IT Security Specialist
Axios · Remote
About The Role
<p><span style="font-family: helvetica, arial, sans-serif;"><strong>The big picture: </strong>Axios is a media company dedicated to delivering trustworthy news and information with efficiency, clarity, and Smart Brevity. We are hiring an IT Security Specialist on our IT team to help protect the systems, devices, identities, applications, and workflows that power the company.</span></p>
<p><span style="font-family: helvetica, arial, sans-serif;"><strong>Why it matters: </strong>Security at Axios is not simply a matter of deploying tools or responding to vulnerabilities. It means understanding how systems are used, assessing whether they are fit for purpose, and identifying risk created by workflows, permissions, configurations, vendors, and user behavior.</span></p>
<p><span style="font-family: helvetica, arial, sans-serif;">This role will help de-risk current and future solutions by embedding security into technology decisions from evaluation and procurement through implementation, monitoring, and continuous improvement.</span></p>
<p><span style="font-family: helvetica, arial, sans-serif;"><strong>Go deeper: </strong>This role will own key areas of our corporate security environment, including endpoint security, identity and access management, Google Workspace, SaaS security, security monitoring, security awareness, and AI security. We’re looking for an experienced practitioner who understands that, in a modern company, the browser is often the operating system through which people access data, applications, and business workflows.<strong> </strong>In this role, you will:</span></p>
<ul>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Own security for Axios’ Mac fleet, including Jamf, compliance, monitoring, alert investigation, malware response, and device remediation.</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Own Okta-based identity and access management, including adaptive MFA, authentication, SSO, application assignments, access scopes, and joiner/mover/leaver processes.</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Partner with People, Legal and Infrastructure to improve provisioning, offboarding, access removal, archival, legal holds, and lifecycle automation.</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Establish and maintain security configurations and risk controls for core services and SaaS applications, including authentication, access, collaboration, email security, data protection, alerting, activity monitoring, vendor and procurement reviews, security questionnaires, evidence gathering, and recommended safeguards.</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Treat the browser and SaaS layer as critical security boundaries, evaluating how users access data and applications and where browser-based workflows create risk.</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Use logs and activity monitoring across endpoints, browsers, identity systems, Google Workspace, and SaaS applications to investigate suspicious activity and support incident response.</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Assess systems, tools, permissions, and workflows for security, operational fit, and long-term supportability.</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Help protect high-risk users, including journalists and executives, through appropriate privacy, account-security, and personal-data protections.</span></li>
</ul>
<p><span style="font-family: helvetica, arial, sans-serif;"><strong>Security awareness and AI security</strong></span></p>
<ul>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Own security awareness programs, including human risk, phishing simulations, reporting workflows, completion tracking, and targeted training for higher-risk users.</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Design and deliver customized training for different parts of the company, including the newsroom, journalists, business teams, and technical teams, based on their workflows and threat models.</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Develop practical AI security policies and guidance, and review AI tools, automations, agents, and internally built solutions for data handling, permissions, authentication, authorization, secrets management, logging, monitoring, human oversight, and operational readiness.</span></li>
</ul>
<p><span style="font-family: helvetica, arial, sans-serif;"><strong>Worthy of your time: </strong>This is an opportunity to shape security inside an AI-enabled media company. You’ll have meaningful ownership and the chance to improve security across our technology environment and the workflows built on top of it.</span></p>
<p><span style="font-family: helvetica, arial, sans-serif;">We’re looking for someone who:</span></p>
<ul>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Has substantial experience in IT security, endpoint security, identity and access management, systems administration, or a related field.</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Has hands-on experience with macOS, Jamf or comparable endpoint platforms, CrowdStrike Falcon, Okta or a similar identity provider, and Google Workspace security.</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Understands modern security boundaries across browsers, SaaS applications, identity providers, endpoints, APIs, data flows, and AI-enabled systems.</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Has experience with security logging, monitoring, incident investigation, vendor assessments, and SaaS risk management.</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Has operated or improved security awareness, phishing, or role-specific training programs.</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Can evaluate risk in the context of real-world workflows, users, business requirements, and operational constraints.</span></li>
</ul>
<p><span style="font-family: helvetica, arial, sans-serif;"><em>Starting salary for this role is in the range of $85,000 - $105,000 and is dependent on numerous factors, including but not limited to location, work experience, and skills. This range does not include other compensation benefits. Axios' compensation philosophy takes into account the cost of labor differentials across the country. Because this is a remote-optional job posting, this salary range takes into account all possible locations within the United States, but candidates will only be eligible for the salary range for their location.</em></span></p>
<p><span style="font-family: helvetica, arial, sans-serif;">Axios is committed to embracing artificial intelligence as a core part of how we work. All team members are expected to actively develop AI literacy and use AI tools to enhance their productivity, creativity, and efficiency. We invest in ongoing learning to ensure every employee is equipped to responsibly and effectively integrate AI into their daily workflows.</span><br><br></p>
<p><span style="font-family: helvetica, arial, sans-serif;"><strong>What Axios brings to the table besides salary:</strong></span></p>
<ul>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">401(k) with employer match</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Robust PPO and High Deductible health insurance options on the Blue Cross Blue Shield network</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Employer Health Savings Account (HSA) contribution for the high deductible health plan option</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Dental and vision coverage</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Primary caregiver 12-week paid leave</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Birth-givers will have an additional 6-8 weeks depending on type of delivery, for a total of 18-20 weeks continuous leave</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Generous vacation policy, plus holidays</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">One mental health day per quarter</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Annual learning and development stipend</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">$100 monthly work-from-home stipend</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Tele-mental health services through Headspace</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">OneMedical membership, including tele-health services</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Personal health advocacy resources through HealthAdvocate</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Inclusive fertility, hormonal health and family forming benefits through Carrot Fertility</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Access to the Axios “Family Fund”, which was created to allow employees to request financial support when facing financial hardship or emergencies</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Increased work flexibility for parents and caretakers</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">Virtual company-sponsored social events</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">A strong and positive work environment</span></li>
<li style="font-family: helvetica, arial, sans-serif;"><span style="font-family: helvetica, arial, sans-serif;">A commitment to an open, inclusive, and diverse work culture</span></li>
</ul>
<p><span style="font-family: helvetica, arial, sans-serif;"><strong>Equal Opportunity Employer Statement </strong></span></p>
<p><span style="font-family: helvetica, arial, sans-serif;">Axios is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, age, gender identity, gender expression, veteran status, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws. </span></p>
<p><span style="font-family: helvetica, arial, sans-serif;">This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, compensation, benefits, training, and apprenticeship. Axios makes hiring decisions based solely on qualifications, merit, and business needs at the time.</span></p>
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing