Cybersecurity & IT Engineer

Compound Eye

Redwood City (CA)

Hybrid

USD 150,000 - 185,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Medical, dental, and vision insurance
Annual home office stipend
ISO stock options
401(k) with match after 6 months
Flexible PTO and holidays

Job summary

Compound Eye seeks a Cybersecurity & IT Engineer to own identity, endpoint, network, and security practice for a hands-on, generalist role in engineering. You will fix friction, harden access, audit OAuth grants, and enable secure lab work for a mostly remote team.

You’ll partner with DevOps on AWS, GPUs, and the developer toolchain while applying NIST 800-171 and CMMC 2.0 practices. No security certification required.

Qualifications

  • 5+ years in IT, systems administration, or security engineering, including time owning broad scope on a small team.
  • Hands-on administration of both Microsoft 365 and Google Workspace.
  • Strong Linux administration, plus working competence with Windows and macOS.
  • Hands-on networking experience with firewalls, VPNs, managed switches, VLANs, routing.
  • Practical experience with zero-trust/overlay networking (Cloudflare Tunnel, WireGuard, Tailscale, or similar).
  • Ownership of DNS and email authentication for a production domain.
  • Familiarity with NIST 800-171 and CMMC 2.0 sufficient to avoid creating compliance debt. No certification required.
  • A track record of writing security practices that engineers actually adopt.
  • Comfortable working independently and partnering with engineering teams without close oversight.

Responsibilities

  • Build our internal security standard on top of NIST 800-171: Hardening guides, onboarding/offboarding, access reviews, incident response runbooks
  • Run recurring access, logs, and configuration audits, and maintain evidence for our compliance contractor.
  • Own identity across Entra ID, Intune, Microsoft 365 (Defender, Purview, GCC High), and Google Workspace.
  • Own email authentication and DNS (SPF, DKIM, DMARC, MTA-STS) and manage zones/certificates across Cloudflare.
  • Secure engineer and lab access via Cloudflare Tunnel/Zero Trust Mesh, VPN jump hosts, and SSH certificate authorities.
  • Manage the device fleet (Windows, macOS, Linux, Android, iOS) and the physical network (firewalls, switches, VLANs, lab isolation).
  • Define AI tooling guardrails for Claude Code and other agentic workflows.
  • Keep documentation current and manage vendor relationships within budget.
  • Manage hardware logistics from our Redwood City office, including shipping, returns, and spare equipment storage.

Skills

Identity management
Endpoint security
Network security
Zero trust
DNS & DMARC
Linux admin
Windows/macOS
Cloudflare Tunnel
Entra ID
Google Workspace
Microsoft 365

Tools

Cloudflare Tunnel
VPN
SSH certificates
Google Workspace
Microsoft 365

Job description

Company Overview

Compound Eye teaches machines to understand their surroundings in 3D and in real time using only passive sensors like cameras. Our VIDAS™ technology enables vehicles, drones, and other robots to determine their position and navigate their environment without LiDAR, radar, or GPS. Compound Eye has customers in both defense and commercial robotics and is backed by Khosla Ventures, RTX Ventures, and other leading investors. We operate as a CMMC 2.0 Level 2 environment supporting a team of 20 computer vision and machine learning engineers.

The Role

We're hiring a Cybersecurity & IT Engineer to report directly to the VP of Engineering. You will own the identity, endpoint, network, and security practice that supports our engineering team. You'll inherit a working stack with room to improve it.

This is a hands-on generalist role, not a ticket-queue role and not a compliance-paperwork role. You'll sit in engineering standups, find where access, identity, or network friction is slowing the team down, and have the autonomy to fix it. On a given week, you might harden conditional access policies in Entra, audit third-party OAuth grants in Google Workspace, get a remote engineer a working path to a Jetson AGX sitting on a lab VLAN, fix a DMARC alignment failure, and write the internal standard that keeps all three from breaking again.

A large part of the job is enabling engineers to build securely rather than telling them not to. Our engineers connect distributed equipment over Cloudflare tunnels and mesh VPN overlays, run agentic tooling like Claude Code against real codebases, and stand up their own lab environments. You'll define what safety looks like, make the safe path the easy path, and make it work for a mostly-remote team.

You won't own CMMC compliance and you are not expected to hold a certification yourself. But we're a CMMC 2.0 Level 2 environment, so every configuration decision you make needs to be NIST 800-171 aware. You'll be the person the contractor comes to for evidence and implementation detail. You'll partner with our DevOps Engineer, who owns AWS workloads, GPU compute, and the developer toolchain.

Key Responsibilities
  • Build our internal security standard on top of NIST 800-171: Hardening guides, onboarding/offboarding, access reviews, incident response runbooks
  • Run recurring access, logs, and configuration audits, and maintain evidence for our compliance contractor.
  • Own identity across Entra ID, Intune, Microsoft 365 (Defender, Purview, GCC High), and Google Workspace.
  • Own email authentication and DNS (SPF, DKIM, DMARC, MTA-STS) and manage zones/certificates across Cloudflare.
  • Secure engineer and lab access via Cloudflare Tunnel/Zero Trust Mesh, VPN jump hosts, and SSH certificate authorities.
  • Manage the device fleet (Windows, macOS, Linux, Android, iOS) and the physical network (firewalls, switches, VLANs, lab isolation).
  • Define AI tooling guardrails for Claude Code and other agentic workflows.
  • Keep documentation current and manage vendor relationships within budget.
  • Manage hardware logistics from our Redwood City office, including shipping, returns, and spare equipment storage.
To Thrive in This Role, You Have
  • 5+ years in IT, systems administration, or security engineering, including time owning broad scope on a small team.
  • Hands-on administration of both Microsoft 365 and Google Workspace.
  • Strong Linux administration, plus working competence with Windows and macOS.
  • Hands-on networking experience with firewalls, VPNs, managed switches, VLANs, routing.
  • Practical experience with zero-trust/overlay networking (Cloudflare Tunnel, WireGuard, Tailscale, or similar).
  • Ownership of DNS and email authentication for a production domain.
  • Familiarity with NIST 800-171 and CMMC 2.0 sufficient to avoid creating compliance debt. No certification required.
  • A track record of writing security practices that engineers actually adopt.
  • Comfortable working independently and partnering with engineering teams without close oversight.
Work Environment
  • Primarily hybrid from our Redwood City, CA office: typically 1-3 days per week on-site, with more days during build-outs and quarterly company on-sites.
  • Less than 10% domestic travel, occasional and infrequent.
  • Able to lift and carry equipment up to 40 lbs and do occasional on-site physical work (cabling, racking); reasonable accommodations available upon request.
Compensation & Benefits
  • Base salary: $150k-185k, depending on experience.
  • Strong Incentive Stock Options (ISO)
  • Medical, dental, and vision insurance
  • Annual home office stipend
  • Employer-paid long-term disability, short-term disability, and life insurance
  • 401(k) with employer match after 6 months
  • Flexible PTO and 8 holidays + 2 week winter break
  • Paid family leave
  • Quarterly onsites in San Francisco

We're looking for a great engineer to join our US team of twenty-five. Our mission is to teach machines to see. Our culture is based on transparency, mutual respect, mutual accountability, and valuing great ideas no matter where they come from. We already have revenue and our Series A round was led by a tier-one VC. We are a remote-first company with employees across the United States. We had remote employees long before the pandemic and our team is now distributed across multiple states. We offer competitive benefits including comprehensive health care plans, 401k with matching, flexible schedules, and discretionary PTO.

Compound Eye is committed to building a diverse and inclusive work environment. We understand that no candidate is perfectly qualified for any job and experience comes in different forms.

Compound Eye is an Equal Opportunity Employer and a VEVRAA Federal Contractor. We do not discriminate based on race, color, religion, sex, national origin, disability, or protected veteran status. This position requires access to technology controlled under the International Traffic in Arms Regulations (ITAR). Applicants must be a U.S. person as defined under ITAR (U.S. citizen, lawful permanent resident, asylee, or refugee) or qualify for a license exception.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity & IT Engineer
Cybersecurity & IT Engineer

Compound-Eye • Redwood City (CA)

Hybrid
USD 150,000 - 185,000
Annual home office stipend
ISO stock options
Health insurance
+3
Cybersecurity & IT Engineer
Cybersecurity & IT Engineer

Compound Eye, Inc. • Redwood City (CA), Northern (KY)

Hybrid
USD 150,000 - 185,000
Incentive Stock Options (ISO)
Medical, dental, and vision insurance
Annual home office stipend
+5
Robotics Integration Engineer
Robotics Integration Engineer

Compound Eye • Redwood City (CA)

On-site
USD 135,000 - 175,000
ISO stock options
Medical, dental, vision insurance
Annual home office stipend
+2
Robotics Integration Engineer
Robotics Integration Engineer

Compound Eye, Inc. • Redwood City (CA), Northern (KY)

Hybrid
USD 135,000 - 175,000
ISO stock options
Medical, dental, and vision insurance
Annual home office stipend
+2
Senior Security Engineer - Product Security
Senior Security Engineer - Product Security

Cogent-Security • United States

On-site
USD 100,000 - 300,000
Founding IT Engineer
Founding IT Engineer

Cogent-Security • San Francisco (CA)

On-site
USD 140,000 - 190,000
Field Robotics Engineer (SF Bay Area w/ Travel)
Field Robotics Engineer (SF Bay Area w/ Travel)

SupportFinity™ • California (MO)

Hybrid
USD 135,000 - 175,000
Strong Incentive Stock Options
Medical, dental, and vision insurance
Annual home office stipend
+3
Founding IT Engineer
Founding IT Engineer

Cogent • San Francisco (CA)

On-site
USD 140,000 - 210,000
Security Engineer - Infrastructure Security
Security Engineer - Infrastructure Security

Figureai • San Jose (CA)

On-site
USD 150,000 - 250,000
Security Engineer - Infrastructure Security
Security Engineer - Infrastructure Security

AI Chopping Block • San Jose (CA)

Hybrid
USD 150,000 - 250,000