.
- AWS or GCP cloud security depth.
- Prior incident response leadership at a healthcare or regulated company.
- HITRUST or NIST 800-66 specific familiarity.
- Experience working with external auditors and assessors.
The national pay range for this role is $160,000.00 – $180,000.00 per year. Actual compensation will be determined by factors such as the candidate's geographic market, experience, skills, and qualifications. Certain roles may also be eligible for additional compensation, including a comprehensive benefits package such as medical, dental, vision, unlimited PTO, and a 401(k) plan, stock options and bonuses. If your compensation requirement is greater than our posted range, please still consider applying; a determination can be made based on unique qualifications. Expected compensation ranges for this role may change over time.
Location & Eligibility
Where is the job
United States
Remote within one country
Who can apply
US
Listing Details
- Posted
- September 29, 2026
- First seen
- September 29, 2026
- Last seen
- September 29, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 66%
- Scored at
- September 29, 2026
Signal breakdown
freshnesssource trustcontent trustemployer trust
Browse Similar Jobs
Devops Engineer3.9kFullstack Developer2.7kEngineering Manager2.2kQa Engineer2kSoftware Architect2kMechanical Engineer1.9kElectrical Engineer1.7kProject Engineer1.6kBackend Developer1.5kSecurity Engineer1.4kDevOps & Infrastructure1.2kFrontend Developer1.2kDesign Engineer1.1kQuality Engineer979Process Engineer865Mobile Developer777Product Engineer745Automation Engineer603Application Engineer601Backend Engineering594
Newsletter
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
A
B
C
D
No spam. Unsubscribe at any time.