Head of IT & Security @OpenEd
Information Technology
Salary usd 195,000 - 2..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago

[Hiring] Head of IT & Security @OpenEd

1mth ago - OpenEd is hiring a remote Head of IT & Security. πŸ’Έ Salary: usd 195,000 - 220,000 per year πŸ“Location: USA

Role Description

As the founding Security Engineer at OpenEd, you'll join a small, high-impact team changing the nature of education. This is a truly unique opportunity to be the founding member of our security team, and to ensure we earn the trust of families that their student's education β€” and data β€” is safe with us.

You'll own the IT, identity, and compliance programs directly, with a broad range of responsibilities and the autonomy to tackle them as you see fit. We serve over 100,000 students, which means the security bar isn't theoretical: it's the reason families keep trusting us with their kids.

Your Immediate Impact

  • Identity & access: SSO/SAML, MFA, provisioning, a least-privilege access model, and reliable onboarding/offboarding.
  • Corporate/IT security: Endpoint/MDM, SaaS and vendor risk, the phishing and awareness program, and incident response playbooks.
  • Compliance: Drive SOC 2 (Type II), map FERPA/COPPA/state privacy controls, and own audits and their outcomes.
  • Application security: Contribute to key AppSec initiatives (SAST/DAST/SCA in CI), triage and drive remediation with engineers, and run external pen test audits.

Success Metrics

In your first 12 months:

  • Compliance: SOC 2 Type II readiness completed, gaps remediated, and the audit window passed with no material exceptions.
  • Identity: Every employee and contractor on SSO with MFA enforced, access granted by least-privilege role, and onboarding/offboarding running on automated provisioning with same-day deprovisioning.
  • Endpoint coverage: Full MDM enrollment across the fleet with enforced, documented baselines.
  • Vulnerability management: SAST/DAST/SCA running in CI, severity-based remediation SLAs consistently met, and an annual external pen test with findings tracked to closure.
  • Readiness: Incident response playbooks documented and exercised, and a phishing/awareness program running with measurably improving results.
  • Privacy: FERPA, COPPA, and state privacy requirements mapped to controls with evidence collection that doesn't depend on a fire drill.

Qualifications

  • 6+ years in security, ideally in a regulated vertical (finance, education, healthcare).
  • Hands-on across IT/identity and security operations β€” not just advisory.
  • You've taken an org through SOC 2 (or ISO 27001).
  • Experienced at establishing and driving human-centered processes for ensuring security across an organization.
  • Strong judgment on risk: you know what actually matters and what's theater.
  • Deeply technical with excellent communication skills β€” able to work with software engineers and elementary school teachers equally well.
  • Hands-on experience designing or running a zero-trust environment (e.g., identity-based access, continuous verification, no implicit network trust).

Bonus

  • Edtech/FERPA/privacy background, CISSP, or OSCP.

This Role Will Excite You IF

  • You'd rather automate a security control than police it manually.
  • You design systems that are robust to inevitable human failure rather than aiming for perfect human compliance.
  • You want the full surface area β€” identity, IT, compliance, and AppSec β€” instead of a narrow slice of someone else's program.
  • A blank slate energizes you more than an inherited playbook does.
  • You want the thing you're protecting to matter: the education and personal data of 100,000+ students.

Team & Autonomy

You are the security team. You'll set the strategy, choose the tooling, and decide the sequencing, partnering closely with engineering, IT, and legal as you go. Expect wide latitude and very little process standing between you and shipping a control β€” along with the accountability that comes with being the person who owns the outcome.

Reporting Line

This role reports directly to the CTO.

EEO Statement

OpenEd is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

OpenEd participates in E-Verify.

Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Head of IT & Security @OpenEd
Information Technology
Salary usd 195,000 - 2..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,895+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later