Stop applying to remote jobs that are already dead.
Every listing checked, aged honestly, expired when filled.

All listings

Fullbay via Bamboohr

Head of IT & Security

United States head
still open verified 2h ago posted 1d ago seen just now
Apply at fullbay.bamboohr.com

This is the employer's own posting, not a copy on a job board.

What we know

Is it still open?

Confirmed still open

Last checked 2h ago — checked against the employer's own applicant tracking system, which is the company answering directly.

We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.

Check this listing's status as JSON

How old is it?

Posted 1d ago

The date the source published, not the day we noticed it (2026-10-02). Last seen at its source just now.

Is it remote?

Marked remote on the employer's board

Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.

Who may apply?

United States

The description states no restriction of its own. This is the source's own tag.

Skills named in the ad

Escalation ManagementHIPAAISO 27001Incident ManagementOnboardingPCI DSSProcurementRisk ManagementSOC 2SSOSparkTechnical SupportTroubleshooting

Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.

Carried by 1 source

The listing

Head of IT & Security 


About us:

At Fullbay, our mission is simple — to create safer roads for our families and yours. As leaders in the heavy-duty repair industry, we power shops with technology that helps them run smarter and more efficiently. As an AI-First company, we invite artificial intelligence to eliminate friction, spark innovation, and drive efficiencies in every conversation— for our teams and our customers. Fullbay is the number one cloud-based shop management software for commercial repair shops and is growing fast. This is an exciting opportunity to join a high-performing team and help shape the next phase of growth for the company.

Position Overview:

Fullbay's Security and IT Manager owns two functions that are usually split across two people: the security program that keeps Fullbay's systems, people, and customer data safe, and the IT operations that keep the business running day to day. Reporting to the VP of IT, this role designs the security and IT program from the ground up and owns its execution end-to-end — there's no existing playbook to inherit and no separate team to hand the work to.


This role is well-suited to someone who has built a security program before, not just operated inside one — someone comfortable being the primary responder when an MDR alert escalates, the person who leads SOC 2 through an actual audit, and the same person who's also the company's escalation point when someone's laptop won't image. This is a player-coach role: you set the standards, and you personally execute the work.


Success here looks like passing SOC 2 audits with no major findings, on schedule; security incidents that get triaged, contained, and resolved fast enough that they stay incidents, not breaches; IT support that doesn't make employees wait, with devices provisioned before day one and tickets closed without a saga; and a risk posture leadership can see clearly at any time, not just when an audit forces the question.


The Right Wrench for the Job

A shop's most dangerous moments are never the ones people see coming. The person who wires the electrical panel, checks the fire suppression, and makes sure the alarm actually calls someone when it goes off isn't thinking about any one repair — they're thinking about what keeps the whole building standing. This role does that for Fullbay's systems and data, and then still picks up the phone when someone's laptop won't turn on.

You're the right fit if you've built a security program from a blank page before — not just operated inside one someone else designed — and you know the difference between a control that looks good on paper and one that actually holds up when an auditor or an attacker tests it. You can walk into a SOC 2 evidence review in the morning, triage a real MDR alert at noon, and still be the person who gets a new hire's laptop imaged and ready before their first day.

This isn't the role for someone who wants to own strategy and hand off the keyboard. If your instinct is to write the policy and let someone else enforce it, this isn't your shop. But if you're the kind of person who'll design the program, defend it to an auditor, and still crawl under the desk to fix a network cable — we'd like to talk.



Primary Duties & Responsibilities:

  • Security Program Ownership: Design, build, and continuously improve Fullbay’s security program using NIST CSF 2.0 as the governance architecture and CIS Controls v8.1 (IG1 to IG2) as the tactical execution roadmap.
  • Security Operations Oversight: Manage Fullbay’s always-on MDR platform, which provides automated threat detection and triage across endpoints and cloud environments. Serve as the primary responder for escalated alerts requiring human judgment, and lead investigation, containment, and remediation for confirmed incidents, including participation in an on-call rotation for high-severity escalations.
  • SOC 2 Readiness and Audit Management: Lead all SOC 2 readiness activities including control mapping, evidence collection, gap remediation, and audit firm coordination for Type I and Type II engagements.
  • Tool and Platform Governance: Own and configure Fullbay’s security tooling stack, including the MDR platform, MDM, email security, anti-phishing, and security awareness training. Tune and maintain tools to Fullbay standards, and evaluate new tools or vendors as needed.
  • Policy and Standards Development: Author, maintain, and enforce information security policies, standards, and procedures across the organization. Ensure policies align with regulatory requirements and audit frameworks.
  • Identity and Access Management: Oversee IAM posture across Google Workspace, including passkeys, MFA, SSO, and privileged access controls, including MDM and Apple Business Manager configuration.
  • Incident Response: Develop and own the incident response plan. Serve as the primary responder for security events escalated by the MDR platform or identified through other internal monitoring. Lead response activities and post-incident reviews.
  • Risk Management: Maintain a risk register. Identify, assess, and track security risks across people, process, and technology. Communicate risk posture to the VP of IT and senior leadership.
  • Security Awareness: Oversee the security awareness training program, including phishing simulations and compliance-based training cycles.
  • Vendor and Third-Party Risk: Assess security posture of third-party vendors and new software applications. Maintain a vendor risk inventory and drive remediation for identified gaps.
  • End-User IT Support: Serve as the primary escalation point for company-wide technical support, resolving hardware, software, network, and account issues for employees across the organization.
  • Device & Asset Lifecycle Management: Own procurement, provisioning, and deprovisioning of company devices, coordinating imaging and configuration through Apple Business Manager and NinjaOne, and maintaining an accurate IT asset inventory.
  • SaaS Application Administration: Manage user provisioning, licensing, and configuration across Fullbay’s core SaaS applications, including Google Workspace and other business tools, ensuring accounts are created, modified, and deactivated promptly.
  • Onboarding & Offboarding: Own the IT components of employee onboarding and offboarding, including account creation, device setup, access provisioning, and timely access removal.
  • IT Vendor & Procurement Management: Manage relationships and contracts with IT vendors and service providers, evaluate new tools, and control IT spend.
  • Adheres to all confidentiality and compliance regulations.
  • Performs other duties as assigned.

Minimum Education & Work Experience:

  • 7-10 years of combined experience across IT operations and security, cybersecurity, or information security required; 10+ years preferred.
  • Experience managing and responding to alerts from an MDR/EDR platform, including triage, investigation, and remediation of confirmed incidents, required.
  • Demonstrated experience owning a compliance or regulatory program (SOC 2, ISO 27001, HIPAA, PCI-DSS, or equivalent) required.
  • SOC 2 audit experience (Type I or Type II) strongly preferred.
  • Bachelor’s degree in Information Security, Computer Science, Information Systems, or a related field, or equivalent work experience.
  • Hands-on experience administering Google Workspace, MDM platforms (e.g., NinjaOne, Apple Business Manager), and providing general end-user IT support required.

Key Skills and Qualifications:

  • Deep knowledge of security frameworks including NIST CSF 2.0 and CIS Controls v8.1.
  • Working knowledge of MDR/EDR platforms and MDM solutions, with the ability to investigate and respond to escalated alerts.
  • Required platform experience: Google Workspace administration and security configuration, Apple Business Manager (ABM), NinjaOne endpoint management.
  • Preferred platform experience: Proofpoint email security, Ironscales anti-phishing.
  • Strong understanding of IAM concepts including SSO, MFA, passkeys, and privileged access management.
  • Ability to operate as a player-coach: design the security program, set the standards, and personally execute the work.
  • Strong written and verbal communication skills with the ability to present security risk and program status to executive leadership.
  • Experience working cross-functionally with Engineering, Legal, Finance, and business stakeholders.
  • Preferred certifications: CISSP, CISM, CISA, CCSP, CompTIA Security+, or CASP+.
  • Strong general IT troubleshooting skills across Mac and Windows environments, networking fundamentals, and common business SaaS applications.
  • Experience with IT ticketing/helpdesk systems and asset management tools.

Physical Demands and Work Environment:

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions

  • Regularly required to sit at a desk in front of a computer and use hands to finger, handle, or feel objects, tools, or controls (including a computer keyboard and operating a telephone), lift and/or move up to 10 pounds. 
  • Frequently requires the use of hands and arms for reaching, as well as the ability to walk and communicate effectively through speaking and listening.
  • Specific vision abilities required by this position include close vision, color vision, and the ability to adjust focus.   
  • Noise level in the work environment is usually moderate.
  • Type on a computer keyboard and look at a computer monitor, and operate a cell phone or a computer-based phone
Apply at fullbay.bamboohr.com