Back to jobs
New

Senior IT Security Engineer

Remote (within the U.S.)

About The Role:

The Senior IT Security Engineer is a hands-on, cross-functional role within VentureWell’s Information Technology (IT) team, responsible for both secure systems engineering and cybersecurity governance, risk, and compliance (GRC). This role owns the security and reliability of VentureWell’s macOS fleet, SaaS ecosystem, and cloud infrastructure while supporting compliance with NIST SP 800-171 and CMMC Level 2.

This role is both strategic and execution-focused, requiring the ability to think holistically about how VentureWell’s systems and security posture should evolve, while also rolling up your sleeves to implement, support and continuously improve those systems in day-to-day operations.

You will proactively identify gaps and opportunities to strengthen security and system reliability and scalability, helping to mature VentureWell’s IT and security practices as the organization grows.

This position is ideal for someone who is equally comfortable engineering systems, securing them, and documenting how and why they are secured. You will work closely with IT leadership to implement security-by-design practices, respond to incidents, maintain audit readiness, and serve as a senior escalation point for complex technical and security issues.

You will operate with a high degree of autonomy, managing priorities across multiple systems and initiatives while balancing immediate operational needs with longer-term improvements.

Responsibilities:

Systems Engineering & IT Operations (40–45% of time)

  • Manage VentureWell’s device fleet (macOS, iOS, iPadOS) using Jamf, including configuration profiles, patching, encryption enforcement, and endpoint hardening
  • Configure, administer, and secure SaaS platforms including Google Workspace, Okta, Slack, Zoom, Salesforce, Box, and BetterCloud, including integrations and lifecycle management
  • Administer and maintain cloud-based systems and services (including AWS), partnering with vendors and internal teams to ensure uptime and security
  • Serve as the escalation point for complex technical issues related to SaaS platforms, device management, identity systems, and integrations
  • Maintain a transparent, documented SaaS application inventory and support software request review, vetting, and decision documentation
  • Develop and maintain SOPs and technical documentation for systems, integrations, and operational processes
  • Identify opportunities to improve system architecture, scalability, and reliability across SaaS and cloud environments and lead implementation of those improvements
  • Evaluate and recommend new tools, technologies and integrations to enhance system performance, security and operational efficiency
  • Drive continuous improvement of IT systems and processes, balancing day-to-day operational support with longer-term optimization initiatives

Security Operations & Threat Management (25–30% of time)

  • Monitor and respond to security alerts, vulnerability findings, and threat intelligence across endpoint, SaaS, and cloud environments
  • Perform root cause analysis on security incidents and recommend corrective actions
  • Manage endpoint security tooling and monitoring (e.g., Jamf Protect) and integrate telemetry with logging platforms (e.g., Datadog, CloudWatch)
  • Lead vulnerability scans, penetration test coordination, and remediation tracking
  • Review logs and security reports to identify risks, trends, and required remediation
  • Proactively identify security gaps, risks and emerging threats and implement improvements to strengthen VentureWell’s overall security posture
  • Continuously enhance monitoring, detection and response capabilities across endpoint, SaaS and cloud environments
  • Partner with internal team members to priorities and remediate vulnerabilities based on risk, business impact and organizational priorities 

Governance, Risk & Compliance (30% of time)

  • Support implementation and ongoing maintenance of NIST SP 800-171 and CMMC Level 2 controls
  • Maintain and update the System Security Plan (SSP) and Plan of Action & Milestones (POA&M)
  • Draft, review, and maintain security policies, standards, baselines, and procedures
  • Conduct Security Impact Analyses (SIA) for system changes, integrations, or architectural decisions
  • Coordinate evidence collection and support internal and external audits
  • Ensure secure configuration baselines are defined, documented, and reviewed on a regular basis
  • Identify gaps in existing controls and lead efforts to strengthen and mature VentureWell’s compliance and security frameworks
  • Translate compliance requirements (i.e. NIST 800-171, CMMC) into scalable, practical technical and operational solutions
  • Drive continuous improvement of documentation, policies and control implementation to support audit readiness and long-term program maturity 

 

What You Bring:

Experience & Skills

  • 7+ years of experience in IT systems engineering, security engineering, or a combined role
  • Practical experience implementing or supporting cybersecurity compliance frameworks, particularly NIST 800-171 and/or CMMC
  • Strong hands-on experience using Jamf to manage macOS environments, including policy creation and enforcement 
  • Experience administering SaaS platforms such as Google Workspace, Okta, Slack, Zoom, Salesforce, and Box
  • Experience managing or securing Linux-based systems (Ubuntu, CentOS) in cloud environments
  • Working knowledge of scripting or automation (Bash, Python, or similar)
  • Strong understanding of security principles including least privilege, defense in depth, and zero trust
  • Experience with vulnerability management, log aggregation, and monitoring/SIEM tools
  • Ability to clearly document technical configurations, security controls, and processes
  • Proven ability to operate independently, prioritize effectively, and drive initiatives forward with minimal oversight
  • Ability to identify gaps and recommend scalable solutions to improve security posture, system reliability and operational efficiency
  • Demonstrated ability to balance hands-on operational support with longer-term system and security improvements

Preferred Certifications (one or more)

  • Jamf 200, 300, or 370 (Endpoint Security Admin)
  • CompTIA Security+ 
  • AWS Certified Security – Specialty 
  • GIAC Information Security Fundamentals (GISF) or Security Essentials (GSEC)
  • ISC2 Certified in Cybersecurity (CC) or CISSP (Associate)
  • Certified CMMC Professional (CCP) or NIST 800-171 Implementer 
  • Google Professional Workspace Administrator

Across the Board, VentureWell Staff:

  • Are able to succeed and thrive in an environment with competing and changing priorities and tight deadlines
  • Have track records of and ability to build solid collaborative working relationships, and are proven team players who enjoy a “customer service” orientation to collaboration
  • Are committed to embedding equity for all in our internal practices and culture and in our programs in order to live and achieve our mission
  • Bring openness and engagement to personal, professional, and organization-wide learning
  • Are curious and committed to issues of environmental sustainability
  • Are self-starters with excellent attention to detail and a commitment to delivering high-quality work 
  • Are active learners who independently learn new tools and work processes quickly
  • Have excellent written and oral communication skills

Our Benefits*:

  • An attractive and equitable compensation package, including: 
    • a salary range of $115,000 - $140,000 commensurate with experience and internal equity
    • 403 (b) with 200% match up to a maximum contribution from VentureWell of 10% when the employee puts in 5% (eligible after one year of service for the match)
    • Medical, Dental, and Vision insurance
    • $1,000 home office stipend upon hire
  • A true focus on work-life balance with work weeks that reflect that
    • It’s our aim for our employees in this position to not work more than a 40-hour workweek 
    • 20 paid vacation days
    • 12 paid holidays 
    • 12 paid wellness days 

*Benefits are reviewed each fiscal year and may be subject to change.

What We Offer:

  • A culture where people work intentionally and collaboratively in pursuit of our mission  
  • Values we believe in

About VentureWell: 

VentureWell supports the cultivation of science and technology inventors and the innovation and entrepreneurship ecosystems critical to their success. Since its founding in 1995, VentureWell has funded or trained over 20,500 early-stage science and technology inventors and innovators, resulting in the emergence of more than 6,700+ ventures with groundbreaking technological advancements in fields like biomedicine and healthcare, sustainable energy and materials, and solutions for low-resource settings. The ventures it has supported have raised subsequent funds totaling more than $9.0 billion and are reaching millions of people globally.

Visit venturewell.org to learn more.

Create a Job Alert

Interested in building your career at VentureWell? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...
Select...
Select...
Which security monitoring and assessment tools do you have experience with? (Select all that apply.) *
Select...
Which certifications do you have? (Check all that apply) *
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in VentureWell’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.