Home › Companies › Mirrorweb › Senior IT & Security Engineer
Senior IT & Security Engineer
Mirrorweb · Austin, Texas, 78701, United States · Active · BambooHR
Job facts
| Field | Value |
|---|---|
| Company | Mirrorweb |
| Title | Senior IT & Security Engineer |
| Normalized title | - |
| Department / team | Operations |
| Location | Austin, United States |
| Work model | - |
| Employment type | Full Time |
| Salary | - |
| Status | active |
| ATS provider | BambooHR |
| Posted / first seen | 2026-06-02 / 2026-06-03 |
| Changed / last seen | 2026-06-03 / 2026-06-18 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from Mirrorweb. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through BambooHR. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| City jobs | Active postings in Austin. | Open |
| Department jobs | Active postings in Operations. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | Mirrorweb |
| Source | e28f6901-6fcb-4461-9c0d-4b21f65dbaa7 |
| ATS provider | BambooHR |
Description
The role
MirrorWeb runs a compliance archiving platform for regulated financial services firms, so our own internal security posture has to be exemplary. The core systems are already in place and working. We need one capable, self-sufficient person to take them over, run them well day to day for a company of close to 100 users, and push our security posture forward as we move into an AI agentic world.
This is not a from-scratch build. Identity through Okta, the Kandji-managed Mac fleet, email on Microsoft 365, endpoint security, and our ISO 27001 and SOC 2 programmes all exist. What we want is someone who keeps that estate running cleanly and handles the harder support escalations, and who brings a builder's instinct to the security layer on top: evaluating and rolling out new tooling, leading our DLP rollout, and rethinking how we secure a fleet of Macs as AI agents become part of daily work. You will own the function without day-to-day oversight, and there is scope to bring on a junior team member reporting to you as the company grows. We run on Claude across the company, so the right person will be at home in a heavily AI-native environment.
How we work with AI
MirrorWeb is a heavily AI-native company and this role sits at the centre of it. We run on Claude, with Claude Code, Cursor and Codex used daily across engineering and an extensive internal ecosystem of MCP servers and agents that the business relies on. We expect you to already be a very strong, hands-on user of Claude and AI coding tools, using them as a force multiplier in your own work rather than as an occasional aid. Just as important, you will help us adopt AI safely: securing the AI surface, governing access for agents and MCP services, and getting ahead of the new questions an agentic environment raises.
What you will own
Advancing our security posture: this is where the role earns its keep. Continuously look for ways to improve how we protect the business, evaluate and roll out new security tooling, lead our data loss prevention (DLP) rollout across email, endpoints, and AI tooling, and harden the Mac fleet for an environment where agents and AI tools are running on endpoints.
Identity and access (Okta): Okta is our directory. Administer it day to day, keep SSO, MFA, and conditional access policy healthy, run the joiner-mover-leaver process, maintain least privilege, and run regular access reviews.
Apple fleet via Kandji: onboarding, configuration, patching, device compliance, and offboarding across a Mac-only estate, with an eye on tightening the security model over time.
Microsoft 365 (email): Exchange Online administration, mail flow, and email security: anti-phishing, anti-spam, SPF, DKIM, DMARC, and DLP on outbound mail.
Endpoint and security operations: keep EDR, hardening baselines, vulnerability management, and alerting running, and lead incident response when something happens.
Internal IT support (escalation): act as the escalation point for internal IT across roughly 100 users. The support team handles level 1; anything more complex comes to you. Hold the triage boundary with the support team and resolve the harder problems.
AI security and governance: keep AI tooling adopted safely across the company, watch for data leakage through LLMs and shadow AI, maintain access controls for agents and internal MCP services, and keep our AI usage policy enforced and current.
Compliance operations: run the ISO 27001 ISMS day to day, keep evidence current in Drata, support SOC 2, and turn around customer and investor security questionnaires and DDQs promptly.
What you need
Several years running IT and security in an established environment, ideally as the sole or lead owner at a regulated or fintech SaaS company.
A track record of improving security posture, not just maintaining it. You have evaluated, selected, and rolled out security tooling, and ideally led a DLP rollout.
Hands-on Okta administration: managing SSO, MFA, conditional access, and lifecycle in a live directory.
Proven management of a Mac fleet through an MDM such as Kandji or Jamf, with a real point of view on securing macOS endpoints. This is a hard requirement, not a nice-to-have.
Solid Microsoft 365 email administration: Exchange Online, mail flow, and email security (anti-phishing, SPF, DKIM, DMARC).
Operational security experience: endpoint security, vulnerability management, and handling incidents calmly.
Comfort maintaining and extending scripts and automation, even if you are not building large systems from scratch.
Working knowledge of ISO 27001 and SOC 2 as an operator who has kept evidence current and been through audits, plus comfort with GRC tooling like Drata.
Very good, hands-on experience using Claude and AI coding tools (such as Claude Code or Cursor) in your daily work. This is a core requirement: you should already use AI as a force multiplier and be able to reason about the security questions an agentic environment raises.
A genuine service mindset. You will be the escalation point for everyone in the company, so you need to handle people well and stay responsive.
Self-directed and trustworthy. You will hold privileged access to everything, so reliability, judgment, and discretion matter as much as technical skill.
Nice to have
Exposure to regulated financial services and to responding to investor or customer due diligence.
AWS security experience.
Experience securing AI or agentic systems.
Experience that would let you mentor and lead a junior hire later.
Relevant certifications (CISSP, Security+, or similar) are a useful signal but not a requirement.
Who you are
You are a reliable operator who keeps things running without being chased, and you are not content to just keep the lights on. You spot gaps before they become problems, bring ideas for how to make us more secure, and follow through on rolling them out. You are comfortable being the only person in the seat for now, you document as you go, you keep the CTO informed rather than asking permission for each step, and you are discreet with the access you hold.
What success looks like in year one
The estate runs smoothly with nothing slipping: identity, Mac fleet, email, and endpoint security all healthy.
A DLP solution is rolled out across email, endpoints, and AI tooling.
The Mac fleet security model is measurably tighter and fit for an agentic AI environment.
At least one meaningful new security tooling improvement is evaluated and shipped.
The ISMS runs cleanly through an audit cycle and DDQ turnaround stays quick.
Internal IT escalations are handled cleanly, with a clear level 1 boundary holding.
Full job record
| Job ID | da8ed222fabfeb127bd51256397d3aa682551011 |
| Org ID | 595a0457-0c9a-441f-8989-db8df89943f8 |
| Source ID | e28f6901-6fcb-4461-9c0d-4b21f65dbaa7 |
| Board ID | e28f6901-6fcb-4461-9c0d-4b21f65dbaa7 |
| Provider | bamboohr |
| Provider Job Key | 80 |
| Title | Senior IT & Security Engineer |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | Austin, Texas, 78701, United States |
| Department | Operations |
| Team | — |
| Employment Type | full_time |
| Workplace Type | — |
| Remote Policy | — |
| Country | United States |
| Region | — |
| City | Austin |
| Salary Raw | — |
| Salary Min | — |
| Salary Max | — |
| Salary Currency | — |
| Salary Period | — |
| Source URL | https://mirrorweb.bamboohr.com/careers/80 |
| Apply URL | https://mirrorweb.bamboohr.com/careers/80 |
| First Seen At | 2026-06-03 10:39:03Z |
| Last Seen At | 2026-06-18 10:34:54Z |
| Last Checked At | 2026-06-18 10:34:54Z |
| Last Changed At | 2026-06-03 10:39:03Z |
| Inactive At | — |
| Source Posted At | 2026-06-02 00:00:00Z |
| Source Updated At | — |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=bamboohr/board=mirrorweb/date=2026-06-18/2026-06-18T10-34-52-957Z-ae2efe444adec109b1d6f06d5adedee21ca97ff03d10eba6b0eaf31ffdde602c.json |
Event Fields
{
"content_hash": "46734d386c7f2b8bd8f226db033b7757563e97dae9453a7854922bf0b0002906",
"source_hash": "30efe18cb15b79269f7bd35b73dfa5aab87dec3a48ccea2631a1ac41cc7cb3f3",
"last_changed_at": "2026-06-03T10:39:03.821Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "Austin, Texas, 78701, United States",
"city": "Austin",
"region": null,
"country": "United States",
"is_remote": false,
"confidence": 0.95
},
"salary_max": null,
"salary_min": null,
"inferred_at": "2026-06-18T10:34:54.580Z",
"launch_scope": {
"reason": "bamboohr_production_catalog",
"included": true,
"location": {
"raw": "Austin, Texas, 78701, United States",
"city": "Austin",
"region": null,
"country": "United States",
"is_remote": false,
"confidence": 0.95
},
"countries": [
"United States"
]
},
"remote_policy": null,
"salary_period": null,
"workplace_type": null,
"salary_currency": null
}Extensions
{}Native Structured
{
"list_job": {
"id": "80",
"isRemote": null,
"location": {
"city": "Austin",
"state": "Texas"
},
"atsLocation": {
"city": null,
"state": null,
"country": null,
"province": null
},
"departmentId": "18638",
"locationType": "2",
"jobOpeningName": "Senior IT & Security Engineer",
"departmentLabel": "Operations",
"employmentStatusLabel": "Full-Time"
},
"detail_errors": [],
"detail_job_opening": {
"location": {
"city": "Austin",
"state": "Texas",
"postalCode": "78701",
"addressCountry": "United States"
},
"datePosted": "2026-06-02",
"atsLocation": {
"city": null,
"state": null,
"country": null,
"countryId": null
},
"description": "<p><span style=\"font-weight: bold\">The role</span></p>\n<p><br></p>\n<p>MirrorWeb runs a compliance archiving platform for regulated financial services firms, so our own internal security posture has to be exemplary. The core systems are already in place and working. We need one capable, self-sufficient person to take them over, run them well day to day for a company of close to 100 users, and push our security posture forward as we move into an AI agentic world.</p>\n<p><br>This is not a from-scratch build. Identity through Okta, the Kandji-managed Mac fleet, email on Microsoft 365, endpoint security, and our ISO 27001 and SOC 2 programmes all exist. What we want is someone who keeps that estate running cleanly and handles the harder support escalations, and who brings a builder's instinct to the security layer on top: evaluating and rolling out new tooling, leading our DLP rollout, and rethinking how we secure a fleet of Macs as AI agents become part of daily work. You will own the function without day-to-day oversight, and there is scope to bring on a junior team member reporting to you as the company grows. We run on Claude across the company, so the right person will be at home in a heavily AI-native environment.</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">How we work with AI</span></p>\n<p><br></p>\n<p>MirrorWeb is a heavily AI-native company and this role sits at the centre of it. We run on Claude, with Claude Code, Cursor and Codex used daily across engineering and an extensive internal ecosystem of MCP servers and agents that the business relies on. We expect you to already be a very strong, hands-on user of Claude and AI coding tools, using them as a force multiplier in your own work rather than as an occasional aid. Just as important, you will help us adopt AI safely: securing the AI surface, governing access for agents and MCP services, and getting ahead of the new questions an agentic environment raises.</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">What you will own</span></p>\n<p><br></p>\n<ul>\n<li><span style=\"font-weight: bold\">Advancing our security posture:</span> this is where the role earns its keep. Continuously look for ways to improve how we protect the business, evaluate and roll out new security tooling, lead our data loss prevention (DLP) rollout across email, endpoints, and AI tooling, and harden the Mac fleet for an environment where agents and AI tools are running on endpoints.</li>\n<li><span style=\"font-weight: bold\">Identity and access (Okta):</span> Okta is our directory. Administer it day to day, keep SSO, MFA, and conditional access policy healthy, run the joiner-mover-leaver process, maintain least privilege, and run regular access reviews.</li>\n<li><span style=\"font-weight: bold\">Apple fleet via Kandji:</span> onboarding, configuration, patching, device compliance, and offboarding across a Mac-only estate, with an eye on tightening the security model over time.</li>\n<li><span style=\"font-weight: bold\">Microsoft 365 (email):</span> Exchange Online administration, mail flow, and email security: anti-phishing, anti-spam, SPF, DKIM, DMARC, and DLP on outbound mail.</li>\n<li><span style=\"font-weight: bold\">Endpoint and security operations:</span> keep EDR, hardening baselines, vulnerability management, and alerting running, and lead incident response when something happens.</li>\n<li><span style=\"font-weight: bold\">Internal IT support (escalation):</span> act as the escalation point for internal IT across roughly 100 users. The support team handles level 1; anything more complex comes to you. Hold the triage boundary with the support team and resolve the harder problems.</li>\n<li><span style=\"font-weight: bold\">AI security and governance:</span> keep AI tooling adopted safely across the company, watch for data leakage through LLMs and shadow AI, maintain access controls for agents and internal MCP services, and keep our AI usage policy enforced and current.</li>\n<li><span style=\"font-weight: bold\">Compliance operations:</span> run the ISO 27001 ISMS day to day, keep evidence current in Drata, support SOC 2, and turn around customer and investor security questionnaires and DDQs promptly.</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">What you need</span></p>\n<p><br></p>\n<ul>\n<li>Several years running IT and security in an established environment, ideally as the sole or lead owner at a regulated or fintech SaaS company.</li>\n<li>A track record of improving security posture, not just maintaining it. You have evaluated, selected, and rolled out security tooling, and ideally led a DLP rollout.</li>\n<li>Hands-on Okta administration: managing SSO, MFA, conditional access, and lifecycle in a live directory.</li>\n<li>Proven management of a Mac fleet through an MDM such as Kandji or Jamf, with a real point of view on securing macOS endpoints. This is a hard requirement, not a nice-to-have.</li>\n<li>Solid Microsoft 365 email administration: Exchange Online, mail flow, and email security (anti-phishing, SPF, DKIM, DMARC).</li>\n<li>Operational security experience: endpoint security, vulnerability management, and handling incidents calmly.</li>\n<li>Comfort maintaining and extending scripts and automation, even if you are not building large systems from scratch.</li>\n<li>Working knowledge of ISO 27001 and SOC 2 as an operator who has kept evidence current and been through audits, plus comfort with GRC tooling like Drata.</li>\n<li>Very good, hands-on experience using Claude and AI coding tools (such as Claude Code or Cursor) in your daily work. This is a core requirement: you should already use AI as a force multiplier and be able to reason about the security questions an agentic environment raises.</li>\n<li>A genuine service mindset. You will be the escalation point for everyone in the company, so you need to handle people well and stay responsive.</li>\n<li>Self-directed and trustworthy. You will hold privileged access to everything, so reliability, judgment, and discretion matter as much as technical skill.</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Nice to have</span></p>\n<p><br></p>\n<ul>\n<li>Exposure to regulated financial services and to responding to investor or customer due diligence.</li>\n<li>AWS security experience.</li>\n<li>Experience securing AI or agentic systems.</li>\n<li>Experience that would let you mentor and lead a junior hire later.</li>\n<li>Relevant certifications (CISSP, Security+, or similar) are a useful signal but not a requirement.</li>\n</ul>\n<p><br></p>\n<p><span style=\"font-weight: bold\">Who you are</span></p>\n<p><br></p>\n<p>You are a reliable operator who keeps things running without being chased, and you are not content to just keep the lights on. You spot gaps before they become problems, bring ideas for how to make us more secure, and follow through on rolling them out. You are comfortable being the only person in the seat for now, you document as you go, you keep the CTO informed rather than asking permission for each step, and you are discreet with the access you hold.</p>\n<p><br></p>\n<p><span style=\"font-weight: bold\">What success looks like in year one</span></p>\n<p><br></p>\n<ul>\n<li>The estate runs smoothly with nothing slipping: identity, Mac fleet, email, and endpoint security all healthy.</li>\n<li>A DLP solution is rolled out across email, endpoints, and AI tooling.</li>\n<li>The Mac fleet security model is measurably tighter and fit for an agentic AI environment.</li>\n<li>At least one meaningful new security tooling improvement is evaluated and shipped.</li>\n<li>The ISMS runs cleanly through an audit cycle and DDQ turnaround stays quick.</li>\n<li>Internal IT escalations are handled cleanly, with a clear level 1 boundary holding.</li>\n</ul>",
"compensation": null,
"departmentId": "18638",
"locationType": "2",
"seekPromoted": false,
"jobCategoryId": null,
"jobOpeningName": "Senior IT & Security Engineer",
"departmentLabel": "Operations",
"jobOpeningStatus": "Open",
"minimumExperience": null,
"jobOpeningShareUrl": "https://mirrorweb.bamboohr.com/careers/80",
"employmentStatusLabel": "Full-Time"
}
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/da8ed222fabfeb127bd51256397d3aa682551011?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/595a0457-0c9a-441f-8989-db8df89943f8JSONGET https://api.bluedoor.sh/job-postings/v1/sources/e28f6901-6fcb-4461-9c0d-4b21f65dbaa7JSONGET https://api.bluedoor.sh/job-postings/v1/jobs/da8ed222fabfeb127bd51256397d3aa682551011/eventsJSON