
IT Security Lead
Ruby Labs
full-time
Posted on:
Location Type: Remote
Location: Ukraine
Visit company websiteExplore more
Job Level
Tech Stack
About the role
- Design and build operations security infrastructure and IAM from scratch.
- Develop, implement, and maintain comprehensive security policies, strategies, and protocols to safeguard the intellectual property, and prevent unauthorized access.
- Deploy and manage security tools and solutions, with preference for open-source technologies where appropriate.
- Utilize MDM software with other products to ensure organization-wide device security compliance and enforce consistent protection standards across all endpoints.
- Establish and enforce remote work security standards and best practices for company owned and BOYD devices.
- Design and implement access structure using identity provider.
- Manage user provisioning and deprovisioning workflows across all company tools and services.
- Automate access lifecycle management, including onboarding and offboarding processes.
- Control and audit access permissions to ensure principle of least privilege.
- Implement and maintain identity federation technologies across multiple platforms.
- Administer Google Workspace with focus on security configurations and compliance.
- Configure policies like Context Aware Access, LDAP, SCIM, and other controls within Google Workspace.
- Establish IT security operations (SecOps) best practices and standard operating procedures.
- Conduct regular security assessments and vulnerability management.
- Define security metrics and KPIs; provide regular security posture reports.
- Advise leadership on security risks, compliance requirements, and remediation strategies.
- Develop and maintain comprehensive security documentation, runbooks, and policies.
- Streamline security-related processes for efficiency and effectiveness.
- Create and maintain disaster recovery and business continuity plans.
- Drive security awareness and training initiatives across the organization.
Requirements
- At least 5 years of experience in IT security engineering or infrastructure security roles.
- Proven track record of building corporate security infrastructure from the ground up.
- Strong automation (for example n8n, getcakewalk, Slack workflows, jumpcloud, etc) and basic REST API knowledge.
- Deep understanding of IT security operations (SecOps) best practices and frameworks.
- Strong engineering background with experience in infrastructure design and implementation.
- Hands-on experience with Google Workspace administration and security configuration.
- Expert knowledge of identity and access management, including user provisioning and deprovisioning workflows.
- Experience with SSO, SAML, OIDC, and identity federation technologies.
- Knowledge of Docker.
- Experience with IAM automation and orchestration.
- Understanding of compliance frameworks (SOC 2, ISO 27001, etc.).
Benefits
- Remote Work Environment: Embrace the freedom to work from anywhere, anytime, promoting a healthy work-life balance.
- Unlimited PTO: Enjoy unlimited paid time off to recharge and prioritize your well-being, without counting days.
- Paid National Holidays: Celebrate and relax on national holidays with paid time off to unwind and recharge.
- Company-provided MacBook: Experience seamless productivity with top-notch Apple MacBooks provided to all employees who need them.
- Flexible Independent Contractor Agreement: Unlock the benefits of flexibility, autonomy, and entrepreneurial opportunities. Benefit from tax advantages, networking opportunities, reduced employment obligations, and the freedom to work from anywhere.
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
IT security engineeringinfrastructure securitysecurity policiesidentity and access managementuser provisioningdeprovisioning workflowsautomationREST APIsecurity assessmentsvulnerability management
Soft Skills
leadershipcommunicationorganizational skillsproblem-solvingtraining and awareness
Certifications
SOC 2ISO 27001