Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
MACH Ai8 is seeking an IT Manager to own the technology environment, lead the help desk, manage endpoints and identities, and govern security and compliance programs. The role spans networking, cloud, AI-enabled IT operations, and budget stewardship for a security-focused, U.S.-owned advanced wireless systems company.
You will drive CMMC Level 2 and NIST SP 800-171 controls, oversee lab connectivity, and implement modern AI tools to optimize IT processes while ensuring auditable control evidence
MACH Ai8 builds the next generation of American wireless connectivity products designed for reliability, security, and scale. The company is being formed as a U.S.-owned and controlled advanced wireless systems company that designs, engineers, manufactures, certifies, provisions, and manages secure connected devices for the American market.
We serve both internal house-brand product launches and external ODM/private-label customers that need trusted U.S.-controlled product development, firmware control, secure provisioning, lifecycle software, supply-chain provenance, and domestic or nearshore production pathways.
The IT Manager will own the technology environment MACH Ai8's own employees depend on every day, and the security posture the company must be able to prove to customers, partners, and government-adjacent programs. This person will run the help desk, manage endpoints and identity, administer SaaS systems, design and support office and lab networking including internet and connected 5G/LTE FWA links, deploy and govern AI platforms, and lead the practical implementation of CMMC Level 2 / NIST SP 800-171.
The right candidate is a hands-on IT generalist with real depth in networking and cybersecurity, the discipline to own a compliance program, and genuine fluency with modern AI tools. The role requires enough technical depth to configure a firewall and trace a network path personally, enough rigor to build and maintain control evidence that survives an assessment, and enough judgment to know what to automate, what to document, what to buy, and what to escape.
Office and lab networking, including connected FWA
Design, deploy, and support MACH Ai8's internal networks: firewalls, VLANs and segmentation, switching, enterprise Wi-Fi, VPN and secure remote access, DNS/DHCP, NAT, RADIUS/802.1X, QoS, ISP circuits, and 5G/LTE connected FWA gateways used as backup or primary WAN for the office and lab. Own uptime, failover testing, and network documentation.
Lead the internal implementation of the 110 NIST SP 800-171 controls across the 14 CMMC domains: scoping and enclave design for CUI, System Security Plan (SSP) authoring, POA&M management, control evidence and artifact collection, annual self-assessment and SPRS scoring, and readiness for a C3PAO assessment where a contract requires one. Coordinate outside RPO/C3PAO advisors where used.
Own the help desk end to end: ticketing system, published SLAs, triage and escalation, onboarding and offboarding, asset and license inventory, imaging and MDM for a mixed Mac and Windows fleet, mobile devices, conference rooms and AV, printers, and a knowledge base that measurably reduces repeat tickets.
Run day-to-day security: identity with MFA/SSO, least privilege and periodic access reviews, endpoint protection and EDR, patch and vulnerability management, email and phishing defense, logging and alert review, encryption and key handling, backup integrity, incident-response runbooks and tabletop exercises, security awareness training, and zero-trust principles applied practically.
Own the practical systems layer: Microsoft 365 / Entra ID or Google Workspace, Windows and Linux servers, cloud tenants and infrastructure, file storage and permission models, endpoint management, backup and disaster recovery with tested restores, monitoring, collaboration tools, SaaS consolidation and license spend, lab and test environments, and secure data-room support.
Deploy and govern AI where it improves the business: administer approved AI platforms and copilots, set acceptable-use and data-handling policy, prevent shadow AI and confidential-data leakage, and apply AI and scripting to ticket triage, documentation, configuration generation, log and alert review, vulnerability summarization, knowledge-base creation, compliance-evidence drafting, and onboarding automation.
Manage ISPs, carriers, MSPs, hardware and software vendors, and security tooling: quotes, contracts, renewals, warranty and RMA, asset lifecycle, license true-ups, and a defensible IT budget with prioritized spend recommendations and clear trade-offs for the CEO.
Support Engineering and Quality with lab connectivity, bench network access, test equipment on the network, isolated test VLANs, and controlled access for contractors - without owning product architecture, firmware rollout, device provisioning strategy, or customer deployments.
Create and maintain IT and security policies, SOPs, runbooks, network diagrams, asset registers, onboarding/offboarding checklists, and escalation paths. Define the future help desk, systems, and security hiring plan as headcount grows, and keep the environment explainable to an auditor.