Skip to content

Open nowPosted 11 hours ago

Pasito (YC S22) - Security & IT Manager

Silver48 open roles

Pay
$70,000 – $90,000 a year
Where
Remote
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPasito (YC S22) - Security & IT ManagerSilver · Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Silver's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.3% of postings close within 7 days. Measured by our own scanner across the market. Silver postings stay open a median of 13 days.

Share of postings closed within
  1. 1.9%1 day
  2. 4.0%3 days
  3. 8.3%7 days
  4. 15.3%14 days
  5. 34.2%30 days
This job: posted 11 hours ago

Silver median: 13 days open

The posting

ABOUT PASITO https://pasito.ai

Pasito is the AI workspace for employee benefits.

We’re rethinking how group insurance and benefits are underwritten, delivered, used and measured - by the people who design them and the people who depend on them. Instead of static PDFs, disconnected systems, and manual workflows, Pasito brings plan design, payroll and benefits data, claims, and financial context into a single, AI-native workspace that helps benefits actually work for the 178 million Americans who depend on this system.

We don’t build for brokers, carriers and employers - we build with them. That collaboration shows up in everything we ship: AI agents that extract and structure plan data, tools that turn complexity into clarity for employees, and workflows that save carriers and consultants hundreds of hours per case.

Today, Pasito supports many of the largest insurance carriers and brokers in the U.S. We’re backed by Y Combinator, Insight Ventures and Core Innovation Capital, and we’re growing quickly. We ship fast, iterate relentlessly, and care deeply about building systems that are accurate, scalable, and human.

If you’re excited to work alongside exceptional operators and engineers, and apply AI in a legacy industry where precision and trust matter, Pasito is the place for you.

THE ROLE

We’re looking for a Security & IT Manager to be the first dedicated owner of Pasito’s security, IT, and compliance program. Today this work is split across engineering, sales, and operations: Vanta, audits, pen tests, device setup, access requests, and security questionnaires all land on different people. You’ll own it end to end and become the connective tissue between engineering, HR, legal, sales, our auditors, and our customers.

Security and compliance have been part of how we build from the start, because our customers place their trust in us every day and we support employees in some of their most important financial decisions. We’re HIPAA-regulated and SOC 2 Type II certified, and our customers’ security teams review us closely before every deal.

This is a high-visibility, high-impact role at the center of how Pasito runs. You’ll touch everything from how a new hire gets their laptop on day one, to how we message employees by SMS and email in compliance with U.S. law, to how fast we close a critical vulnerability. This is a senior hire by design: you’ve already run a security and compliance program, and you can pick this one up and run it largely on your own from day one.

WHAT YOU’LL DO

IT, ACCESS & DEVICE MANAGEMENT

- Direct Pasito’s complete IT footprint, including domain management, Google Workspace, and our broader platform portfolio.

- Oversee identity and permission governance: SSO, MFA, role-based controls, least-privilege architecture, and routine quarterly reviews.

- Lead team onboarding and offboarding procedures, ensuring immediate provision of system access for new joiners and instant revocation upon departure.

- Supervise organizational hardware via our MDM solution, handling enrollment, encryption protocols, patching cycles, endpoint protection, and inventory logging.

- Act as the primary point of contact for internal IT issues and access requests.

SECURITY & COMPLIANCE PROGRAM

- Vanta: Maintain daily operations within Vanta by resolving failing tests, delegating fixes, keeping audit trails current, and eliminating operational backlogs.

- SOC 2 Type II: Manage the annual audit execution, from gathering documentation to control mapping and liaison with external auditing teams.

- HIPAA: Ensure continuous alignment with HIPAA regulations, managing executed BAAs and operational policy frameworks.

- Penetration testing: Facilitate yearly security evaluations from partner selection through remediation, validation, and package preparation for clients.

- Vendor & subprocessor risk: Conduct thorough security evaluations of third-party vendors including AI, payroll, and HRIS tools, managing associated DPAs, BAAs, and public records.

- Program hygiene: Drive policy updates, risk reviews, security training, and the upkeep of our internal trust resource hubs.

- AI security: Establish AI risk governance models and monitor third-party artificial intelligence platform integration.

LEGAL & RISK PARTNERSHIP

- Work closely with legal advisors to identify, analyze, and minimize potential security and compliance exposures across the organization.

- Maintain an active risk log, offering transparent and consistent updates on organizational security posture to leadership.

- Collaborate with leadership to ensure security and compliance as product expands and identify risks.

ENGINEERING REMEDIATION & PROJECT MANAGEMENT

- Partner with software engineering teams to resolve vulnerabilities, audit items, and testing findings with clear accountability and timelines.

- Lead operational security projects across departments, managing roadmaps, dependencies, and deliverables.

- Direct our sales security response process, completing SIG, CAIQ, and custom client questionnaires while connecting complex queries to technical leads to keep pipeline moving.

PEOPLE & HR PARTNERSHIP

- Coordinate with HR on security-adjacent personnel operations, including background verifications, policy sign-offs, team security training, and lifecycle checklists.

- Help foster a security-focused culture by offering clear, practical, and actionable advice to the team.

WHAT WE’RE LOOKING FOR

- 5+ years in security, IT, or GRC, including personally owning at least one full SOC 2 Type II cycle end to end.

- Hands-on experience running IT operations at a startup or growth-stage company: identity and access management, SSO, MDM, and SaaS administration.

- Experience operating a compliance automation platform in production (Vanta, Drata, or Secureframe).

- Enough technical depth to read a pen-test report, judge severity, and work credibly with engineers on remediation.

- Strong project-management skills. You keep cross-functional work moving with clear owners and deadlines.

- Excellent written and verbal English communication. You can explain risk clearly to engineers, lawyers, executives, and customers.

- Highly organized and deadline-driven. Much of this job is time-sensitive and deal-blocking.

- Based in Latin America, with strong overlap with U.S. business hours.

NICE TO HAVE

- CISA, CISSP, or ISO 27001 Lead Auditor certification.

- Healthcare, HIPAA, or benefits/insurance industry experience.

- Experience at an early- or growth-stage B2B SaaS company selling to enterprise or regulated buyers.

WHAT’S IN IT FOR YOU

- Strategic visibility: Report to the VP of Engineering and work closely with leadership, HR, legal, and sales on decisions that shape how Pasito scales.

- Ownership: Build and own the security, IT, and compliance function from the ground up.

- Growth: Join at a pivotal stage and grow as the company scales.

- Competitive compensation: Salary benchmarked to your market, paid in USD.

- Remote-first: Work from anywhere in Latin America with a highly collaborative team.

- Learning and development: A budget to invest in yourself, whether that’s certifications, courses, books, or conferences.

- Team offsites: We get together in person every year to work, connect, and have fun.

EQUAL OPPORTUNITY

Pasito is proud to be an equal opportunity employer. We believe great teams are built through diversity of background, perspective, and experience, and we’re committed to creating an inclusive environment where everyone can do their best work.

THE INTERVIEW PROCESS

- Silver Screening Interview

- Client Resume Review

- Client Screening Interview

- Client Technical Interview (You are going to make a presentation and defend it!)

- Client Behavioral Interview

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Silver's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Silver's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Silver's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.