Head of IT & Security
Jobleads-US
Head of IT & Security
About us:
At Fullbay, our mission is simple — to create safer roads for our families and yours. As leaders in the heavy‑duty repair industry, we power shops with technology that helps them run smarter and more efficiently. As an AI‑First company, we invite artificial intelligence to eliminate friction, spark innovation, and drive efficiencies in every conversation— for our teams and our customers. Fullbay is the number one cloud‑based shop management software for commercial repair shops and is growing fast. This is an exciting opportunity to join a high‑performing team and help shape the next phase of growth for the company.
Position Overview:
Fullbay's Security and IT Manager owns two functions that are usually split across two people: the security program that keeps Fullbay's systems, people, and customer data safe, and the IT operations that keep the business running day to day. Reporting to the VP of IT, this role designs the security and IT program from the ground up and owns its execution end-to-end — there's no existing playbook to inherit and no separate team to hand the work to.
This role is well‑suited to someone who has built a security program before, not just operated inside one — someone comfortable being the primary responder when an MDR alert escalates, the person who leads SOC 2 through an actual audit, and the same person who's also the company's escalation point when someone's laptop won't image. This is a player‑coach role: you set the standards, and you personally execute the work.
Success here looks like passing SOC 2 audits with no major findings, on schedule; security incidents that get triaged, contained, and resolved fast enough that they stay incidents, not breaches; IT support that doesn't make employees wait, with devices provisioned before day one and tickets closed without a saga; and a risk posture leadership can see clearly at any time, not just when an audit forces the question.
The Right Wrench for the Job
A shop's most dangerous moments are never the ones people see coming. The person who wires the electrical panel, checks the fire suppression, and makes sure the alarm actually calls someone when it goes off isn't thinking about any one repair — they're thinking about what keeps the whole building standing. This role does that for Fullbay's systems and data, and then still picks up the phone when someone's laptop won't turn on.
You're the right fit if you've built a security program from a blank page before — not just operated inside one someone else designed — and you know the difference between a control that looks good on paper and one that actually holds up when an auditor or an attacker tests it. You can walk into a SOC 2 evidence review in the morning, triage a real MDR alert at noon, and still be the person who gets a new hire's laptop imaged and ready before their first day.
This isn't the role for someone who wants to own strategy and hand off the keyboard. If your instinct is to write the policy and let someone else enforce it, this isn't your shop. But if you're the kind of person who'll design the program, defend it to an auditor, and still crawl under the desk to fix a network cable — we'd like to talk.
Primary Duties & Responsibilities:
- Security Program Ownership: Design, build, and continuously improve Fullbay’s security program using NIST CSF 2.0 as the governance architecture and CIS Controls v8.1 (IG1 to IG2) as the tactical execution roadmap.
- Security Operations Oversight: Manage Fullbay’s always‑on MDR platform, which provides automated threat detection and triage across endpoints and cloud environments. Serve as the primary responder for escalated alerts requiring human judgment, and lead investigation, containment, and remediation for confirmed incidents, including participation in an on‑call rotation for high‑severity escalations.
- SOC 2 Readiness and Audit Management: Lead all SOC 2 readiness activities including control mapping, evidence collection, gap remediation, and audit firm coordination for Type I and Type II engagements.
- Tool and Platform Governance: Own and configure Fullbay’s security tooling stack, including the MDR platform, MDM, email security, anti‑phishing, and security awareness training. Tune and maintain tools to Fullbay standards, and evaluate new tools or vendors as needed.
- Policy and Standards Development: Author, maintain, and enforce information security policies, standards, and procedures across the organization. Ensure policies align with regulatory requirements and audit frameworks.
- Identity and Access Management: Oversee IAM posture across Google Workspace, including passkeys, MFA, SSO, and privileged access controls, including MDM and Apple Business Manager configuration.
- Incident Response: Develop and own the incident response plan. Serve as the primary responder for security events escalated by the MDR platform or identified through other internal monitoring.
- Risk Management: Maintain a risk register. Identify, assess, and track security risks across people, process, and technology. Communicate risk posture to the VP of IT and senior leadership.
- Security Awareness: Oversee the security awareness training program, including phishing simulations and compliance‑based training cycles.
- Vendor and Third‑Party Risk: Assess security posture of third‑party vendors and new software applications. Maintain a vendor risk inventory and drive remediation for identified gaps.
- End‑User IT Support: Serve as the primary escalation point for company‑wide technical support, resolving hardware, software, network and account issues for employees across the organization.
- Device & Asset Lifecycle Management: Own procurement, provisioning, and deprovisioning of company devices, coordinating imaging and configuration through Apple Business Manager and NinjaOne, and maintaining an accurate IT asset inventory.
- SaaS Application Administration: Manage user provisioning, licensing and configuration across Fullbay’s core SaaS applications, including Google Workspace and other business tools, ensuring accounts are created, modified, and deactivated promptly.
- Onboarding & Offboarding: Own the IT components of employee onboarding and offboarding, including account creation, device setup, access provisioning and timely access removal.
- IT Vendor & Procurement Management: Manage relationships and contracts with IT vendors and service providers, evaluate new tools, and control IT spend.
- Adheres to all confidentiality and compliance regulations.
- Performs other duties as assigned.
Minimum Education & Work Experience:
- 7‑10 years of combined experience across IT operations and security, cybersecurity, or information security required; 10+ years preferred.
- Experience managing and responding to alerts from an MDR/EDR platform, including triage, investigation, and remediation of confirmed incidents, required.
- Demonstrated experience owning a compliance or regulatory program (SOC 2, ISO 27001, HIPAA, PCI‑DSS, or equivalent) required.
- SOC 2 audit experience (Type I or Type II) strongly preferred.
- Bachelor’s degree in Information Security, Computer Science, Information Systems, or a related field, or equivalent work experience.
- Hands‑on experience administering Google Workspace, MDM platforms (e.g., NinjaOne, Apple Business Manager), and providing general end‑user IT support required.
Key Skills and Qualifications:
- Deep knowledge of security frameworks including NIST CSF 2.0 and CIS Controls v8.1.
- Working knowledge of MDR/EDR platforms and MDM solutions, with the ability to investigate and respond to escalated alerts.
- Required platform experience: Google Workspace administration and security configuration, Apple Business Manager (ABM), NinjaOne endpoint management.
- Preferred platform experience: Proofpoint email security, Ironscales anti‑phishing.
- Strong understanding of IAM concepts including SSO, MFA, passkeys, and privileged access management.
- Ability to operate as a player‑coach: design the security program, set the standards, and personally execute the work.
- Strong written and verbal communication skills with the ability to present security risk and program status to executive leadership.
- Experience working cross‑functionally with Engineering, Legal, Finance, and business stakeholders.
- Preferred certifications: CISSP, CISM, CISA, CCSP, CompTIA Security+, or CASP+.
- Strong general IT troubleshooting skills across Mac and Windows environments, networking fundamentals, and common business SaaS applications.
- Experience with IT ticketing/helpdesk systems and asset management tools.
Physical Demands and Work Environment:
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions
- Regularly required to sit at a desk in front of a computer and use hands to finger, handle, or feel objects, tools, or controls (including a computer keyboard and operating a telephone), lift and/or move up to 10 pounds.
- Frequently requires the use of hands and arms for reaching, as well as the ability to walk and communicate effectively through speaking and listening.
- Specific vision abilities required by this position include close vision, color vision, and the ability to adjust focus.
- Noise level in the work environment is usually moderate.
- Type on a computer keyboard and look at a computer monitor, and operate a cell phone or a computer‑based phone
$275k - $305k
...services business, and over $11Bn in personal and home loans originations via our banking‑as‑a‑service partner. Chief Information Security Officer (CISO) is responsible for establishing and executing the enterprise cybersecurity strategy for a high‑growth, private fintech...SuggestedContract workRemote workWork from homeShift work- ...Chief Information Security Officer (CISO) / Head of Information Security Overview We are seeking an experienced Information Security Leader to define and execute a comprehensive enterprise security strategy. This role is responsible for safeguarding systems, data, and...SuggestedWork at officeRemote work3 days per week
$50 per hour
...Experienced ProfessionalFT/PT/Casual: FullTimeDepartment: RMS CoreBusiness Unit: RMS CoreShort DescriptionThe Work:This Information System Security Officer (ISSO) position will support the Information System Security Manager (ISSM) in developing, maintaining and overseeing the...SuggestedFull timeTemporary workWork experience placementCasual workFlexible hoursShift workDay shift- ...ECS is seeking a CISO to work in our Sierra Vista, AZ office. The Chief Information Security Officer will serve as the senior cybersecurity leader and principal security advisor to the Program Manager for The Army Endpoint Security Solution (AESS). This role is responsible...SuggestedContract workWork at officeLocal area
- ...Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry Information Technology and Services Type Privately Held Founded 2024 Employees 51-200 Specialties cloud backup...Suggested
- ...Job Description Job Description Chief Information Security Officer (CISO) / Head of Information Security ABOUT THE ROLE This is not a purely... ...YOU WILL OWN PERSONALLY This is a build role before it is a management role. The security function is growing, and...Remote work
- ...guide the firm through technology transitions—with emphasis on security, compliance, and business continuity.Key ResponsibilitiesStrategic... ...project management skills including prior experience managing IT projectsExcellent attention to detail and problem-solving skillsStrong...Contract workRemote work
- ...to interface carrier equipment with specific local equipment; low-band, VHF, UHF, 800 MHz base station/repeater 2-way radios; site security alarm and control equipment; site grounding grids, etc.).14. Participates in mountaintop user associations to reduce problems...Work experience placementWork at officeLocal areaRemote workFlexible hoursNight shift
- ...Virtual Chief Information Security OfficerPhoenix's small and mid-sized businesses face the same cybersecurity threats as the Fortune 50... ...on cloudIT's security stackPresent security posture updates to IT leaders and business owners in clear, actionable termsTrack emerging...Full timeWork at officeShift work
- ...also be tasked with overseeing the development and maintenance of secure, scalable, and efficient payment solutions, and ensuring... ...qualification being a plus, and at least 10 years of experience in IT leadership, particularly in the payments or financial services industry...Remote work
- Chief Trust Officer (CTO) About the Company Highly respected wealth management firm with boutique, client-centric service for sophisticated families. Industry Financial Services Type Privately Held About the Role The Company is in search of a Chief...
- ...Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014...
- ...Deputy Chief Information Security Officer (CISO) About the Company Innovative digital life insurance company Industry Insurance Type Privately Held, VC-backed Founded 2016 Employees 501-1000 Funding $6-$10 million Specialties life insurance...
- ...Job Description Job Description Virtual Chief Information Security Officer ● cloudIT ● Phoenix, AZ ● In-Office Phoenix... ...on cloudIT's security stack•Present security posture updates to IT leaders and business owners in clear, actionable terms•Track...Full timeWork at officeShift work
- Part-Time Chiropractor - Ownership Track Opportunity NuSpine Chiropractic is a rapidly expanding franchise system redefining modern chiropractic care through clinical excellence, operational precision, affordability, and meaningful patient relationships. Our examinations...Part timeImmediate start
- Company DescriptionIDEALFORCE has a CONTRACT position available immediately for a Sr Telecom Project Manager to join our customer in Phoenix Arizona. This is an ONSITE position. Please find below additional details about this job. Client is considering only LOCAL CANDIDATES...Contract workWork at officeLocal areaImmediate startFlexible hours
- ...grows will be a key focus, along with customer satisfaction and security. The CIO will support and lead teams in Digital Media and Information... ..., cybersecurity, compliance, and architecture. Oversee the IT and Digital Media Teams. Work in collaboration with marketing to...Work at office
$82.28k - $108.77k
DEPARTMENT OF PUBLIC SAFETY The Department of Public Safety’s mission is to provide public safety to the state of Arizona. Visit our website at Telecommunications Supervisor Salary: $82,277.73 - $108,766.74 Job Summary: The Arizona Department of Public Safety is seeking...Temporary workWork experience placement$120k
...The Information Security Manager leads the design, implementation, and continuous enhancement of the organization's cybersecurity program under the Security Officers guidance. This position ensures that technical and administrative safeguards align with HIPAA, CIS, NIST...Contract workRemote work$123k - $215.25k
...providing world-class customer service, we operate with a strong risk mindset, ensuring we continue to uphold our brand promise of trust, security, and service.As part of Team Amex, you’ll experience our powerful backing with comprehensive support for your holistic well-being...Contract workFor contractors- ...Director of IT *Relocation to a Beautiful and Scenic City* *Relo Incentive DOE* McCall & Lee Healthcare has been commissioned by... ...Responsibilities Oversee all technology operations (e.g. network security) and evaluate them according to established goals Devise and...Work experience placementRelocation
- Managing Director, Chief Technology Officers Practice, Retained Search About the Company Dynamic executive search firm specializing in diversity & inclusion solutions Industry Management Consulting Type Privately Held Founded 2021 Employees 5...
- ...OVERVIEW We are seeking an Archer Operations Support Analyst / Cyber Security Specialist to provide production support, administration, and... ...working closely with Risk, Compliance, Audit, Security, and IT teams. • RSA Archer / Archer IRM Administration Secondary (Good...
$36 - $40 per hour
...solving and challenging the status quo are celebrated. Join a team where your contributions directly shape the future of financial security and innovation. Are you a cybersecurity enthusiast with a passion for protecting critical data? We are seeking a dynamic and...Hourly payWeekly payTemporary work$80k
Chiropractor Position at LifeClinic At LifeClinic, our mission is to restore, maintain, and optimize human function and performance. As a chiropractor here, you'll provide adjustments, soft tissue work, and rehab exercises inside Life Time facilities. We're already ...Temporary workRelocationDay shift- Field Chief Technology Officer (CTO) About the Company Regarded provider of professional technology & software solutions Industry Computer Software Type Privately Held Founded 2006 Employees 51-200 Categories Information Technology & Services...Apprenticeship
- ...Regional Field Chief Technology Officer (CTO) About the Company Globally recognized provider of automated solutions for securing & managing open source software Industry Computer Software Type Public Company Founded 2002 Employees 5001-10,000...
$40 - $45 per hour
...manage your insurance and deal with all of your business administration, as well as ensuring that you have the financial stability and security to think long term. Underpinning all of this is a clear set of values that drive every decision we make: trust, respect,...Part timeWork at officeWeekday work- ...Cybersecurity Advisor (SA) plays a critical role in serving as a trusted partner to Optiv’s clients. By combining sales skills and broad security practitioner knowledge, the SA designs security solutions for assigned clients. Aligned with their client's security initiatives...Full timeWork experience placementLocal areaRemote workWork from home
- ...partner to Optiv’s clients. By combining advanced business and security practitioner knowledge, the Principal AI Cybersecurity Advisor designs... ...planning, forecasting, and pipeline management activities as it pertains to growing Optiv pipeline, closed business, and...Full timeLocal areaRemote workWork from home
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Head of IT & Security. Be the first to apply!
- chief information security officer ciso Phoenix, AZ
- business information security officer Phoenix, AZ
- information security officer Phoenix, AZ
- ciso Phoenix, AZ
- chief information security officer Phoenix, AZ
- IT security Phoenix, AZ
- chief information security officer ciso
- business information security officer biso
- business information security officer
- information systems security officer



