> Markdown version of [/jobs/ext/2106188-it-and-security-specialist](https://www.wearedevelopers.com/jobs/ext/2106188-it-and-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT and Security Specialist - **Company:** EPOCH AI, INC. - **Location:** United States (Remote available) - **Experience:** Starter - **Salary:** $125,000.0 - $155,000.0 - **Contract:** Temporary to permanent - **Skills:** Microsoft Access, Artificial Intelligence, Amazon Web Services, Cloud Computing, Cyber Security, Github, Identity and Access Management, Information Technology Operations, Machine Learning, Google Cloud, Gsuite, Devsecops, Airtable - **Published:** August 18, 2026 - **Apply:** https://jobs.lever.co/epoch-ai/d84390c5-cb4e-46f3-9c64-910b7df77f8b/apply?lever-origin=applied&lever-source%5B%5D=BuiltInNationwide ## About the Role * 5+ years of experience in security, DevSecOps, IT operations, or a similar field. * Experience owning security at a medium-sized organisation, rather than only advising on it. * Experience with complex technical and research projects, ideally in the AI space. * Fluency working with engineers. You will write very little code in this role, but you will work closely and constantly with people who do. * Experience running IT or security operations: identity, access, endpoints and cloud. Deep knowledge of Google Workspace administration and AWS IAM is a strong plus. * Comfort holding admin authority and making access decisions without a committee. Familiarity with AI research and with what Epoch does is a plus. If you don't tick all these boxes but think you would be a great fit, please consider applying anyway!, While we welcome applicants from all time zones, we prefer candidates who can overlap with UTC-8 (Pacific Time) and UTC+1 (Central European Time), as most of our staff work in this range of time zones. We also prefer candidates who can travel: we hold three retreats per year, during which we record podcast episodes and other communication efforts. Please submit all of your application materials in English and note that we require professional level English proficiency. ## Description Epoch AI is looking for an IT and Security Specialist to own the systems, accounts and access the whole team depends on, and to set the security standards that protect our research and our data. You would decide who can reach what, run the accounts and tools we all work in, find and fix security risks yourself, and work with our engineers and researchers so that our protocols get followed rather than worked around. About the roleWe want someone who can make Epoch meaningfully harder to attack without slowing the team down. Two things sit at the centre of the job. The first is access: who can reach which systems, and keeping that current as people join, move between projects and leave. The second is security itself, setting the standards and doing the hands-on work to make them real. You would work closely with our engineering and research teams, set standards that work in practice, and own the decisions behind them. Day to day you would be finding and fixing security risks, doing the hands-on work yourself, and making calls on questions like how we implement 2FA. A lot of the job is judging whether a control is worth the friction it adds. Our default is not to add a process unless there is a clear reason for it. You would write very little code in this role, but you would work with engineers constantly. An ideal candidate might have 5+ years across security and IT operations. Security judgement is the part we care most about: a practical, risk-based sense of which threats are worth a control and which are not. Having been the person who owns access at a growing organisation is useful but not essential. We would rather hire someone with strong security instincts who can pick up the access side than the other way round. This role is fully remote, and we are able to hire in most locations between the US Pacific and Central European time zones. We invite anyone who is interested to apply, regardless of background, experience, or credentials. Please do not include a cover letter, photograph, or headshot of yourself, or any personal information that is not relevant to the role for which you're applying (including marital status, age, identity traits, etc.)., * Set our security protocols and keep them current, without adding processes the team does not need. * Identify and remediate security risks: both the hands-on technical work, and making sure engineers and researchers implement security measures correctly. * Own implementation decisions, such as our approach to 2FA, and be able to explain the tradeoffs behind them. * Partner with our engineering and research teams to set security standards that are workable in practice. * Hold us to the standards we set, and keep them light enough that people actually follow them. * Own who can reach what across Google Workspace, GitHub, AWS, Google Cloud, 1Password, Slack and Airtable, and grant, change and remove that access as people join, switch projects or leave. * Hold the admin and owner roles on our core platforms, so that access decisions do not queue behind our COO. * Run our cloud accounts and software subscriptions: new projects, IAM, budgets and quota increases, plus seats, licences, renewals and nonprofit pricing. * Own the technical half of onboarding and offboarding: every account and group a new person needs on their first day, and a clean removal when someone leaves. * Be the first person staff come to when something technical breaks. We are remote, so this is accounts and software rather than deskside hardware., Handle incoming owner relations inquiries about revenue, land, division orders, JIB, A/R, and A&P. Log and follow up cases in a tracking system, build trusting client relationships, manage difficult situations calmly, provide accurate timely responses, and participate in cross-training. Top Skills: MS Office Enverus ## Related Videos - [Shipping Faster with Less: Render on Cloud Hosting, AI Workloads, and the Future of DevOps](https://www.wearedevelopers.com/videos/1894-shipping-faster-with-less-render-on-cloud-hosting-ai-workloads-and-the-future-of-devops) - [The Vonage Trivia Voyage: Quiz Your Way to the Top!](https://www.wearedevelopers.com/videos/761-the-vonage-trivia-voyage-quiz-your-way-to-the-top) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Techies vs. Suits: Decoding the Distinct Paths to Startup Success in Europe and the US](https://www.wearedevelopers.com/videos/826-techies-vs-suits-decoding-the-distinct-paths-to-startup-success-in-europe-and-the-us) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [Coffee with Developers - Maria Apazoglou](https://www.wearedevelopers.com/videos/1209-coffee-with-developers-maria-apazoglou) ## Related Articles - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)