Zest Health logo
Zest Health
Posted 16 days agoVerified live 1d ago

Corporate IT and Security Engineer

Brief overview

Remote
UndergradOr in progress
2+ yrsMinimum
OktaSingle Sign-On (SSO)Multi-Factor Authentication (MFA)User Lifecycle ManagementMobile Device Management (MDM)Access Provisioning and Access ReviewsSOC 2 ComplianceHIPAA ComplianceVulnerability ManagementIncident ResponseLLM Tools ClaudeLLM Tools GeminiSecurity Automation

About the company

Zest Health logo
Zest Healthzesthealth.com

Value based care platform focused on treating patients with inflammatory skin diseases

Job description

Summary

Zest Health is a virtual dermatology company focused on making care more accessible, effective, and affordable for people with chronic dermatologic conditions. The Corporate IT and Security Engineer will own corporate IT, identity, security, and compliance operations, including access management, endpoint administration, audits, security assessments, and vulnerability remediation. The role will also partner with Engineering on application security and automate repetitive IT, security, and compliance workflows using AI and other tools.

Responsibilities

  • Administer Okta: add and configure new applications, manage SSO and MFA, and maintain groups and access policies
  • Own access provisioning and deprovisioning across every system we use, developing sustainable and clear SLAs to support the entire organization
  • Own the employee onboarding and offboarding process, from the first-day laptop to the last-day access removal, and keep it fast, reliable, and auditable
  • Run regular access reviews and make sure least-privilege holds up over time
  • Automate repetitive identity work, such as access requests, provisioning steps, and access review prep, with Okta Workflows, scripting, and AI-assisted tooling
  • Manage our MDM: enrollment, device policies, encryption, patching, and endpoint compliance
  • Maintain an accurate inventory of devices, applications, accounts, and licenses
  • Serve as the first point of contact for employee IT and security questions
  • Own day-to-day operation of our compliance program: control monitoring, evidence collection, audit preparation, and coordination with auditors
  • Own policy approvals and the annual policy review cycle
  • Administer HIPAA and security awareness training and track completion
  • Create and maintain the processes and policies we need to meet compliance requirements, including incident notification procedures
  • Track security developments, vulnerabilities, and vendor advisories relevant to our stack and drive remediation
  • Own responses to client security assessments and questionnaires, and maintain a reusable library of security and compliance answers
  • Support client audits and security reviews as our healthcare partnerships continually expand
  • Partner with Engineering on application security standards, dependency and vulnerability scanning, and penetration test coordination
  • Track application security findings through remediation and verify that critical issues are resolved
  • Help engineers adopt new tools with appropriate access, privacy, and data controls

Skills

  • 2+ years of experience in corporate IT, systems administration, IT security, security operations, or a related role
  • Hands-on experience with an identity provider (Okta or similar), including SSO, MFA, and user lifecycle management
  • Experience with an MDM platform (Kandji, Jamf, Intune, Mosyle, or similar), ideally in a primarily macOS environment
  • Experience with employee onboarding and offboarding, access provisioning, and access reviews
  • Familiarity with SOC 2 or a similar compliance framework, including how controls, policies, and evidence fit together
  • Working knowledge of security fundamentals: least privilege, endpoint security, vulnerability management, and incident response basics
  • Clear written communication. Much of this job is documenting processes, writing policies, and explaining security to non-technical teammates
  • Fluency with LLM tools (Claude and Gemini) as a normal part of your work, and the judgment to verify their output before you act on it
  • Good judgment when balancing security, usability, and speed
  • Comfort operating within a broad function, learning quickly, and solving problems directly
  • Commitment to work Eastern Timezone hours
  • This role is not eligible for visa sponsorship, now or in the future. Candidates must be authorized to work in the U.S. without sponsorship
  • Experience supporting a SOC 2 audit from readiness through report
  • Experience with HIPAA or another healthcare compliance requirement
  • Experience with a compliance automation platform (Vanta, Drata, Secureframe, or similar)
  • Experience responding to client security questionnaires or enterprise diligence requests
  • Ability to automate IT and security workflows with scripting, APIs, or modern automation tools
  • Comfort in a codebase: opening pull requests for security patches and dependency updates
  • Familiarity with cloud identity and security in AWS, GCP, or Azure
  • Experience as an early IT or security hire at a growing startup

Qualifications

Must Haves

  • 2+ years of experience in corporate IT, systems administration, IT security, security operations, or a related role
  • Hands-on experience with an identity provider (Okta or similar), including SSO, MFA, and user lifecycle management
  • Experience with an MDM platform (Kandji, Jamf, Intune, Mosyle, or similar), ideally in a primarily macOS environment
  • Experience with employee onboarding and offboarding, access provisioning, and access reviews
  • Familiarity with SOC 2 or a similar compliance framework, including how controls, policies, and evidence fit together
  • Working knowledge of security fundamentals: least privilege, endpoint security, vulnerability management, and incident response basics
  • Clear written communication. Much of this job is documenting processes, writing policies, and explaining security to non-technical teammates
  • Fluency with LLM tools (Claude and Gemini) as a normal part of your work, and the judgment to verify their output before you act on it
  • Good judgment when balancing security, usability, and speed
  • Comfort operating within a broad function, learning quickly, and solving problems directly
  • Commitment to work Eastern Timezone hours
  • This role is not eligible for visa sponsorship, now or in the future. Candidates must be authorized to work in the U.S. without sponsorship

Nice to Haves

  • Experience supporting a SOC 2 audit from readiness through report
  • Experience with HIPAA or another healthcare compliance requirement
  • Experience with a compliance automation platform (Vanta, Drata, Secureframe, or similar)
  • Experience responding to client security questionnaires or enterprise diligence requests
  • Ability to automate IT and security workflows with scripting, APIs, or modern automation tools
  • Comfort in a codebase: opening pull requests for security patches and dependency updates
  • Familiarity with cloud identity and security in AWS, GCP, or Azure
  • Experience as an early IT or security hire at a growing startup

Benefits

  • Competitive pay
  • Equity grants
  • Retirement plan matching
  • Employer-sponsored medical, dental, and vision plans
  • The scope of this role expands as the company does. Successful people in this seat grow into senior security, GRC, or IT leadership roles
  • Do meaningful work alongside dynamic, mission-driven teammates
  • Opportunity to join a high-growth start-up that is revolutionizing care delivery for dermatology patients

More jobs like this