As our first Head of Security, you will build one: secure our corporate IT and infrastructure, put the foundations in place for DoD compliance, and grow a team as the company scales. This is a hands-on builder role. You will make architecture decisions, configure tools and write policy yourself in the first year, then hire people to take over.
What You Own
- Corporate IT and infrastructure security: Identity and access management, endpoint protection, network and cloud security, logging and monitoring, and secure configuration across the enterprise environment.
- Security foundations: Policies, risk register, asset inventory, vendor risk and security awareness, all built from the ground up.
- Export control: Work with Legal on ITAR/EAR controls, including U.S.-person access enforcement across systems and tooling.
- Detection and response: Stand up monitoring (in-house or MSSP) and an incident response plan, including DFARS reporting timelines.
- Product and supply chain security (later phase): Establish a basic framework for firmware integrity, secure boot and supplier risk, then hire or contract specialist depth.
- Team and vendors: Build the team over time and manage MSSP, assessor and tooling relationships.
What You Bring
- 8+ years in security, with experience building or significantly maturing a program from an early state
- Hands-on depth in enterprise security: identity, endpoint, cloud and network
- Experience with NIST 800-171, CMMC, DFARS or similar frameworks in defense or government contracting
- Familiarity with ITAR/EAR constraints on cloud and tooling choices
- Comfortable operating without an existing team, and able to prioritize ruthlessly with limited resources
- Credibility with executives, engineering leaders and government customers
Nice to Have
- Defense tech or hardware company experience
- Exposure to embedded, OT or firmware security
- Experience with a facility clearance or classified environments
- Prior experience as a first security hire at a growth-stage company