Position Overview
MFO Ventures is seeking a highly motivated, detail-oriented Information Security & IT Operations Specialist. Operating within a centralized shared services model across our portfolio entities, this role sits at the intersection of internal IT coordination, security operations, policy alignment, and cloud governance.
Working directly alongside the CISO, you will coordinate key technical activities with our Managed Service Provider (MSP), evaluate operational risks, assist with policy documentation to bridge governance with actual execution, and assist in operating the tools that enhance our security posture. We place top priority on critical thinking, high attention to detail, strong self-initiative, and professional discretion. Technical mentorship and framework training will be provided—we care most about finding a sharp, hard-working problem solver eager to build a career in technology and cybersecurity.
Key Responsibilities
-
Security Posture & Tool Optimization: Assist in operating and optimizing internal security platforms—including SecurityScorecard and posture management tools—to identify risks, track vulnerabilities, and support ongoing posture improvements.
-
MSP Coordination & Risk Evaluation: Act as a central point of contact working alongside our external MSP, coordinating routine technical workflows, evaluating operational risks, and verifying that IT activities align with enterprise security standards.
-
Phishing & Threat Triage: Serve as the primary point of contact for employee-reported phishing emails, conducting initial analysis, executing remediation steps, and escalating security events under the CISO’s guidance.
-
Tenant Security Hygiene: Perform routine configuration and access audits across Microsoft Entra ID (Azure AD), M365, and Google Workspace environments to evaluate risk, enforce least-privilege access, and maintain multi-factor authentication (MFA) standards.
-
Cloud Infrastructure & Baseline Monitoring: Review configurations and evaluate security posture across multi-cloud environments (Azure, GCP, and AWS) in alignment with CIS benchmarks.
-
Compliance Tracking & Audits: Assist with regular log reviews, system health checks, and maintaining evidence documentation required for HIPAA, HITRUST CSF, and SOC 2 audits.
-
Policy Alignment & Documentation: Assist in reviewing, modifying, drafting, and updating information security policies, standards, and standard operating procedures (SOPs) to ensure governing documentation accurately reflects and aligns with daily technical operations and external compliance standards.
- Perform other duties as assigned.
Qualifications & Attributes
-
Core Competencies: Exceptional critical thinking, rigorous attention to detail, strong technical writing capabilities, and a proactive, self-starter mindset. Must take pride in high-quality, error-free work.
-
Professional Standards: Strong verbal and written communication skills with the maturity to interact professionally with leadership, external vendors, and cross-entity personnel.
-
Technical & Documentation Aptitude: Foundational exposure to or familiarity with:
-
Microsoft Cloud Ecosystems (M365, Entra ID / Azure AD)
-
Core cybersecurity principles (Multi-Factor Authentication, Role-Based Access Control, encryption)
-
IT policy frameworks and bridging governance with practical operational workflows
-
Google Workspace administration basics and cloud concepts (Azure, AWS, or GCP)
-
-
Education & Training: Formal technical education is helpful—including a Bachelor’s degree, Associate’s degree (AA/AS), completion of a technical bootcamp, trade program, or equivalent practical training/experience in Support, Computing principals, IT, Cybersecurity, or a related discipline. Please list all related Certifications/Certificates (e.g. Security +, AWS fundamentals, AWS Security etc.)
What We Offer
-
Direct Executive Mentorship: Work directly alongside enterprise security leadership, gaining hands-on training in enterprise security operations, policy governance, and CISO-level strategy.
-
Framework Mastery: Build practical experience applying HIPAA, SOC 2, HITRUST CSF, and CIS Benchmarks in real-world technology settings.
-
Multi-Tenant Scope: Gain broad, practical experience supporting security posture and operational alignment across a dynamic, growing venture portfolio.
Job Benefits
-
Health insurance
-
Vision insurance
-
Dental insurance
- Bonus
-
Life insurance
-
Retirement plan
-
Paid time off
Location
-
Remote