Remote job
Director of Information Security
Job details
About this role
Role overview This is the first dedicated security leadership role at a deep-tech company building energy-efficient processor architecture. The position is a hands-on founding charter: protect source code, compiler toolchains, and hardware designs, stand up a federal compliance program, and run IT end-to-end while a dedicated IT Manager is hired. The work sits at the intersection of engineering, federal/defense customer requirements, and export-controlled technology, reporting to senior legal leadership and holding a standing seat in engineering architecture review.
Responsibilities - Design protections for source code, compiler toolchains, and hardware designs, including classification, encryption, storage, and access boundaries. - Own the access model across engineering systems, covering repository permissions, credential governance, and recurring access reviews. - Mature NIST SP 800-171 and CMMC programs: assessments, system security plans, POA&Ms, SPRS, remediation, and audit readiness. - Secure the software supply chain end-to-end, including dependencies, build pipelines, release integrity, and the compiler itself. - Own network and infrastructure security architecture, detection, logging, incident response, and the associated playbooks. - Implement export control obligations technically, including access segregation, U.S.-person gating, and deemed-export analysis. - Govern AI tool usage against sensitive material, including approved tools, provisioning, and seat/budget management. - Run IT operations directly: device management, identity, onboarding/offboarding, and multi-site systems, until a dedicated IT hire takes over.
Requirements - Demonstrated ability to build a security function as a team of one, then scale it. - Hands-on depth configuring controls across developer workstations, build infrastructure, and non-standard environments. - Practical experience securing source control, CI/CD, secrets management, and cloud infrastructure. - Working knowledge of NIST SP 800-171, CMMC, or comparable federal frameworks, ideally having led a company through an assessment. - IT operations depth to run devices, identity providers, SSO, automated user lifecycle, and multi-site networking independently. - Strong identity and access architecture skills (SSO, MFA, least privilege, practical access reviews). - Clear written communication and the judgment to align engineers around security decisions. - Willingness to travel approximately 25% between offices. - U.S. person status (citizen or lawful permanent resident) due to export control regulations.
Nice to have - Experience with EAR/ITAR, CUI, or facility clearance processes. - Background in semiconductor, hardware, or EDA environments. - Prior support for federal or defense customer security requirements. - Certifications such as CISSP, GIAC, or CMMC CCP/CCA. - Scripting and infrastructure-as-code skills (Python, Bash, IaC). - Experience governing AI tools inside a company.
Benefits and work setup - Base salary generally $180,000–$230,000 with a 10% annual bonus, meaningful equity, 401(k) match, company-paid benefits, and paid parental leave.