Head of IT & Security

OpenEd

United States

On-site

USD 140,000 - 180,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

OpenEd is seeking a founding Security Engineer to build and own our security program for 100,000+ students and families. You will lead identity and access, corporate IT security, compliance, and application security initiatives with autonomy and a hands-on approach.

The role demands deep technical expertise and the ability to collaborate with engineers and educators alike. You will report to the CTO, shape the security strategy, establish zero-trust concepts, and drive SOC 2 Type II readiness

Qualifications

  • 6+ years in security, ideally in a regulated vertical (finance, education, healthcare).
  • Hands-on across IT/identity and security operations — not just advisory.
  • You've taken an org through SOC 2 (or ISO 27001).
  • Experienced at establishing and driving human-centered processes for ensuring security across an organization.
  • Strong judgment on risk: you know what actually matters and what's theater.
  • Deeply technical with excellent communication skills — able to work with software engineers and elementary school teachers equally well.
  • Hands-on experience designing or running a zero-trust environment (e.g., identity-based access, continuous verification, no implicit network trust).
  • Bonus: Edtech/FERPA/privacy background, CISSP, or OSCP.

Responsibilities

  • Own four programs end to end: Identity & access; Corporate IT security; Compliance; Application security.
  • Manage SSO/SAML, MFA, provisioning, least-privilege access model, and onboarding/offboarding.
  • Oversee Endpoint/MDM, SaaS and vendor risk, phishing awareness, and incident response playbooks.
  • Drive SOC 2 Type II readiness, map FERPA/COPPA/state privacy controls, and own audits and outcomes.
  • Contribute to AppSec initiatives (SAST/DAST/SCA in CI), triage remediation with engineers, and run external pen tests.

Skills

Security engineering
Identity & access management
SOC 2
Zero-trust
Vulnerability management
Edtech security

Job description

About OpenEd

At OpenEd, we’re opening the world to every learner. With over 100,000 students served and growing rapidly, families trust us as a partner to the most precious thing in their lives, their children. Our vision: a future where education is no longer constrained by geography, rigid models, or outdated systems. Our mission: to give every student customized, world-class education and resources, empowering families and opening millions of doors for learners across the country.

Our Culture (The Foundation of Everything We Do)

Culture at OpenEd is intentional. It’s defined by what we promote—and what we tolerate. Our latest eNPS (employee net promoter score) of 79 places OpenEd in the top .1% of technology companies. Our values aren't just words; they are non-negotiable principles that guide every decision:

  • Customer First – Obsessed with delivering value; we fight tirelessly for our learners and families.

  • Hard Choices, Easy Life – Face challenges directly, swiftly, and transparently.

  • I Did > We Should – Action over theory; bring experiments, not just opinions.

  • Learn Out Loud – Share your growth openly; feedback is a gift, ego is the enemy.

  • Prioritize Ruthlessly – Excellence in the few critical areas over mediocrity everywhere.

  • Fast AND World Class – Speed doesn’t compromise quality.

  • Strong Opinions, Weakly Held – Advocate passionately, adjust readily.

  • Make Others Famous – Elevate your colleagues, partners, and community.

We're currently accepting applications from those living in: AR, AZ, CO, FL, GA, ID, IN, IL, IO, KS, KY, MA, MD, MN, MO, MT, ND, NC, NM, NV, NY, OH, OK, OR, RI, SC, TN, TX, UT, VA, WA, WI, WV.

About the Role

As the founding Security Engineer at OpenEd, you'll join a small, high-impact team changing the nature of education. This is a truly unique opportunity to be the founding member of our security team, and to ensure we earn the trust of families that their student's education — and data — is safe with us.

You'll own the IT, identity, and compliance programs directly, with a broad range of responsibilities and the autonomy to tackle them as you see fit. We serve over 100,000 students, which means the security bar isn't theoretical: it’s the reason families keep trusting us with their kids.

Your Immediate Impact

You'll own four programs end to end:

  • Identity & access: SSO/SAML, MFA, provisioning, a least-privilege access model, and reliable onboarding/offboarding.

  • Corporate/IT security: Endpoint/MDM, SaaS and vendor risk, the phishing and awareness program, and incident response playbooks.

  • Compliance: Drive SOC 2 (Type II), map FERPA/COPPA/state privacy controls, and own audits and their outcomes.

  • Application security: Contribute to key AppSec initiatives (SAST/DAST/SCA in CI), triage and drive remediation with engineers, and run external pen test audits.

Success Metrics:

In your first 12 months:

  • Compliance: SOC 2 Type II readiness completed, gaps remediated, and the audit window passed with no material exceptions.

  • Identity: Every employee and contractor on SSO with MFA enforced, access granted by least-privilege role, and onboarding/offboarding running on automated provisioning with same-day deprovisioning.

  • Endpoint coverage: Full MDM enrollment across the fleet with enforced, documented baselines.

  • Vulnerability management: SAST/DAST/SCA running in CI, severity-based remediation SLAs consistently met, and an annual external pen test with findings tracked to closure.

  • Readiness: Incident response playbooks documented and exercised, and a phishing/awareness program running with measurably improving results.

  • Privacy: FERPA, COPPA, and state privacy requirements mapped to controls with evidence collection that doesn't depend on a fire drill.

Who You Are:
  • 6+ years in security, ideally in a regulated vertical (finance, education, healthcare).

  • Hands-on across IT/identity and security operations — not just advisory.

  • You've taken an org through SOC 2 (or ISO 27001).

  • Experienced at establishing and driving human-centered processes for ensuring security across an organization.

  • Strong judgment on risk: you know what actually matters and what's theater.

  • Deeply technical with excellent communication skills — able to work with software engineers and elementary school teachers equally well.

  • Hands-on experience designing or running a zero-trust environment (e.g., identity-based access, continuous verification, no implicit network trust).

  • Bonus: Edtech/FERPA/privacy background, CISSP, or OSCP.

This Role Will Excite You IF:
  • You'd rather automate a security control than police it manually.

  • You design systems that are robust to inevitable human failure rather than aiming for perfect human compliance.

  • You want the full surface area — identity, IT, compliance, and AppSec — instead of a narrow slice of someone else's program.

  • A blank slate energizes you more than an inherited playbook does.

  • You want the thing you're protecting to matter: the education and personal data of 100,000+ students.

Team & Autonomy:

You are the security team. You'll set the strategy, choose the tooling, and decide the sequencing, partnering closely with engineering, IT, and legal as you go. Expect wide latitude and very little process standing between you and shipping a control — along with the accountability that comes with being the person who owns the outcome.

Reporting Line:

This role reports directly to the CTO.

EEO Statement

OpenEd is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.

OpenEd participates in E-Verify.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Head of IT & Security
Head of IT & Security

OpenEd • Northern (KY)

Hybrid
USD 120,000 - 180,000
Staff Product Engineer
Staff Product Engineer

OpenEd • Northern (KY)

Hybrid
USD 140,000 - 190,000
Staff Product Engineer
Staff Product Engineer

OpenEd • United States

On-site
USD 150,000 - 210,000
Founding Security Engineer & IT Leader
Founding Security Engineer & IT Leader

OpenEd • Northern (KY)

Hybrid
USD 120,000 - 180,000
Founding IT & Security Leader
Founding IT & Security Leader

OpenEd • United States

On-site
USD 140,000 - 180,000
Head of Security (Cloud, Corporate & Physical)
Head of Security (Cloud, Corporate & Physical)

StudyFetch Inc. • Beverly Hills (CA)

On-site
USD 180,000 - 240,000
Employer-paid Medical, Dental, and Vis
401(k) with employer matching
Daily team dinner provided in-office
Director of Customer Success, Operations
Director of Customer Success, Operations

OpenEd • Northern (KY)

Hybrid
USD 120,000 - 180,000
Competitive compensation
401(k) with company matching
Comprehensive health benefits
+3
Software Engineer Security – Remote US – Paraform
Software Engineer Security – Remote US – Paraform

Syndesus, Inc. • United States

Remote
USD 180,000 - 230,000
Health insurance
Unlimited PTO
Parental leave
+1
Enterprise Security Engineer
Enterprise Security Engineer

Opendoor • Miami (FL)

On-site
USD 110,000 - 140,000
Vulnerability & Attack Surface Management Analyst II
Vulnerability & Attack Surface Management Analyst II

OpenLoop Health • United States

Hybrid
USD 110,000 - 140,000
Competitive compensation
Medical, Dental & Vision
Flexible Spending / Health Savings
+4