Skip to content

Open nowPosted 124 days ago

IT & Security Operations Manager

Workable (global search)108,016 open roles

Where
Walnut Creek, CA, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowIT & Security Operations ManagerWorkable (global search) · Walnut Creek, CA, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 124 days ago

Workable (global search) median: 7 days open

The posting

Clearstory is looking for an IT & Security Operations Manager to manage and improve the day-to-day operations of our IT, security compliance, and corporate systems infrastructure.

We've built a solid foundation - SOC 2 compliance tooling in Vanta, structured onboarding and offboarding workflows, a vendor security review process, and a cross-functional data governance program. What we need is a dedicated owner to manage these programs day-to-day, project manage key deliverables, maintain what's already working, and identify opportunities to improve and scale as we grow.

If you thrive as the go-to person for IT, compliance coordination, and keeping an organization running smoothly, this role is for you.

Responsibilities

IT Administration

  • Manage day-to-day identity and access management - Google Workspace admin, Slack admin, AI platform administration, shared inbox management
  • Run employee onboarding provisioning - Day 1 account creation, checklist management, Vanta security onboarding, welcome communications, completion tracking
  • Run employee offboarding - access revocation, system owner coordination, equipment return, deprovisioning verification within SLA
  • Serve as the internal IT point of contact - password resets, hardware troubleshooting, software support, connectivity issues
  • Manage the asset lifecycle - laptop procurement, serial number tracking, equipment reassignment, peripherals ordering
  • Coordinate the annual SOC 2 audit process - project manage evidence collection, organize documentation, track control status in Vanta, follow up on remediation, and liaise with external auditors
  • Execute quarterly and annual access reviews, verifying active users against the employee roster, documenting findings, and remediating stale access
  • Manage Vanta day-to-day - dashboards, weekly compliance summaries, Trust Center access requests, failed test remediation
  • Monitor and drive employee security compliance - agent installs, 1Password provisioning, MFA enforcement, security awareness training
  • Take first pass on inbound customer security questionnaires and maintain an answer library to streamline future responses
  • Track and execute data governance action items from biweekly cross-functional meetings - tool policy enforcement, vendor risk monitoring, etc.

Security & Compliance

  • Coordinate the annual SOC 2 audit process - project manage evidence collection, organize documentation, track control status in Vanta, follow up on remediation, and liaise with external auditors
  • Execute quarterly and annual access reviews, verifying active users against the employee roster, documenting findings, and remediating stale access
  • Manage Vanta day-to-day - dashboards, weekly compliance summaries, Trust Center access requests, failed test remediation
  • Monitor and drive employee security compliance - agent installs, 1Password provisioning, MFA enforcement, security awareness training
  • Take first pass on inbound customer security questionnaires and maintain an answer library to streamline future responses
  • Track and execute data governance action items from biweekly cross-functional meetings - tool policy enforcement, vendor risk monitoring, etc.

Business Operations

  • Maintain and improve a centralized SaaS inventory - tools, seat counts, renewal dates, and costs. Keep a renewal calendar with advance notice to budget owners
  • Manage new software requests - intake, triage, security review routing, approval tracking, provisioning
  • Prepare vendor security assessments - collect SOC 2 reports, DPAs, and documentation for CTO review and approval
  • Support office IT and facilities - conference room AV, key fob provisioning, building management coordination
  • Document key processes - onboarding/offboarding runbooks, SOC 2 evidence collection guides, vendor review steps, AI usage best practices
  • Identify and implement automation opportunities - workflows for onboarding triggers, access request routing, renewal reminders, and offboarding checklists

The Opportunity

This is an opportunity to be the dedicated owner of IT and security operations at a growing SaaS company.

You will:

  • Take ownership of established compliance, IT, and security programs and keep them running smoothly
  • Project manage SOC 2 audit readiness as the company expands its customer base
  • Identify gaps and inefficiencies in existing workflows and fix them
  • Help create scalable processes that support the company through its next stage of growth
  • Work cross-functionally with Engineering, Finance, and GTM teams

Success in this role means Clearstory's IT, security compliance, and corporate systems run reliably and keep getting better over time.

The Company You'll Join

Clearstory is a SaaS platform modernizing how construction companies communicate, approve, and track change orders and related cost workflows. We replace paper, spreadsheets, and email with simple, trusted financial workflows that help contractors get paid accurately and on time.

We are a Series B, 100% SaaS company with strong product-market fit, growing six-figure deals, and a large, underserved TAM. Our customers love us, our retention is strong, and we are building for long-term impact.

Requirements

  • 4-7 years of experience in IT operations, security operations, or SaaS business operations
  • Hands-on SOC 2 evidence collection and audit coordination experience (not just awareness - you've done the work)
  • Google Workspace administration experience (security settings, groups)
  • Experience with compliance platforms like Vanta, Drata, or similar
  • SaaS vendor management experience - renewals, license optimization, procurement intake
  • Comfort with automation tools to streamline established workflows
  • The ability to work directly with a CTO on security operations without needing hand-holding on fundamentals
  • A builder's mindset - you'd rather create a process than follow a broken one, and you document what you build

Strong plus if you have:

  • Experience completing customer security questionnaires
  • Office or facilities coordination at a startup
  • MDM deployment experience

About You

You're a hands-on operator who gets things done without being asked. You see a problem, fix it, and move on - whether that's a password reset at 9am or prepping access review documentation at 2pm. Task size doesn't faze you because you know the small stuff and the big stuff both matter at a company this size.

You're organized and reliable. When you're asked to coordinate an offboarding or chase down a vendor's SOC 2 report, it gets done on time and nothing slips. You're comfortable working across teams - Engineering, Finance, GTM - and you can translate security and IT requirements into plain language for people who don't live in that world.

You understand that IT and security operations at a growing company isn't glamorous - but you also know it's foundational. You've seen what happens when access deprovisioning slips or when SOC 2 evidence collection becomes a fire drill. You're the person who keeps things running so that doesn't happen.

This is not a security engineering or CISO-track role - the CTO owns security architecture and policy. This is not a pure helpdesk role either - IT support is part of the job, but compliance coordination and process maintenance are the core.

Benefits

  • Competitive salary and meaningful equity ownership
  • Comprehensive health, dental, and vision coverage
  • 401(k) plan to support your long-term financial goals
  • Flexible PTO and company holidays
  • Remote-friendly work environment with flexibility and autonomy
  • Opportunity to work alongside a high-caliber, mission-driven team
  • Career growth and leadership opportunities as the company scales
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.