Security & IT Engineer
We're looking for a hands-on Security & IT Engineer to own and strengthen Givzey's security posture while managing our internal IT infrastructure. This is a hybrid role combining security engineering, cloud infrastructure management, and IT operations. You'll be responsible for everything from ensuring SOC 2 / ISO compliance and securing AWS environments to managing employee devices and implementing company-wide security best practices.
This role is perfect for someone who can think strategically about risk and compliance while still getting into the weeds of configuration, automation, and incident response.
About Givzey:
Givzey is a Boston-based, rapidly growing digital fundraising solutions company, built by fundraisers for nonprofit organizations.
Join a fast-growing, mission-driven team working across two innovative platforms: Givzey, the first donor commitment management platform revolutionizing nonprofit fundraising, and Version2.ai, a cutting-edge AI platform helping individuals and organizations create their most authentic, effective digital presence. As an engineer at the intersection of philanthropy and artificial intelligence, you'll build scalable, high-impact solutions that empower nonprofit fundraisers and redefine how people tell their stories online. We're a collaborative, agile team that values curiosity, autonomy, and purpose. Whether you're refining AI-driven experiences or architecting tools for the future of giving, your work will help shape meaningful technology that makes a difference.
What You'll Do
Security & Compliance
- Own and evolve our information security program, including policies, controls, and procedures aligned with SOC 2, ISO 27001, and other frameworks.
- Conduct regular security risk assessments and audits; maintain continuous compliance readiness.
- Manage vulnerability scanning, penetration testing, and incident response processes.
- Oversee access control, identity management, and data protection across all systems.
- Partner with legal and operations teams to ensure vendor and data processing compliance.
Cloud Infrastructure Security
- Secure and manage AWS infrastructure (IAM, networking, encryption, logging, monitoring, etc.).
- Implement security automation for configuration management, secrets management, and incident alerts.
- Collaborate with engineering teams to embed security into CI/CD pipelines and software lifecycle.
IT Administration
- Manage company devices (Macs) using MDM and endpoint protection tools.
- Set up and maintain SSO, MFA, and access control across tools and services.
- Handle onboarding/offboarding from a security and IT perspective.
- Support internal IT operations and ensure systems run securely and smoothly.
Governance & Culture
- Build a strong security culture through training, awareness, and best practices.
- Stay current on emerging security threats and compliance standards.
What You'll Bring
- 5+ years of experience in IT, DevOps, or security engineering roles.
- Hands-on experience with AWS, IAM, and cloud security tools.
- Strong familiarity with SOC 2, ISO 27001, and related compliance frameworks(TX-RAMP).
- Understanding of network security, identity & access management, and incident response.
- Comfortable being both strategic and tactical — from writing policies to hardening infrastructure.
- Bonus: experience with Pulumi