> Markdown version of [/jobs/ext/440022-it-security-manager](https://www.wearedevelopers.com/jobs/ext/440022-it-security-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Manager - **Company:** Edvisorly, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Amazon S3, Software as a Service, Cloud Computing Security, Cyber Security, Domain Name System Security Extensions, Identity and Access Management, Security Information and Event Management, Data Streaming, Data Logging, Google Cloud, Okta, Software Security, Static Application Security Testing - **Published:** June 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=5e102b982b53976d ## About the Role Do you have experience in Tooling?, 5+ years of information security experience, with direct ownership of security programs or workstreams Hands-on experience with SOC 2 Type II (personally led or co-led audit cycles) Demonstrated ability to draft and implement security policies, standards, and procedures from scratch Experience configuring/managing security tools in a cloud-first environment (EDR, WAF, DNS security, SIEM/logging, or equivalent) Familiarity with identity and access management tools (Okta or equivalent SSO/MFA platforms) Strong written and verbal communication, able to explain security risks to non-technical audiences Comfort operating with high autonomy and minimal oversight in a fast-paced, ambiguous environment Preferred: Experience in SaaS, edtech, or higher education, particularly with FERPA-adjacent or student data privacy Prior mentoring experience or ability to transition into a direct manager as the team grows Familiarity with managed security service providers and escalation workflows Knowledge of cloud security fundamentals (GCP, AWS, IAM, Security Command Center, GuardDuty, S3 policy, etc.) Exposure to application security concepts (SAST, SCA, secure SDLC) Experience with vendor risk management programs (questionnaire design, third-party access tiering) Relevant certifications: CISSP, CISM, GSEC, GCIH, or similar GIAC credentials ## Description As EdVisorly's first internal security hire, you will own security operations end-to-end-including governance and compliance, identity and access modernization, security tooling configuration, managed security service coordination, and policy development. You will serve as the primary liaison to both our managed IT provider and our vCISO for strategic direction. In your first year, this is a hands-on builder role: you'll deploy tools, draft policies, and stand up foundational operational practices. As the team grows, this position will evolve into a lead role with direct management responsibility. The work you do at EdVisorly directly protects 200+ higher education institutions and the students whose data flows through our platform. Security is a core sales enabler at EdVisorly, and this position makes that possible. What You'll Do Own EdVisorly's day-to-day security program, translating vCISO direction into outcomes across identity, detection, data, and application security Maintain and evolve the SOC 2 Type II compliance program-evidence collection, control mapping, policy updates, audit preparation Draft, update, and operationalize security policies and procedures, ensuring documentation reflects real practices and company-wide acknowledgment Develop and maintain incident response runbooks; serve as incident coordinator during events, escalating to the vCISO as needed Lead deployment and configuration of identity and access management tools (SSO, Adaptive MFA), establishing and enforcing the company's identity perimeter Directly own and administer identity, MFA, and email security tooling; partner with managed IT and Engineering to ensure security across all platforms Coordinate with the MSSP on alert triage and access provisioning/deprovisioning, including governance and break-glass procedures Serve as the primary security liaison to MilesIT, ensuring managed IT aligns with security policies and SOC 2 requirements Design and maintain a vendor risk management intake process, including questionnaires and a critical vendor register updated quarterly Support HR and Legal with role-based hiring security controls, background screenings, and provisioning gates Manage the security awareness program-review effectiveness, refresh content, and conduct annual tabletop exercises ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [WeAreDevelopers LIVE - CSS is DOOMed](https://www.wearedevelopers.com/videos/1838-wearedevelopers-live-css-is-doomed) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [Hate organising your photos? Try it with 5 Terabytes](https://www.wearedevelopers.com/videos/79-hate-organising-your-photos-try-it-with-5-terabytes) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)