About The Role :
Join a growing team of IT professionals who have a passion for the potential of technology tools to transform the work of a nonprofit. As the IT Security Engineer, you will play an important role in building VentureWell's cybersecurity and Governance, Risk & Compliance (GRC) program, including managing day-to-day security operations, investigating events, identifying areas of risk, and building out security focused documentation. We are looking for someone who has a passion for technology, teamwork, and continuous improvement.
Responsibilities :
Security Operations & Threat Management (40% of time)
- Monitor and respond to security alerts, vulnerability reports, and threat intelligence
- Perform root cause analysis on security incidents and recommend corrective actions
- Manage endpoint protection, cloud configuration monitoring, and IAM role reviews
- Maintain continuous monitoring dashboards (e.g., Datadog, Jamf, Google Admin, Amazon Web Services (AWS) CloudWatch)
- Lead the design and execution of vulnerability assessments, penetration tests, and security audits.
Governance, Risk & Compliance (35% of time)
Support NIST SP 800-171 and Cybersecurity Maturity Model Certification (CMMC) control implementation and validationMaintain the System Security Plan (SSP) and Plan of Action & Milestones (POA&M )Draft, review, and maintain security policies, standards, and proceduresConduct Security Impact Analyses (SIA) for configuration or architectural changesCoordinate evidence collection for internal and external auditsEnsure secure configuration baselines are documented and reviewed regularlySecurity Engineering and Cloud infrastructure (25% of time)
Implement and maintain secure configurations in AWS, Salesforce, Box, and Google WorkspaceManage access controls, Multi-Factor Authentication (MFA) enforcement, and session management policiesAutomate security tasks via scripts or cloud-native toolsParticipate in architecture reviews to ensure security-by-design principlesRecommend new tools or integrations to enhance visibility and compliance automationWhat You Bring :
Bachelor's degree in Information Security, Computer Science, or equivalent experienceMinimum of 4 years of direct experience supporting and adhering to cybersecurity compliance (GR&C)One or more of the following industry certifications preferred :CompTIA Security+GIAC Information Security FundamentalsAWS Certified Security - SpecialtyISC2 CC or CISSP (Associate level acceptable)Extensive experience with security monitoring and assessment toolsExperience with cloud security best practicesFamiliarity with NIST special publications and frameworks (800-171, CSF)Fundamental knowledge of key security concepts including defense in depth, least privilege, and zero trustExperience with NIST 800-171 / CMMC Level 2 / CSF implementation and audit prepExcellent analytical, documentation, and cross-functional communication skillsFamiliarity with Software-as-a-Service (SaaS) applications including Google Workspace, Salesforce, OktaWorking technical knowledge of Open Worldwide Application Security Project (OWASP) Top 10 security risks and mitigation strategiesExperience with vulnerability management, log aggregation, and SIEM solutionsProven ability to operate as a self-starter, working autonomously and driving initiatives forward with minimal oversightAcross the Board, VentureWell Staff :
Are able to succeed and thrive in an environment with competing and changing priorities and tight deadlinesHave track records of and ability to build solid collaborative working relationships, and are proven team players who enjoy a "customer service" orientation to collaborationAre committed to embedding equity for all in our internal practices and culture and in our programs in order to live and achieve our missionBring openness and engagement to personal, professional, and organization-wide learningAre curious and committed to issues of environmental sustainabilityAre self-starters with excellent attention to detail and a commitment to delivering high-quality workAre active learners who independently learn new tools and work processes quicklyHave excellent written and oral communication skillsOur Benefits
An attractive and equitable compensation package, including :a salary range of $95,000-$115,000 commensurate with experience and internal equity403 (b) with 200% match up to a maximum contribution from VentureWell of 10% when the employee puts in 5% (eligible after one year of service for the match)Medical, Dental, and Vision insurance$1,000 home office stipend upon hireA true focus on work-life balance with work weeks that reflect thatIt's our aim for our employees in this position to not work more than a 40-hour workweek20 paid vacation days12 paid holidays12 paid wellness daysBenefits are reviewed each fiscal year and may be subject to change.What We Offer :
A culture where people work intentionally and collaboratively in pursuit of our missionValues we believe inAbout VentureWell :
VentureWell supports the cultivation of science and technology inventors and the innovation and entrepreneurship ecosystems critical to their success. Since its founding in 1995, VentureWell has funded or trained over 19,000 early-stage science and technology inventors and innovators, resulting in the emergence of more than 6,100+ ventures with groundbreaking technological advancements in fields like biomedicine and healthcare, sustainable energy and materials, and solutions for low-resource settings. The ventures it has supported have raised subsequent funds totaling more than $7.8 billion and are reaching millions of people globally.
Visit venturewell.org to learn more.