Fullbay
Head of IT & Security
Phoenix, Arizona, Remote
Get past the screening software and onto a recruiter's desk
hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.
- Keywords matched to this posting
- Fit score before you apply
- Cover letter included
Matched against 2.6M live jobs from 190,000+ employers in 200+ countries.
Tailor my resume for this job →Apply from your AI assistant
Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.
Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.
hirly's read of this role
- Seniority
- Lead / management
- Country
- US
- Work mode
- Remote-friendly
- First seen by hirly
- 3 Oct 2026
Derived automatically from the posting. Upload your resume above to see how the role scores against it.
the posting
Head of IT & Security
- About us:
- At Fullbay, our mission is simple — to create safer roads for our families and yours. As leaders in the heavy-duty repair industry, we power shops with technology that helps them run smarter and more efficiently. As an AI-First company, we invite artificial intelligence to eliminate friction, spark innovation, and drive efficiencies in every conversation— for our teams and our customers. Fullbay is the number one cloud-based shop management software for commercial repair shops and is growing fast. This is an exciting opportunity to join a high-performing team and help shape the next phase of growth for the company.
Position Overview:
Fullbay's Security and IT Manager owns two functions that are usually split across two people: the security program that keeps Fullbay's systems, people, and customer data safe, and the IT operations that keep the business running day to day. Reporting to the VP of IT, this role designs the security and IT program from the ground up and owns its execution end-to-end — there's no existing playbook to inherit and no separate team to hand the work to.
This role is well-suited to someone who has built a security program before, not just operated inside one — someone comfortable being the primary responder when an MDR alert escalates, the person who leads SOC 2 through an actual audit, and the same person who's also the company's escalation point when someone's laptop won't image. This is a player-coach role: you set the standards, and you personally execute the work.
Success here looks like passing SOC 2 audits with no major findings, on schedule; security incidents that get triaged, contained, and resolved fast enough that they stay incidents, not breaches; IT support that doesn't make employees wait, with devices provisioned before day one and tickets closed without a saga; and a risk posture leadership can see clearly at any time, not just when an audit forces the question.
The Right Wrench for the Job
A shop's most dangerous moments are never the ones people see coming. The person who wires the electrical panel, checks the fire suppression, and makes sure the alarm actually calls someone when it goes off isn't thinking about any one repair — they're thinking about what keeps the whole building standing. This role does that for Fullbay's systems and data, and then still picks up the phone when someone's laptop won't turn on.
You're the right fit if you've built a security program from a blank page before — not just operated inside one someone else designed — and you know the difference between a control that looks good on paper and one that actually holds up when an auditor or an attacker tests it. You can walk into a SOC 2 evidence review in the morning, triage a real MDR alert at noon, and still be the person who gets a new hire's laptop imaged and ready before their first day.
This isn't the role for someone who wants to own strategy and hand off the keyboard. If your instinct is to write the policy and let someone else enforce it, this isn't your shop. But if you're the kind of person who'll design the program, defend it to an auditor, and still crawl under the desk to fix a network cable — we'd like to talk.
Primary Duties & Responsibilities:
Security Program Ownership: Design, build, and continuously improve Fullbay’s security program using NIST CSF 2.0 as the governance architecture and CIS Controls v8.1 (IG1 to IG2) as the tactical execution roadmap.
Security Operations Oversight: Manage Fullbay’s always-on MDR platform, which provides automated threat detection and triage across endpoints and cloud environments. Serve as the primary responder for escalated alerts requiring human judgment, and lead investigation, containment, and remediation for confirmed incidents, including participation in an on-call rotation for high-severity escalations.
SOC 2 Readiness and Audit Management: Lead all SOC 2 readiness activities including control mapping, evidence collection, gap remediation, and audit firm coordination for Type I and Type II engagements.
Tool and Platform Governance: Own and configure Fullbay’s security tooling stack, including the MDR platform, MDM, email security, anti-phishing, and security awareness training. Tune and maintain tools to Fullbay standards, and evaluate new tools or vendors as needed.
Policy and Standards Development: Author, maintain, and enforce information security policies, standards, and procedures across the organization. Ensure policies align with regulatory requirements and audit frameworks.
Identity and Access Management: Oversee IAM posture across Google Workspace, including passkeys, MFA, SSO, and privileged access controls, including MDM and Apple Business Manager configuration.
Incident Response: Develop and own the incident response plan. Serve as the primary responder for security events escalated by the MDR platform or identified through other internal monitoring. Lead response activities and post-incident reviews.
Risk Management: Maintain a risk register. Identify, assess, and track security risks across people, process, and technology. Communicate risk posture to the VP of IT and senior leadership.
Security Awareness: Oversee the security awareness training program, including phishing simulations and compliance-based training cycles.
Vendor and Third-Party Risk: Assess security posture of third-party vendors and new software applications. Maintain a vendor risk inventory and drive remediation for identified gaps.
End-User IT Support: Serve as the primary escalation point for company-wide technical support, resolving hardware, software, network, and account issues for employees across the organization.
Device & Asset Lifecycle Management: Own procurement, provisioning, and deprovisioning of company devices, coordinating imaging and configuration through Apple Business Manager and NinjaOne, and maintaining an accurate IT asset inventory.
SaaS Application Administration: Manage user provisioning, licensing, and configuration across Fullbay’s core SaaS applications, including Google Workspace and other business tools, ensuring accounts are created, modified, and deactivated promptly.
Onboarding & Offboarding: Own the IT components of employee onboarding and offboarding, including account creation, device setup, access provisioning, and timely access removal.
IT Vendor & Procurement Management: Manage relationships and contracts with IT vendors and service providers, evaluate new tools, and control IT spend.
Adheres to all confidentiality and compliance regulations.
Performs other duties as assigned.
Minimum Education & Work Experience:
7-10 years of combined experience across IT operations and security, cybersecurity, or information security required; 10+ years preferred.
Experience managing and responding to alerts from an MDR/EDR platform, including triage, investigation, and remediation of confirmed incidents, required.
Demonstrated experience owning a compliance or regulatory program (SOC 2, ISO 27001, HIPAA, PCI-DSS, or equivalent) required.
SOC 2 audit experience (Type I or Type II) strongly preferred.
Bachelor’s degree in Information Security, Computer Science, Information Systems, or a related field, or equivalent work experience.
Hands-on experience administering Google Workspace, MDM platforms (e.g., NinjaOne, Apple Business Manager), and providing general end-user IT support required.
Key Skills and Qualifications:
Deep knowledge of security frameworks including NIST CSF 2.0 and CIS Controls v8.1.
Working knowledge of MDR/EDR platforms and MDM solutions, with the ability to investigate and respond to escalated alerts.
Required platform experience: Google Workspace administration and security configuration, Apple Business Manager (ABM), NinjaOne endpoint management.
Preferred platform experience: Proofpoint email security, Ironscales anti-phis
Listed on hirly, a job board. hirly is not the employer: Fullbay is hiring for this role.
Similar jobs
- EUS Manager Technical Services (Hybrid) - WashU IT Security & AccessWustl · Washington University Medical CampusFirst seen today
- Principal Analyst, IT SecurityRaymondjamesFirst seen 4d ago
- Senior Manager, Corporate IT Security & ComplianceLivenation · Work From Home - FloridaFirst seen 5d agoremote
- Principal IT Security ConsultantYum! · Irvine, CA, United StatesFirst seen 6d ago
- IT Security Manager - Third-Party IT Risk ManagerWk · 11 LocationsFirst seen 6d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job