IT Security Specialist
Axios · Remote
About this role
## IT Security Specialist — Axios ### The big picture Axios is a media company dedicated to delivering trustworthy news and information with efficiency, clarity, and Smart Brevity. We’re hiring an **IT Security Specialist** on our IT team to help protect the systems, devices, identities, applications, and workflows that power the company. ### Why it matters Security at Axios isn’t just about deploying tools or responding to vulnerabilities. It’s about understanding how systems are used, assessing whether they’re fit for purpose, and identifying risk created by workflows, permissions, configurations, vendors, and user behavior. This role helps **de-risk current and future solutions** by embedding security into technology decisions—from evaluation and procurement through implementation, monitoring, and continuous improvement. ### Go deeper — What you’ll own In this role, you’ll own key areas of Axios’ corporate security environment, including: - Endpoint security - Identity and access management - Google Workspace - SaaS security - Security monitoring - Security awareness - AI security You’ll also treat the **browser as a critical security boundary**, since it’s often the “operating system” for how people access data, applications, and business workflows. #### In this role, you will: - **Own security for Axios’ Mac fleet**, including Jamf, compliance, monitoring, alert investigation, malware response, and device remediation. - **Own Okta-based identity and access management**, including adaptive MFA, authentication, SSO, application assignments, access scopes, and joiner/mover/leaver processes. - **Partner with People, Legal, and Infrastructure** to improve provisioning, offboarding, access removal, archival, legal holds, and lifecycle automation. - **Establish and maintain security configurations and risk controls** for core services and SaaS applications (authentication, access, collaboration, email security, data protection, alerting, activity monitoring, vendor/procurement reviews, security questionnaires, evidence gathering, and recommended safeguards). - **Treat the browser and SaaS layer as critical security boundaries**, evaluating how users access data and applications and where browser-based workflows create risk. - **Use logs and activity monitoring** across endpoints, browsers, identity systems, Google Workspace, and SaaS applications to investigate suspicious activity and support incident response. - **Assess systems, tools, permissions, and workflows** for security, operational fit, and long-term supportability. - **Help protect high-risk users** (e.g., journalists and executives) through appropriate privacy, account-security, and personal-data protections. ### Security awareness and AI security - **Own security awareness programs**, including human risk, phishing simulations, reporting workflows, completion tracking, and targeted training for higher-risk users. - **Design and deliver customized training** for different parts of the company (newsroom, journalists, business teams, technical teams) based on workflows and threat models. - **Develop practical AI security policies and guidance**, and review AI tools/automations/agents and internally built solutions for data handling, permissions, authentication, authorization, secrets management, logging, monitoring, human oversight, and operational readiness. ### Worthy of your time This is an opportunity to shape security inside an AI-enabled media company—**with meanin
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.