Head of IT & Security

OpenEd
$195,000 - $220,000

About The Position

As the founding Security Engineer at OpenEd, you'll join a small, high-impact team changing the nature of education. This is a truly unique opportunity to be the founding member of our security team, and to ensure we earn the trust of families that their student's education — and data — is safe with us. You'll own the IT, identity, and compliance programs directly, with a broad range of responsibilities and the autonomy to tackle them as you see fit. We serve over 100,000 students, which means the security bar isn't theoretical: it's the reason families keep trusting us with their kids. You'll own four programs end to end: Identity & access: SSO/SAML, MFA, provisioning, a least-privilege access model, and reliable onboarding/offboarding. Corporate/IT security: Endpoint/MDM, SaaS and vendor risk, the phishing and awareness program, and incident response playbooks. Compliance: Drive SOC 2 (Type II), map FERPA/COPPA/state privacy controls, and own audits and their outcomes. Application security: Contribute to key AppSec initiatives (SAST/DAST/SCA in CI), triage and drive remediation with engineers, and run external pen test audits.

Requirements

  • 6+ years in security, ideally in a regulated vertical (finance, education, healthcare).
  • Hands-on across IT/identity and security operations.
  • Experience taking an organization through SOC 2 (or ISO 27001).
  • Experience establishing and driving human-centered processes for ensuring security across an organization.
  • Strong judgment on risk.
  • Deeply technical with excellent communication skills.
  • Hands-on experience designing or running a zero-trust environment (e.g., identity-based access, continuous verification, no implicit network trust).

Nice To Haves

  • Edtech/FERPA/privacy background
  • CISSP
  • OSCP

Responsibilities

  • Own the IT, identity, and compliance programs.
  • Manage Identity & access programs including SSO/SAML, MFA, provisioning, least-privilege access model, and onboarding/offboarding.
  • Oversee Corporate/IT security including Endpoint/MDM, SaaS and vendor risk, phishing and awareness program, and incident response playbooks.
  • Drive SOC 2 (Type II) compliance, map FERPA/COPPA/state privacy controls, and manage audits.
  • Contribute to Application Security initiatives (SAST/DAST/SCA in CI), triage and remediate vulnerabilities with engineers, and manage external pen test audits.
  • Automate security controls.
  • Design systems that are robust to human failure.
  • Set security strategy, choose tooling, and decide sequencing.
  • Partner closely with engineering, IT, and legal.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service