Remote job

Pasito (YC S22) - Security & IT Manager

Silver

Source: AshbyLocation: Check country restrictionsPublished: Oct 09, 2026Confirmed active: Oct 09, 2026
Full-timeTechnology

Key points from the posting

Tech stack
VantaGoogle WorkspaceSSOMFAMDM
Seniority:
Senior

Automatically extracted

Our assessment

  • The posting states no salary. Comparable roles in our index (105 postings): median 5,000 euros per month, middle range 4,167 to 6,235 euros.
  • 2 more open roles from this employer in our index. 2 of them fully remote.

Automated assessment by nomado24, not an employer statement.

Job description

ABOUT PASITO https://pasito.ai

Pasito is the AI workspace for employee benefits.

We’re rethinking how group insurance and benefits are underwritten, delivered, used and measured - by the people who design them and the people who depend on them. Instead of static PDFs, disconnected systems, and manual workflows, Pasito brings plan design, payroll and benefits data, claims, and financial context into a single, AI-native workspace that helps benefits actually work for the 178 million Americans who depend on this system.

We don’t build for brokers, carriers and employers - we build with them. That collaboration shows up in everything we ship: AI agents that extract and structure plan data, tools that turn complexity into clarity for employees, and workflows that save carriers and consultants hundreds of hours per case.

Today, Pasito supports many of the largest insurance carriers and brokers in the U.S. We’re backed by Y Combinator, Insight Ventures and Core Innovation Capital, and we’re growing quickly. We ship fast, iterate relentlessly, and care deeply about building systems that are accurate, scalable, and human.

If you’re excited to work alongside exceptional operators and engineers, and apply AI in a legacy industry where precision and trust matter, Pasito is the place for you.

THE ROLE

We’re looking for a Security & IT Manager to be the first dedicated owner of Pasito’s security, IT, and compliance program. Today this work is split across engineering, sales, and operations: Vanta, audits, pen tests, device setup, access requests, and security questionnaires all land on different people. You’ll own it end to end and become the connective tissue between engineering, HR, legal, sales, our auditors, and our customers.

Security and compliance have been part of how we build from the start, because our customers place their trust in us every day and we support employees in some of their most important financial decisions. We’re HIPAA-regulated and SOC 2 Type II certified, and our customers’ security teams review us closely before every deal.

This is a high-visibility, high-impact role at the center of how Pasito runs. You’ll touch everything from how a new hire gets their laptop on day one, to how we message employees by SMS and email in compliance with U.S. law, to how fast we close a critical vulnerability. This is a senior hire by design: you’ve already run a security and compliance program, and you can pick this one up and run it largely on your own from day one.

WHAT YOU’LL DO

IT, ACCESS & DEVICE MANAGEMENT

  • Direct Pasito’s complete IT footprint, including domain management, Google Workspace, and our broader platform portfolio.
  • Oversee identity and permission governance: SSO, MFA, role-based controls, least-privilege architecture, and routine quarterly reviews.
  • Lead team onboarding and offboarding procedures, ensuring immediate provision of system access for new joiners and instant revocation upon departure.
  • Supervise organizational hardware via our MDM solution, handling enrollment, encryption protocols, patching cycles, endpoint protection, and inventory logging.
  • Act as the primary point of contact for internal IT issues and access requests.

SECURITY & COMPLIANCE PROGRAM

  • Vanta: Maintain daily operations within Vanta by resolving failing tests, delegating fixes, keeping audit trails current, and eliminating operational backlogs.
  • SOC 2 Type II: Manage the annual audit execution, from gathering documentation to control mapping and liaison with external auditing teams.
  • HIPAA: Ensure continuous alignment with HIPAA regulations, managing executed BAAs and operational policy frameworks.
  • Penetration testing: Facilitate yearly security evaluations from partner selection through remediation, validation, and package preparation for clients.
  • Vendor & subprocessor risk: Conduct thorough security evaluations of third-party vendors including AI, payroll, and HRIS tools, managing associated DPAs, BAAs, and public records.
  • Program hygiene: Drive policy updates, risk reviews, security training, and the upkeep of our internal trust resource hubs.
  • AI security: Establish AI risk governance models and monitor third-party artificial intelligence platform integration.

LEGAL & RISK PARTNERSHIP

  • Work closely with legal advisors to identify, analyze, and minimize potential security and compliance exposures across the organization.
  • Maintain an active risk log, offering transparent and consistent updates on organizational security posture to leadership.
  • Collaborate with leadership to ensure security and compliance as product expands and identify risks.

ENGINEERING REMEDIATION & PROJECT MANAGEMENT

  • Partner with software engineering teams to resolve vulnerabilities, audit items, and testing findings with clear accountability and timelines.
  • Lead operational security projects across departments, managing roadmaps, dependencies, and deliverables. …
ashbyOperations

This role is provided by an external source. Applications are handled on the source website.

New remote jobs like “Pasito” by email

Only when something fitting appears. Free, unsubscribe any time.

Confirm by email. Unsubscribe anytime. Privacy Policy.

All Remote IT Jobs from Home

Or let us search for you

Matching job categories

Not the right job?