IT & Security Administrator Associate at Melora Connect | Torre

IT & Security Administrator Associate

Emma highlights
This highlight was written by Emma’s AI. Ask Emma to edit it.
Internship
Between: Oct 01, 2026 - Mar 31, 2027
(~20 hours per week)
Unpaid
location_on
Remote (anywhere)
Posted 5 days ago

Responsibilities


Job title: IT & Security Administrator Associate. Type: Internship, part-time, 10-20 hours per week, from October 1 2026 to March 31 2027. Location: Remote, worldwide. Language: English at a conversational level is sufficient. Compensation: Unpaid for the first 3-6 months while we bring the product to market, transitioning to a paid contract once the company is generating revenue, with a path to a full-time role as revenue supports it. Academic credit supported where a school allows it. About the company: Melora Connect is association management software built for small associations and chambers of commerce - organizations under 500 members who have been priced out of or buried by the enterprise platforms. The product is built. We are a small team putting it in front of its first customers, which means everyone here works on things that matter immediately rather than on practice projects. Why this role exists: We hold member data for associations and chambers - names, contact details, payment history, board rosters. Our buyers are organizations with no IT department of their own; they are trusting us to be theirs. Today security and internal IT get handled in the margins of other people's jobs, and too much of the operational knowledge sits with one person. That is the gap this role closes. What you will do: Own identity and access across our toolstack - Google Workspace, HubSpot, the product database and everything else: least privilege, MFA everywhere, offboarding that actually removes access. Keep a live inventory of accounts, systems and who has access to what, and why. Run security hygiene alongside the engineering and WordPress associates: dependency updates, secrets handling, and backup and restore testing, because a backup you have never restored is not a backup. Help harden the database that holds member PII - encryption in transit and at rest, role-based access, audit logging, retention rules. Write the security documentation buyers ask for: a security overview, data handling and privacy practices, an incident response plan, and a subprocessor list. Support day-to-day IT for the team: new associates set up with the right access on day one, password manager and device standards, phishing awareness. Help answer the security questionnaires associations and their boards increasingly send before they sign. Track what GDPR and CCPA actually require of a member database and flag what we need to change. Honest framing on stage: We are early. There is no SOC 2 program to inherit and no security team to sit inside. The first months are foundational - inventory, access cleanup, a written baseline - so you will be writing the first version of things rather than tuning the tenth, and you will have to prioritize, because we cannot do everything at once. Who we are looking for: You are comfortable administering cloud and SaaS accounts and you understand identity and access management. You know the fundamentals cold - MFA, least privilege, encryption, backups, patching, logging - and you can explain them to a non-technical association director without jargon. You are comfortable in a terminal and can find your way around a database; PostgreSQL or Supabase experience is a real plus. You write clearly, because much of this job is documentation people will actually read. You are careful with production systems and ask before you change something that can lock people out. No degree required - self-taught, career-changer, bootcamp and student applicants welcome, including people working toward Security+ or similar. Applicants worldwide welcome. What you get: real ownership of security and IT at a company where it decides whether deals close, portfolio artifacts you can point to - an access model, policies, an incident response plan - direct work with the founder rather than three layers down, structured training through our Melora Institute curriculum, and a substantive written reference. Skills required: identity and access management, Google Workspace administration, cloud and SaaS administration, security fundamentals, database basics, technical writing, conversational English. Nice to have: PostgreSQL, Supabase, HubSpot administration, GDPR and CCPA familiarity, incident response, scripting in Bash or Python, Security+ or equivalent coursework.
Closes in:
0
days
0
hours
0
min
0
sec
tune NOT FOR YOU? IMPROVE YOUR RESULTS