Matcha
Galileo logo

IT and Security Generalist

Galileo

Apply

Team-based, data-driven longitudinal care improving affordability and quality nationwide.

$114,893 raised raised· Backed by 8VC, What If Ventures, Redpoint, Equable Capital, Foresite Capital, 10X Capital, Ceteri Capital, Oak HC/FT
$110k - $120kFULL TIMERemote · United States497 employeesPosted Sep 23
identity administrationendpoint administrationoktamacos administrationmdmautomationsecurity operationsvulnerability managementapplication securityscriptingworkflow automationllmsapissecurity fundamentalsincident handlingaudit evidence collection

Remote startup roles in your inbox

Matcha reads all job descriptions to surface the handful that actually matter in a zero noise email. Simple by design.

Describe your next role, cut the noise

About Us

Galileo is a team-based medical practice working to improve the quality and affordability of health care for all. Operating across 50 states, Galileo offers high-touch, data-driven, multi-specialty, longitudinal care to diverse and complex patients—on the phone, in the home, and everywhere in between. Regional and national health plans, employers, and Fortune 500 organizations trust Galileo as the leading solution to improve population health. Founded by Dr. Tom X. Lee, the healthcare pioneer behind One Medical and Epocrates, Galileo is a team of leading innovators from healthcare, technology, and human-centered design. Our mission is to apply that talent and scientific thinking to transform society by solving our largest, toughest healthcare problems, while at the same time bringing patient and provider closer.

About the Role

The Galileo IT and Security team runs identity, endpoints, workforce tooling, security monitoring, and the automation that ties those systems together. That automation is already built and in production: employee onboarding and offboarding, device lifecycle, security alert triage, audit evidence collection, and workforce support all run as workflows with AI-assisted steps, with a person stepping in only for exceptions and decisions. The breadth of this role is possible because the systems handle the volume.

In this role, you will operate that estate, keep it healthy, and extend it where manual work still exists. The scope spans identity and endpoint administration, corporate security monitoring, and minimal workforce support, but the day-to-day is exception handling, review, and building, not ticket volume. Most days you will spend more time improving a workflow than repeating a task.

We are hiring for trajectory. The right candidate is experienced in their career, has more range than depth, and wants to grow into a security engineer by doing the work.

This is a full-time remote position, reporting to our Head of IT and Security.

What you will do:

Identity and endpoints

  • Administer identities in Okta (users, groups, applications, device trust).
  • Manage the MacBook fleet through the MDM platform: enrollment, configuration, compliance, remote actions.
  • Monitor and refine onboarding and offboarding through the existing automated lifecycle workflows and handle the exceptions they surface.

Automation

  • Maintain and extend the automation estate that runs lifecycle, monitoring, and reporting workflows, including the LLM-assisted triage steps built using GenAI.
  • Own the workflows you build: monitor them, fix failures, retire what no longer serves a purpose.
  • Build new automation for manual processes across the company, working with the teams that own those processes.

Security operations

  • Respond to alerts from endpoint protection, cloud monitoring, and identity systems within defined SLAs.
  • Investigate and document security events; escalate incidents per the incident handling procedure.
  • Support vulnerability management: review findings, track remediation with engineering, report status.

Application security (part-time)

  • Participate in security review of engineering changes, integrations, and vendor connections.
  • Review authentication, authorization, and data handling patterns in internal applications and workflows.
  • Work with engineering to set secure defaults from the start, instead of reviewing security after changes are made.

Audit and evidence

  • Make sure automated evidence collection continues to work and look into any gaps flagged by the reconciler.
  • Gather and prepare evidence samples for SOC 2 and HITRUST assessments when automation does not handle a request.

Workforce support

  • Handle support requests that need system access or judgment beyond what the helpdesk bot and knowledge base can provide.
  • Write and update end-user documentation using clear, simple language.

How we work

  • We are a small team that values trust and clear communication. In our standups, we focus on the key points rather than getting into too much detail.
  • We prefer automation. If a task is likely to occur again, we create a solution rather than doing it by hand each time. Alert triage, lifecycle actions, and evidence collection already work this way, so our on-call and ticket load stay light.
  • We keep clear records. We track decisions, changes, and status updates in our project management tools.
  • We test changes before they go live. Work is only done when it works in production.

Growth path

This role is meant to help you develop your skills. As you show what you can do, you will take on more responsibility for different systems and workflows. The next step is to become a Security Engineer with a focus area, like identity, detection and response, or application security. You and the Head of IT and Security will choose this specialty together, based on your strengths and Galileo's needs.

About You

  • You communicate clearly in writing and can explain a problem, a decision, and its status in just a few sentences.
  • You take responsibility for your work, making sure what you build keeps working. You monitor systems and fix issues as soon as they come up.
  • You have 4-5 years of experience in fast-moving IT, security operations, or systems administration environments, or equivalent proven experience.
  • Working knowledge of identity systems (Okta or equivalent) and macOS administration.
  • Some scripting experience and an understanding of the fundamentals. Experience with workflow automation tools, LLMs, and APIs, or a strong interest in learning them.
  • Familiarity with security fundamentals: authentication, least privilege, and logging.
  • You understand when to decide on your own and when to ask for advice. You discuss decisions before acting on them and let the team know about any blockers right away.

Nice to have:

  • Exposure to HIPAA, SOC 2, or HITRUST environments.
  • AWS or GCP administration.
  • Experience with EDR, SIEM, or cloud security monitoring tools.
  • A security certification in progress or completed.

Compensation: $110,000-120,000 annually based upon prior experience, performance, and market dynamics. This role is eligible for a 10% bonus.

Benefits Offered:

  • Medical / Dental / Vision insurance
  • Flexible Spending Account
  • Health Savings Account + match
  • Company paid STD/LTD, AD&D, and Life insurance
  • Paid Family Leave
  • 401K + match
  • Paid Time Off

How We Hire

Galileo Health is an equal-opportunity employer and welcomes applicants from all backgrounds.

We have recently become aware of the fraudulent use of our name on job postings and via recruiting emails that are illegitimate and not in any way associated with us. We will never ask you to provide sensitive personal information as part of the recruiting process, such as your social security number; send you any unsolicited job offers or employment contracts; require any fees, payments or access to any financial accounts; and/or conduct text-only interviews. If you suspect you are being scammed or have been scammed online, you may report the crime to the Federal Bureau of Investigation and obtain more information regarding online scams at the Federal Trade Commission.

Similar remote jobs