Pasito (YC S22) - Security & IT Manager
About Pasito
Pasito is the AI workspace for employee benefits.
We’re rethinking how group insurance and benefits are underwritten, delivered, used and measured - by the people who design them and the people who depend on them. Instead of static PDFs, disconnected systems, and manual workflows, Pasito brings plan design, payroll and benefits data, claims, and financial context into a single, AI-native workspace that helps benefits actually work for the 178 million Americans who depend on this system.
We don’t build for brokers, carriers and employers - we build with them. That collaboration shows up in everything we ship: AI agents that extract and structure plan data, tools that turn complexity into clarity for employees, and workflows that save carriers and consultants hundreds of hours per case.
Today, Pasito supports many of the largest insurance carriers and brokers in the U.S. We’re backed by Y Combinator, Insight Ventures and Core Innovation Capital, and we’re growing quickly. We ship fast, iterate relentlessly, and care deeply about building systems that are accurate, scalable, and human.
If you’re excited to work alongside exceptional operators and engineers, and apply AI in a legacy industry where precision and trust matter, Pasito is the place for you.
The Role
We’re looking for a Security & IT Manager to be the first dedicated owner of Pasito’s security, IT, and compliance program. Today this work is split across engineering, sales, and operations: Vanta, audits, pen tests, device setup, access requests, and security questionnaires all land on different people. You’ll own it end to end and become the connective tissue between engineering, HR, legal, sales, our auditors, and our customers.
Security and compliance have been part of how we build from the start, because our customers place their trust in us every day and we support employees in some of their most important financial decisions. We’re HIPAA-regulated and SOC 2 Type II certified, and our customers’ security teams review us closely before every deal.
This is a high-visibility, high-impact role at the center of how Pasito runs. You’ll touch everything from how a new hire gets their laptop on day one, to how we message employees by SMS and email in compliance with U.S. law, to how fast we close a critical vulnerability. This is a senior hire by design: you’ve already run a security and compliance program, and you can pick this one up and run it largely on your own from day one.
What You’ll Do
IT, Access & Device Management
Direct Pasito’s complete IT footprint, including domain management, Google Workspace, and our broader platform portfolio.
Oversee identity and permission governance: SSO, MFA, role-based controls, least-privilege architecture, and routine quarterly reviews.
Lead team onboarding and offboarding procedures, ensuring immediate provision of system access for new joiners and instant revocation upon departure.
Supervise organizational hardware via our MDM solution, handling enrollment, encryption protocols, patching cycles, endpoint protection, and inventory logging.
Act as the primary point of contact for internal IT issues and access requests.
Security & Compliance Program
Vanta: Maintain daily operations within Vanta by resolving failing tests, delegating fixes, keeping audit trails current, and eliminating operational backlogs.
SOC 2 Type II: Manage the annual audit execution, from gathering documentation to control mapping and liaison with external auditing teams.
HIPAA: Ensure continuous alignment with HIPAA regulations, managing executed BAAs and operational policy frameworks.
Penetration testing: Facilitate yearly security evaluations from partner selection through remediation, validation, and package preparation for clients.
Vendor & subprocessor risk: Conduct thorough security evaluations of third-party vendors including AI, payroll, and HRIS tools, managing associated DPAs, BAAs, and public records.
Program hygiene: Drive policy updates, risk reviews, security training, and the upkeep of our internal trust resource hubs.
AI security: Establish AI risk governance models and monitor third-party artificial intelligence platform integration.
Legal & Risk Partnership
Work closely with legal advisors to identify, analyze, and minimize potential security and compliance exposures across the organization.
Maintain an active risk log, offering transparent and consistent updates on organizational security posture to leadership.
Collaborate with leadership to ensure security and compliance as product expands and identify risks.
Engineering Remediation & Project Management
Partner with software engineering teams to resolve vulnerabilities, audit items, and testing findings with clear accountability and timelines.
Lead operational security projects across departments, managing roadmaps, dependencies, and deliverables.
Direct our sales security response process, completing SIG, CAIQ, and custom client questionnaires while connecting complex queries to technical leads to keep pipeline moving.
People & HR Partnership
Coordinate with HR on security-adjacent personnel operations, including background verifications, policy sign-offs, team security training, and lifecycle checklists.
Help foster a security-focused culture by offering clear, practical, and actionable advice to the team.
What We’re Looking For
5+ years in security, IT, or GRC, including personally owning at least one full SOC 2 Type II cycle end to end.
Hands-on experience running IT operations at a startup or growth-stage company: identity and access management, SSO, MDM, and SaaS administration.
Experience operating a compliance automation platform in production (Vanta, Drata, or Secureframe).
Enough technical depth to read a pen-test report, judge severity, and work credibly with engineers on remediation.
Strong project-management skills. You keep cross-functional work moving with clear owners and deadlines.
Excellent written and verbal English communication. You can explain risk clearly to engineers, lawyers, executives, and customers.
Highly organized and deadline-driven. Much of this job is time-sensitive and deal-blocking.
Based in Latin America, with strong overlap with U.S. business hours.
Nice to Have
CISA, CISSP, or ISO 27001 Lead Auditor certification.
Healthcare, HIPAA, or benefits/insurance industry experience.
Experience at an early- or growth-stage B2B SaaS company selling to enterprise or regulated buyers.
What’s In It For You
Strategic visibility: Report to the VP of Engineering and work closely with leadership, HR, legal, and sales on decisions that shape how Pasito scales.
Ownership: Build and own the security, IT, and compliance function from the ground up.
Growth: Join at a pivotal stage and grow as the company scales.
Competitive compensation: Salary benchmarked to your market, paid in USD.
Remote-first: Work from anywhere in Latin America with a highly collaborative team.
Learning and development: A budget to invest in yourself, whether that’s certifications, courses, books, or conferences.
Team offsites: We get together in person every year to work, connect, and have fun.
Equal Opportunity
Pasito is proud to be an equal opportunity employer. We believe great teams are built through diversity of background, perspective, and experience, and we’re committed to creating an inclusive environment where everyone can do their best work.
The interview process
Silver Screening Interview
Client Resume Review
Client Screening Interview
Client Technical Interview (You are going to make a presentation and defend it!)
Client Behavioral Interview