
Director of IT & Security
Who We Are
At Moxxi, we’re redefining performance marketing with cutting-edge technology and a relentless focus on results. As a profitable, bootstrapped start-up, we are led by a team of industry veterans in performance marketing, ad tech, and digital publishing. Together, we’re building the premier platform to incubate, scale, and optimize digitally born businesses, setting new standards for data-driven success.
Our entrepreneurial team brings proven experience from both global corporations and fast-growing startups. We’re passionate about delivering scalable, profitable outcomes for our partners through advanced profiling, targeting, and continuous optimization. Joining Moxxi means becoming part of a growing start-up in the heart of NYC, where you’ll have the opportunity to accelerate your career, expand your skill set, and shape the future of performance marketing.
The Opportunity
We're hiring a Director, IT & Security to own internal technology end-to-end: the systems, access, security, and infrastructure behind everything we do. You'll run the day-to-day, set the strategy, and operate as the company's most senior owner of internal technology, reporting to the Head of Engineering.
Our team works across a multi-entity portfolio, with multiple tenants across the tools we rely on and access that must be provisioned and revoked cleanly everywhere, from the SaaS stack to our proprietary platform. Managing it well is table stakes. The real mandate is a point of view on the architecture: what to consolidate, what to standardize, what to automate, and how to make a complex footprint feel simple to the people who work inside it.
Security carries equal weight. You'll own it end to end: the baseline of identity and access, the office network, our defenses against cyber threats, and the practices that keep the company safe as it scales. The environment will keep changing, and part of the job is staying ahead of it.
Done right, internal technology becomes a source of speed and trust: invisible when it works, decisive when it matters. This is a build-and-own role for an operator who combines hands-on range with systems thinking and wants the whole problem, not a slice of it.
What You'll Drive
IT Operations and Systems
- Own administration and lifecycle management across our core stack: Microsoft 365, Google Workspace, Slack, Linear, Jira, Zendesk, and AI applications (Cursor, ChatGPT, Claude).
- Run onboarding and offboarding end to end, provisioning and revoking access cleanly and quickly across every system and entity.
- Own vendor relationships, subscriptions, licensing, and spend. Know what we pay for, what we use, and where consolidation creates leverage.
- Serve as the escalation point for the team's day-to-day IT needs, resolving issues directly and building the processes and automation that prevent them.
Identity and Access Across the Portfolio
- Own identity and access management across multiple entities and tenants.
- Own credential and secrets management, including the password manager, shared-credential hygiene, and how privileged access is stored, rotated, and revoked.
- Administer user access into our proprietary platform, with a path toward role-based access control as our internal tooling matures.
- Define the target-state architecture for identity and access across the portfolio, and drive us there.
Security
- Own the security baseline across identity, MFA and SSO, endpoint protection, access reviews, and vendor risk.
- Set the guardrails for AI usage: which tools are approved, what data can go into them, and how tenant configuration and retention are managed.
- Own the security of our office network, from wifi to perimeter, hands-on or through the right vendors, and adapt the setup as how we work evolves.
- Drive our defenses against cyber threats, from phishing and account compromise to incident readiness and response.
- Keep our corporate domains trusted: email authentication and anti-spoofing (SPF, DKIM, DMARC), with the registrar and DNS accounts behind them locked down.
- Bring a security and operations lens to domain architecture and process, partnering with the engineering team that runs day-to-day domain operations.
- Establish practical policies and standards that fit a fast-moving company, and build security awareness into how the whole team operates.
Corporate Information Management
- Own file architecture, sharing standards, and governance at the corporate level across the portfolio.
- Set sane defaults so information is easy to find, simple to share, and secure without anyone thinking about it.
- Own backups, business continuity, and disaster recovery for corporate systems, including verifying that recovery actually works.
What You Bring
- 6+ years in IT, systems administration, or IT operations, including 3+ years owning IT end to end at a growing company, not as one seat inside a large IT organization.
- Deep hands-on administration experience across the modern SaaS stack: Microsoft 365, Google Workspace, Slack, and the identity and access management that ties them together.
- A working command of security fundamentals across identity, network, endpoints, and access, with the judgment to prioritize what matters most.
- Enough command of DNS and email authentication (SPF, DKIM, DMARC) to keep corporate domains trusted and their accounts secure.
- Fluency with AI tools. You use LLMs and AI tooling daily to script, automate, troubleshoot, and get up to speed on unfamiliar systems. This is a requirement, not a nice-to-have.
- Technical range. You script and automate to remove manual work, or you have the drive to build that muscle fast.
- A point of view. You have a track record of designing systems and processes, not just running them, and of bringing order to complexity.
- Unflappable range. Scope here shifts as the company grows, and you absorb new surface area as part of the job, not an exception to it.
- Exceptional judgment and communication. You operate independently, prioritize ruthlessly, and explain technical trade-offs clearly to non-technical stakeholders.
- Start-up DNA: bias for action, low ego, willingness to roll up sleeves and operate with limited resources. Comfort operating in a high-pace, always-on, real-time business.
Bonus Points
- Experience managing IT across multiple corporate entities, tenants, or a portfolio of companies.
- Experience administering an internal or proprietary application with user access management.
- Experience with MDM and endpoint management (e.g., Intune, Jamf).
- Exposure to SOC 2, ISO 27001, or similar frameworks, and what it takes to get an organization ready for them.
- Relevant certifications (e.g., Microsoft 365, Google Workspace, CompTIA, security).
How We Work
- Bias for results. We value outcomes over output.
- Autonomy with accountability. You'll own problems end to end while staying tightly aligned with leadership.
- Build fast, learn faster. We prototype, test, and iterate, and we use AI to move quicker.
- Radical candor. Feedback is given early and often. Ideas win on merit.
- Ownership. You'll build the function, not just run it.
Compensation
The base salary range for this role is $165,000 to $210,000, depending on experience.
Salary Range
$165,000 - $210,000 USD
Create a Job Alert
Interested in building your career at Moxxi Digital? Get future opportunities sent straight to your email.
Apply for this job
*
indicates a required field