Head of Information Security

Hampton North

San Francisco (CA)

On-site

USD 180,000 - 320,000

Full time

34 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Hampton North is seeking a Head of Security to architect and mature our security program from the ground up in a hands-on role. You will define security strategy, establish policies, and lead the build-out of our IT and infrastructure security posture while aligning with ITAR/EAR requirements and DFARS timelines.

In this early-stage leadership position, you will shape governance, risk, and vendor relationships, then recruit and scale the team as the company grows, balancing security with rapid

Qualifications

  • 8+ years in security, with program-building experience.
  • Hands-on depth in enterprise security: identity, endpoint, cloud, network.
  • Experience with NIST 800-171, CMMC, DFARS or equivalent.
  • Familiarity with ITAR/EAR constraints on cloud/tools.
  • Comfort working without an existing team and prioritizing with limited resources.
  • Credibility with executives, engineering leaders and government customers.

Responsibilities

  • Secure corporate IT and infrastructure security across the enterprise.
  • Establish security foundations: policies, asset inventory, risk register.
  • Coordinate ITAR/EAR controls with Legal and enforce U.S.-person access.
  • Stand up detection and response: monitoring and incident response plan.
  • Develop product and supply chain security framework and later hire depth.
  • Build and manage security team and vendor relationships (MSSP, assessor).

Skills

Security leadership
Hands-on enterprise security
NIST 800-171 / CMMC / DFARS
ITAR/EAR compliance
Independent prioritization
Executive credibility

Job description

As our first Head of Security, you will build one: secure our corporate IT and infrastructure, put the foundations in place for DoD compliance, and grow a team as the company scales. This is a hands-on builder role. You will make architecture decisions, configure tools and write policy yourself in the first year, then hire people to take over.

What You Own
  • Corporate IT and infrastructure security: Identity and access management, endpoint protection, network and cloud security, logging and monitoring, and secure configuration across the enterprise environment.
  • Security foundations: Policies, risk register, asset inventory, vendor risk and security awareness, all built from the ground up.
  • Export control: Work with Legal on ITAR/EAR controls, including U.S.-person access enforcement across systems and tooling.
  • Detection and response: Stand up monitoring (in-house or MSSP) and an incident response plan, including DFARS reporting timelines.
  • Product and supply chain security (later phase): Establish a basic framework for firmware integrity, secure boot and supplier risk, then hire or contract specialist depth.
  • Team and vendors: Build the team over time and manage MSSP, assessor and tooling relationships.
What You Bring
  • 8+ years in security, with experience building or significantly maturing a program from an early state
  • Hands-on depth in enterprise security: identity, endpoint, cloud and network
  • Experience with NIST 800-171, CMMC, DFARS or similar frameworks in defense or government contracting
  • Familiarity with ITAR/EAR constraints on cloud and tooling choices
  • Comfortable operating without an existing team, and able to prioritize ruthlessly with limited resources
  • Credibility with executives, engineering leaders and government customers
Nice to Have
  • Defense tech or hardware company experience
  • Exposure to embedded, OT or firmware security
  • Experience with a facility clearance or classified environments
  • Prior experience as a first security hire at a growth-stage company
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Director of Information Security
Director of Information Security

ClinLab Solutions Group • Boston (MA)

On-site
USD 180,000 - 300,000
Founding Security Engineer
Founding Security Engineer

Wise Insight • San Francisco (CA)

On-site
USD 150,000 - 210,000
Head of Security
Head of Security

Code Metal • United States

Hybrid
USD 180,000 - 280,000
Flexible hybrid work
401k / IRA
Uncapped vacation & holidays
+2
Lead Security Engineer
Lead Security Engineer

Harrison Clarke • San Francisco (CA)

On-site
USD 180,000 - 240,000
Director of Information Security
Director of Information Security

Old Republic Commercial Risk • Center Square (PA)

On-site
USD 180,000 - 240,000
Head of Information Security / CISO at Cordia Resources by Cherry Bekaert Arlington, VA
Head of Information Security / CISO at Cordia Resources by Cherry Bekaert Arlington, VA

Cordia Resources by Cherry Bekaert • Arlington (VA)

On-site
USD 180,000 - 250,000
Security Engineer
Security Engineer

Invictus Direct • San Francisco (CA)

On-site
USD 100,000 - 200,000
Relocation assistance
Visa sponsorship
Head of Security
Head of Security

Phaxis • New York (NY)

On-site
USD 180,000 - 320,000
Senior Manager of Information Security
Senior Manager of Information Security

Plume • United States

On-site
USD 180,000 - 240,000
Sr. CyberSecurity Engineer
Sr. CyberSecurity Engineer

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000