Corporate IT and Security Engineer

Zest HealthUnited StatesOn-siteFull-timeStaff, 8–12 yearsListed 15 hours ago

Apply now

About this role

About Us

Zest Health is redefining care for the 40M+ Americans with chronic dermatologic conditions like eczema and psoriasis. Through our virtual dermatology clinic, Zest is making care more accessible, effective, and affordable. Join our well-resourced, passionate team as we set the new gold standard for value-based specialty care.

The Role

We're hiring our first dedicated Corporate IT and Security Engineer . Today these responsibilities are spread across the software engineering team. You'll take them over and build the processes that let us grow without security and compliance becoming a bottleneck.

This is a hands-on role with broad ownership. In a typical week, you might add a new application to Okta and wire up its provisioning, run a quarterly access review, ship a new device policy in our MDM, close out a control in our compliance platform, draft answers to a client security questionnaire, or flag a new vulnerability to the engineering team and track it to remediation.

You don't need to have done all of this before. You need a solid foundation in identity, endpoints, and security fundamentals, the judgment to know what matters, and the drive to own a function at a fast-growing startup. As the company scales, this role grows with it.

We expect AI to be part of how you work, not a novelty. You'll have LLM tooling and MCP connections to Vanta and our other systems, and we want you to use them to automate the repetitive parts of IT, security, and compliance so your time goes to judgment calls. You'll also help decide how the rest of the company uses AI safely.

Engineering will continue to own secure product development. You'll be the SME in the threat landscape: you'll help set standards, track security developments that affect our stack, coordinate testing, and make sure findings get fixed.

Core Responsibilities

Identity and access

- Administer Okta: add and configure new applications, manage SSO and MFA, and maintain groups and access policies
- Own access provisioning and deprovisioning across every system we use, developing sustainable and clear SLAs to support the entire organization
- Own the employee onboarding and offboarding process, from the first-day laptop to the last-day access removal, and keep it fast, reliable, and auditable
- Run regular access reviews and make sure least-privilege holds up over time
- Automate repetitive identity work, such as access requests, provisioning steps, and access review prep, with Okta Workflows, scripting, and AI-assisted tooling

Endpoints and IT

- Manage our MDM: enrollment, device policies, encryption, patching, and endpoint compliance
- Maintain an accurate inventory of devices, applications, accounts, and licenses
- Serve as the first point of contact for employee IT and security questions

Security and compliance

- Own day-to-day operation of our compliance program: control monitoring, evidence collection, audit preparation, and coordination with auditors
- Own policy approvals and the annual policy review cycle
- Administer HIPAA and security awareness training and track completion
- Create and maintain the processes and policies we need to meet compliance requirements, including incident notification procedures
- Track security developments, vulnerabilities, and vendor advisories relevant to our stack and drive remediation

Client trust

- Own responses to client security assessments and questionnaires, and maintain a reusable library of security and compliance answers
- Support client audits and security reviews as our healthcare partnerships continually expand

Secure development partnership

- Partner with Engineering on application security standards, dependency and vulnerability scanning, and penetration test coordination
- Track application security findings through remediation and verify that critical issues are resolved
- Help engineers adopt new tools with appropriate access, privacy, and data controls

Qualifications

- 2+ years of experience in corporate IT, systems administration, IT security, security operations, or a related role
- Hands-on experience with an identity provider (Okta or similar), including SSO, MFA, and user lifecycle management
- Experience with an MDM platform (Kandji, Jamf, Intune, Mosyle, or similar), ideally in a primarily macOS environment
- Experience with employee onboarding and offboarding, access provisioning, and access reviews
- Familiarity with SOC 2 or a similar compliance framework, including how controls, policies, and evidence fit together
- Working knowledge of security fundamentals: least privilege, endpoint security, vulnerability management, and incident response basics
- Clear written communication. Much of this job is documenting processes, writing policies, and explaining security to non-technical teammates
- Fluency with LLM tools (Claude and Gemini) as a normal part of your work, and the judgment to verify their output before you act on it
- Good judgment when balancing security, usability, and speed
- Comfort operating within a broad function, learning quickly, and solving problems directly
- Commitment to work Eastern Timezone hours

Preferred Qualifications

- Experience supporting a SOC 2 audit from readiness through report
- Experience with HIPAA or another healthcare compliance requirement
- Experience with a compliance automation platform (Vanta, Drata, Secureframe, or similar)
- Experience responding to client security questionnaires or enterprise diligence requests
- Ability to automate IT and security workflows with scripting, APIs, or modern automation tools
- Comfort in a codebase: opening pull requests for security patches and dependency updates
- Familiarity with cloud identity and security in AWS, GCP, or Azure
- Experience as an early IT or security hire at a growing startup

Why Join the Zest Team?

- You'll be the owner of IT, identity, and compliance at a fast-growing company, not a ticket queue at a large one
- The scope of this role expands as the company does. Successful people in this seat grow into senior security, GRC, or IT leadership roles
- Do meaningful work alongside dynamic, mission-driven teammates
- Opportunity to join a high-growth start-up that is revolutionizing care delivery for dermatology patients
- Robust compensation package inclusive of competitive pay, equity grants, and retirement plan matching
- Employer-sponsored medical, dental, and vision plans

This role is not eligible for visa sponsorship, now or in the future. Candidates must be authorized to work in the U.S. without sponsorship.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other legally protected basis, in accordance with applicable law.