IT Security Specialist
AxiosThe big picture: Axios is a media company dedicated to delivering trustworthy news and information with efficiency, clarity, and Smart Brevity. We are hiring an IT Security Specialist on our IT team to help protect the systems, devices, identities, applications, and workflows that power the company.
Why it matters: Security at Axios is not simply a matter of deploying tools or responding to vulnerabilities. It means understanding how systems are used, assessing whether they are fit for purpose, and identifying risk created by workflows, permissions, configurations, vendors, and user behavior.
This role will help de-risk current and future solutions by embedding security into technology decisions from evaluation and procurement through implementation, monitoring, and continuous improvement.
Go deeper: This role will own key areas of our corporate security environment, including endpoint security, identity and access management, Google Workspace, SaaS security, security monitoring, security awareness, and AI security. We’re looking for an experienced practitioner who understands that, in a modern company, the browser is often the operating system through which people access data, applications, and business workflows. In this role, you will:
- Own security for Axios’ Mac fleet, including Jamf, compliance, monitoring, alert investigation, malware response, and device remediation.
- Own Okta-based identity and access management, including adaptive MFA, authentication, SSO, application assignments, access scopes, and joiner/mover/leaver processes.
- Partner with People, Legal and Infrastructure to improve provisioning, offboarding, access removal, archival, legal holds, and lifecycle automation.
- Establish and maintain security configurations and risk controls for core services and SaaS applications, including authentication, access, collaboration, email security, data protection, alerting, activity monitoring, vendor and procurement reviews, security questionnaires, evidence gathering, and recommended safeguards.
- Treat the browser and SaaS layer as critical security boundaries, evaluating how users access data and applications and where browser-based workflows create risk.
- Use logs and activity monitoring across endpoints, browsers, identity systems, Google Workspace, and SaaS applications to investigate suspicious activity and support incident response.
- Assess systems, tools, permissions, and workflows for security, operational fit, and long-term supportability.
- Help protect high-risk users, including journalists and executives, through appropriate privacy, account-security, and personal-data protections.
Security awareness and AI security
- Own security awareness programs, including human risk, phishing simulations, reporting workflows, completion tracking, and targeted training for higher-risk users.
- Design and deliver customized training for different parts of the company, including the newsroom, journalists, business teams, and technical teams, based on their workflows and threat models.
- Develop practical AI security policies and guidance, and review AI tools, automations, agents, and internally built solutions for data handling, permissions, authentication, authorization, secrets management, logging, monitoring, human oversight, and operational readiness.
Worthy of your time: This is an opportunity to shape security inside an AI-enabled media company. You’ll have meaningful ownership and the chance to improve security across our technology environment and the workflows built on top of it.
We’re looking for someone who:
- Has substantial experience in IT security, endpoint security, identity and access management, systems administration, or a related field.
- Has hands-on experience with macOS, Jamf or comparable endpoint platforms, CrowdStrike Falcon, Okta or a similar identity provider, and Google Workspace security.
- Understands modern security boundaries across browsers, SaaS applications, identity providers, endpoints, APIs, data flows, and AI-enabled systems.
- Has experience with security logging, monitoring, incident investigation, vendor assessments, and SaaS risk management.
- Has operated or improved security awareness, phishing, or role-specific training programs.
- Can evaluate risk in the context of real-world workflows, users, business requirements, and operational constraints.
Starting salary for this role is in the range of $85,000 - $105,000 and is dependent on numerous factors, including but not limited to location, work experience, and skills. This range does not include other compensation benefits. Axios' compensation philosophy takes into account the cost of labor differentials across the country. Because this is a remote-optional job posting, this salary range takes into account all possible locations within the United States, but candidates will only be eligible for the salary range for their location.
Axios is committed to embracing artificial intelligence as a core part of how we work. All team members are expected to actively develop AI literacy and use AI tools to enhance their productivity, creativity, and efficiency. We invest in ongoing learning to ensure every employee is equipped to responsibly and effectively integrate AI into their daily workflows.
What Axios brings to the table besides salary:
- 401(k) with employer match
- Robust PPO and High Deductible health insurance options on the Blue Cross Blue Shield network
- Employer Health Savings Account (HSA) contribution for the high deductible health plan option
- Dental and vision coverage
- Primary caregiver 12-week paid leave
- Birth-givers will have an additional 6-8 weeks depending on type of delivery, for a total of 18-20 weeks continuous leave
- Generous vacation policy, plus holidays
- One mental health day per quarter
- Annual learning and development stipend
- $100 monthly work-from-home stipend
- Tele-mental health services through Headspace
- OneMedical membership, including tele-health services
- Personal health advocacy resources through HealthAdvocate
- Inclusive fertility, hormonal health and family forming benefits through Carrot Fertility
- Access to the Axios “Family Fund”, which was created to allow employees to request financial support when facing financial hardship or emergencies
- Increased work flexibility for parents and caretakers
- Virtual company-sponsored social events
- A strong and positive work environment
- A commitment to an open, inclusive, and diverse work culture
Equal Opportunity Employer Statement
Axios is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, age, gender identity, gender expression, veteran status, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws.
This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, compensation, benefits, training, and apprenticeship. Axios makes hiring decisions based solely on qualifications, merit, and business needs at the time.