IT and Security Operations Specialist
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
Galileo is a team-based medical practice dedicated to improving healthcare quality and affordability across 50 states. Their mission is to transform society by solving complex healthcare problems while bridging the gap between patients and providers.
About the Role
The Galileo IT and Security team manages identity, endpoints, workforce tooling, security monitoring, and automation. This role focuses on maintaining and extending automated workflows—such as employee onboarding, device lifecycle management, security alert triage, and audit evidence collection—where manual intervention is still required. The position emphasizes exception handling, workflow improvement, and minimal ticket volume, with most days spent enhancing automation rather than repetitive tasks.
This is a full-time remote position, reporting to the Head of IT and Security. The ideal candidate has 4–5 years of experience in fast-moving IT, security operations, or systems administration, with a preference for those who thrive in environments where they can grow into a Security Engineer role.
Key Responsibilities
Identity and Endpoints
- Administer identities in Okta (users, groups, applications, device trust).
- Manage the MacBook fleet via MDM (enrollment, configuration, compliance, remote actions).
- Monitor and refine onboarding/offboarding workflows, handling exceptions.
Automation
- Maintain and extend automation for lifecycle, monitoring, and reporting workflows, including LLM-assisted triage steps using GenAI.
- Own built workflows: monitor, fix failures, and retire obsolete processes.
- Develop new automation for manual processes, collaborating with cross-functional teams.
Security Operations
- Respond to alerts from endpoint protection, cloud monitoring, and identity systems within defined SLAs.
- Investigate and document security events; escalate incidents per procedures.
- Support vulnerability management: review findings, track remediation with engineering, report status.
Application Security (Part-Time)
- Participate in security reviews of engineering changes, integrations, and vendor connections.
- Review authentication, authorization, and data handling patterns in internal applications.
- Collaborate with engineering to set secure defaults from the start.
Audit and Evidence
- Ensure automated evidence collection continues to work; address gaps flagged by reconcilers.
- Gather and prepare evidence samples for SOC 2 and HITRUST assessments when automation fails.
Workforce Support
- Handle support requests requiring system access or judgment beyond helpdesk bots.
- Write and update end-user documentation in clear, simple language.
How We Work
- Trust and clear communication are prioritized in standups (focus on key points, not details).
- Automation is preferred: if a task repeats, build a solution instead of manual execution.
- Clear records are maintained: decisions, changes, and status updates are tracked.
- Changes are tested before production deployment.
Growth Path
This role is designed for skill development. As you demonstrate capabilities, you’ll take on more responsibility across systems and workflows. The next step is becoming a Security Engineer with a focus area (e.g., identity, detection/response, or application security), chosen collaboratively with the Head of IT and Security.
Qualifications
- Clear written communication and concise problem-solving.
- Ownership of work: monitor systems, fix issues promptly.
- 4–5 years of experience in fast-moving IT, security operations, or systems administration.
- Working knowledge of identity systems (Okta) and macOS administration.
- Basic scripting experience and understanding of workflow automation, LLMs, and APIs.
- Familiarity with security fundamentals: authentication, least privilege, and logging.
- Judgment on when to decide independently vs. seek advice; transparency about blockers.
Nice to Have
- Experience with HIPAA, SOC 2, or HITRUST environments.
- AWS or GCP administration.
- Knowledge of EDR, SIEM, or cloud security monitoring tools.
- A security certification in progress or completed.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Galileo
Explore Top Companies in this Space
Nourish
HealthTech / Telehealth / Digital Health
HealthHero
Telehealth / Digital Health / HealthTech
Quiq
Business/Productivity Software / Customer Experience (CX) / Artificial Intelligence / Enterprise Software
Costello Medical
Healthcare / Medical Communications / Health Economics / Consulting
Galileo
View Company ProfileGalileo (operating at galileo.io) is an innovative digital health startup and modern medical practice designed to deliver equitable, high-quality, and affordable healthcare. Founded in 2018 by Dr. Thomas Lee—a physician entrepreneur who previously co-founded Epocrates and One Medical—and headquartered in New York, New York, Galileo replaces fragmented, expensive, and inconvenient traditional office visits with a seamlessly integrated virtual and multi-specialty care delivery model. Under the hood, the platform combines a 24/7 mobile app with mobile and in-person clinical teams, leveraging custom technology to streamline electronic medical records, automate lab orders and prescriptions, and coordinate complex care workflows across primary care, behavioral health, and chronic condition management. Backed by top-tier investors including Oak HC/FT, Pipe Capital, and Redpoint Ventures, Galileo partners with major national health plans and self-insured enterprise employers to manage total cost of care while reaching underserved and broad consumer populations across all 50 states.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.


