IT & Security Lead

Maybell Quantum

Denver (CO)

On-site

USD 150,000 - 170,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Competitive compensation
Equity + bonus eligibility
Direct security leadership role
Cross-functional collaboration
Medical, dental, and vision + 401(k)

Job summary

Maybell Quantum is seeking a hands-on IT & Security Lead to own and shape our security program across three sites, including manufacturing floors and labs. You will decide how our environment is defended and implement the controls that protect export-controlled data while enabling rapid product development.

This role combines strategic architecture with practical incident response, identity and access management, and security operations.

Qualifications

  • 8+ years in IT or security with progressive ownership.
  • Practical security ownership with patching, access reviews, and at least one incident end to end.
  • Deep Microsoft 365 and Entra ID security expertise: conditional access, Intune, Defender in production.
  • Experience supporting a manufacturing, labs, or hardware environment.

Responsibilities

  • Own and mature security baseline across all sites: endpoint protection, patch management, logging and recovery.
  • Set security architecture and enforce technical standards in practice.
  • Prepare security posture documentation for customers, insurers, and investors.
  • Run security awareness training and phishing simulations.
  • Own site access security: badging, visitor procedures, and restricted areas across sites.
  • Own detection, logging coverage, and incident response runbooks.

Skills

Security leadership
Microsoft 365 / Entra ID
Incident response
IT troubleshooting
Multi-site support
Regulated data handling

Tools

Microsoft 365 security tools
Entra ID
Intune
Defender
CI/CD security tooling

Job description

At Maybell Quantum, we're redefining the future of computing. As a venture-backed quantum hardware innovator experiencing rapid growth, we build the cryogenic infrastructure that quantum computers run on - dilution refrigerators, cryogenic RF wiring, and the related systems used by quantum computing companies, national labs, and research institutions worldwide. Quantum computers will be as transformative to the next 30 years as the internet was to the last 30 - and our team is creating the hardware foundation to make this revolution possible.

Position Overview

We're seeking a hands‑on IT & Security Lead to become Maybell's first dedicated security hire and the owner of our security program. This is a high‑ownership, high‑visibility role with real architectural authority: you will decide how our environment is defended, and you will also be the person who implements it.

Security at Maybell is not a paper exercise. We are roughly 100 people (and growing) with the security complexity of a much larger company—multiples countries, a manufacturing floor, cryogenic and RF test labs, GDPR obligations, and engineering systems holding export‑controlled technical data. That work currently runs through the executive team. It needs an owner.

Your primary focus is cybersecurity: identity and access, endpoint and email defense, vulnerability and patch management, logging and monitoring, incident response, and the access controls that protect controlled technical data across all three sites. You will also provide day‑to‑day IT troubleshooting and end‑user support as needed.

You'll partner closely with Operations, Engineering, Trade Compliance, and executive leadership to protect the company's most sensitive technical work without slowing down a manufacturing floor or a test lab.

Key Responsibilities
Security Program Ownership
  • Own and mature Maybell's security baseline across all three sites: endpoint protection, patch and vulnerability management, logging, backup and recovery, and periodic access reviews.
  • Set the security architecture and technical standards for how our environment is built, and enforce them in practice.
  • Prepare and maintain the security posture documentation that customers, insurers, and investors will ask for in diligence.
  • Run security awareness training and phishing simulation, and build a culture where reporting is normal.
  • Own physical site access security — badging and access control systems, visitor and escort procedures, and restricted‑area controls for labs, server rooms, and the manufacturing floor across all three sites.
  • Track and report on security metrics — coverage, patch latency, incident volume, and access review completion—and use them to prioritize.
Identity and Access Security
  • Own the security configuration of Microsoft 365 and Entra ID: conditional access, MFA, privileged access, and guest and external sharing governance.
  • Own Defender and the broader M365 security stack, plus email authentication (SPF, DKIM, DMARC) and mail hygiene.
  • Use Intune to enforce endpoint security policy across Windows and macOS at three sites.
  • Own the joiner/mover/leaver process—provisioning, access changes, and offboarding that actually completes.
Security Operations and Incident Response
  • Serve as first responder for phishing, account compromise, and endpoint incidents, with MSP and external IR support as needed.
  • Build and maintain incident response runbooks, and run tabletop exercises against them.
  • Own detection and logging coverage, and triage what those signals surface.
Controlled Technical Data
  • Implement and maintain access controls on export‑controlled technical data. Our Trade Compliance function determines who is permitted access; you build and enforce the controls that make that real, and you provide the evidence that they worked.
  • Support access reviews, egress visibility, and offboarding hygiene on controlled data. This is a meaningful part of the role, not a footnote.
  • Maintain the experience and certification requirements for personnel who handle export‑controlled technical data — confirm that training, certification, and authorization prerequisites are satisfied before access is granted, re‑verify on role change, and keep the supporting records.
  • Classification of controlled technical data belongs to Trade Compliance; implementation and enforcement belong to you. That separation is deliberate.
Engineering, Manufacturing, and Lab Systems
  • Secure CAD, PLM, and engineering file infrastructure—in scope for this role, not left to engineering.
  • Own source code security — repository access and branch protections, secrets management so credentials never live in code, and CI/CD pipeline security including build integrity, dependency risk, and artifact signing.
  • Design and maintain network segmentation for lab and test instrumentation that cannot be patched or managed conventionally.
  • Address manufacturing IT risk: shop floor systems, ERP endpoints, and the practical realities of instrument PCs running vendor software with long support tails.
  • Hold a standing working relationship with Operations and Engineering leadership on manufacturing and lab systems. Those functions are partners with real operational stakes, not just internal customers.
IT Operations and Support
  • Provide day‑to‑day IT troubleshooting and end‑user support as needed. This is a secondary responsibility—real, but not the focus of the role.
  • Support all global locations, including network, procurement, and local vendor coordination.
  • Own IT vendor and license management—MSP, SaaS portfolio, hardware procurement, and renewals.
  • Push routine support and administration to automation, self‑service, and our MSP wherever it can go, so security work stays the priority.
Qualifications
  • 8+ years in IT or security with progressive ownership; you've been the senior or sole technical decision‑maker for an environment.
  • Practical security ownership—you've run patching, access reviews, and at least one real incident end to end.
  • Deep, current Microsoft 365 and Entra ID security expertise: conditional access, Intune, and Defender in production, not in a lab.
  • Experience supporting a physical operating environment—manufacturing, labs, or hardware engineering. A background exclusively in software companies is unlikely to prepare you for this.
  • Willingness to handle IT troubleshooting and end‑user support when it's needed, without letting it crowd out the security program.
  • Comfort being the person who says no to local admin, unmanaged devices, and shadow SaaS—including to senior people.
  • Exposure to regulated data handling—export controls, ITAR/EAR, CMMC, GDPR, or similar is a strong plus.
  • Multi‑site or international support experience, ideally including Europe, is a strong plus.
  • Experience managing an MSP relationship rather than being managed by one is a strong plus.
  • Network segmentation for OT or lab environments, and CAD/PLM platform experience (SolidWorks PDM, Windchill, or comparable) are strong pluses.
  • Application and source code security experience — repository access controls, secrets management tooling, and securing CI/CD pipelines (GitHub/GitLab, Azure DevOps, or comparable) is a strong plus.
  • Familiarity with physical security and site access controls — badging and access control systems, visitor management, and restricted‑area procedures is a strong plus.
  • Relevant certifications (CISSP, CISM, SC‑200, AZ‑500, or comparable) are welcome but not required.
  • Comfort operating with autonomy and ambiguity in a fast‑moving, resource‑constrained environment.
  • Demonstrated desire to own and build—not just execute someone else's playbook.
What We Offer
  • Competitive Compensation: Base salary range $150,000-$170,000, depending on depth of security and M365 ownership and manufacturing environment experience, plus meaningful equity participation and annual bonus eligibility.
  • Real Authority: You will set the security architecture for the company, not inherit someone else’s. This is the founding security role.
  • Growth Trajectory: A direct path to building and leading Maybell's security function as the company scales.
  • Impact: Direct responsibility for protecting the technical work behind one of the most transformative technologies of our lifetime.
  • Exceptional Team: Collaboration with world‑class scientists, engineers, and business leaders who are defining a new industry.
  • Comprehensive Benefits: Medical, dental, and vision insurance, 401(k), and paid time off.

At Maybell Quantum, we're solving incredibly challenging problems at the cutting edge of physics and engineering. If you're excited about defending one of the most transformative technologies of our lifetime, we want to hear from you.

Maybell is an equal opportunity employer. Because this role involves administrative access to systems containing export‑controlled technical data, we may be required to verify your status as a U.S. person or to obtain export authorization; we assess this consistently with applicable law and do not discriminate on the basis of citizenship or national origin beyond what U.S. export regulations require.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT & Security Lead
IT & Security Lead

Maybell Quantum Industries • Denver (CO)

On-site
USD 150,000 - 170,000
Competitive Salary
Real Authority
Growth Path
+3
Senior Manager, Security Engineering
Senior Manager, Security Engineering

Quanta Services, Inc. • Houston (TX)

Hybrid
USD 140,000 - 210,000
Principal Security Specialist - 939
Principal Security Specialist - 939

Quantinuum • Broomfield (CO)

On-site
USD 160,000 - 200,000
Technical Product Marketing Manager
Technical Product Marketing Manager

InvestedintheMission • Denver (CO)

On-site
USD 110,000 - 150,000
Competitive pay
Equity participation
Growth opportunities
+2
Founding IT & Security Lead for Quantum Hardware
Founding IT & Security Lead for Quantum Hardware

Maybell Quantum Industries • Denver (CO)

On-site
USD 150,000 - 170,000
Competitive Salary
Real Authority
Growth Path
+3
Senior Manager, Security Engineering
Senior Manager, Security Engineering

Socket.dev • Houston (TX)

Hybrid
USD 180,000 - 230,000
Technical Product Marketing Manager
Technical Product Marketing Manager

Maybell Quantum • New York (NY)

On-site
USD 110,000 - 150,000
Competitive salary
Growth opportunities
Impactful work
+2
Senior Cybersecurity Engineer - 930
Senior Cybersecurity Engineer - 930

Quantinuum • Broomfield (CO)

On-site
USD 112,000 - 140,000
Flexible work schedule
Health, dental, and vision insurance
401(k) match
Strategy and Operations Associate
Strategy and Operations Associate

Maybell Quantum • Denver (CO)

On-site
USD 100,000 - 140,000
Health, dental, and vision insurance
401(k) matching
Flexible PTO policy
+2
Lead IT & Security Architect — Quantum Hardware
Lead IT & Security Architect — Quantum Hardware

Maybell Quantum • Denver (CO)

On-site
USD 150,000 - 170,000
Competitive compensation
Equity + bonus eligibility
Direct security leadership role
+2