Director of Information Security

🔥 13 hours ago

🏄 California, Pennsylvania, +1 more states – Remote

infoinfo

💵 $180k - $230k / year

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Efficient Computer

Efficient Computer

11 - 50 employees

Founded 2022

🏭 Manufacturing

🔧 Hardware

🤖 Artificial Intelligence

Manufacturing • Hardware • Artificial Intelligence

Efficient Computer is a technology company developing ultra-energy-efficient processors and accompanying toolchains for edge and embedded computing. Their Fabric spatial dataflow processor architecture and E1 processor target extreme low-power applications (wearables, satellites, industrial sensors) while the effcc compiler enables developers to run familiar languages and AI/ML frameworks on the new hardware. The company focuses on delivering high-performance, long-lived battery operation and customers are primarily device makers and industrial/space operators.

📋 Description

• Serve as Efficient Computer’s first dedicated security leader and define the company’s security program • Protect intellectual property, meet security standards required by defense and government customers, handle export-controlled technology, and harden the engineering environment • Own information technology end to end initially, including devices, identity, onboarding, offboarding, and operational systems • Design and enforce protection for source code, compiler toolchain, and hardware designs • Own engineering access models, repository permissions, credential governance, and recurring access reviews • Establish controls and evidence for sensitive technical data and trade-secret protection • Secure the developer environment, software supply chain, build pipelines, release integrity, compiler, network, and infrastructure • Own detection, logging, incident response, and playbooks • Lead NIST SP 800-171 and CMMC programs, assessments, SSPs, POA&Ms, SPRS, remediation, and audit readiness • Lead security aspects of customer, partner, investor, and government diligence • Establish policies and controls for sensitive and controlled information and train employees • Implement export-control controls, including access segregation, U.S.-person gating, deemed export analysis, classification, licensing, and restricted-party screening • Govern AI tools, sensitive-data handling, AI tool spend, and seat management • Serve as data protection and privacy lead • Run day-to-day IT, onboarding/offboarding, device fleet and MDM, identity and access, office infrastructure, vendors, licensing, and renewals • Build security and IT roadmaps, advise leadership, and make budget and build-vs-buy decisions • Help hire the first dedicated IT Manager and establish the future security and IT team • Sit on the Operations team, report to the Head of Legal and Compliance, and participate in engineering architecture reviews

🎯 Requirements

• 7+ years in information security, including experience as the founding or sole security owner at a company or building a previously nonexistent program • Hands-on ability to configure security controls on developer workstations and build infrastructure • Experience securing source code and developer infrastructure, including source control platforms, CI/CD, secrets management, and cloud infrastructure • Working knowledge of NIST SP 800-171, CMMC, or a comparable federal framework • IT operations experience with MDM, identity providers and SSO, automated user lifecycle management, and multi-site networking • Experience with identity and access architecture, including SSO, MFA, least privilege, and access reviews • Service mindset paired with strategic judgment • Clear written communication and ability to explain security decisions to engineers • Willingness to travel roughly 25% of the time between offices • U.S. person status required: U.S. citizen or lawful permanent resident • Nice to have: experience with export-controlled technical data, CUI, or facility clearance processes • Nice to have: semiconductor, hardware, or EDA environments • Nice to have: federal or defense customer security requirements • Nice to have: CISSP, GIAC, CMMC CCP, or CCA certifications • Nice to have: Python, Bash, or infrastructure as code • Nice to have: experience rolling out or governing AI tools

🏖️ Benefits

• 10% annual bonus • Meaningful equity • 401(k) match • Company-paid benefits • Paid parental leave • Flexible work arrangements • Opportunities to grow skills and career • Comprehensive benefits

Apply Now

Similar Jobs

🔥 14 hours ago

Intus Care

11 - 50

💼 Consulting

📣 Marketing

📦 Logistics

Security and compliance manager leading HIPAA, SOC 2, and HITRUST programs for IntusCare’s healthcare SaaS platform. Driving audits, risk remediation, incident response, and security governance.

🔥 14 hours ago

Hitachi

10,000+ employees

🚘 Automotive

🏗️ Construction

💼 Consulting

Cybersecurity research director guiding Hitachi’s global innovation, policy, and industry partnerships. Shaping strategy, research, and thought leadership for Hitachi’s technology businesses.

🔥 15 hours ago

Momentive Software

1001 - 5000

🤝 B2B

🤝 Non-profit

Directing cybersecurity governance, risk, and compliance for Momentive Software, which provides cloud software and services to purpose-driven organizations. Leading ISMS, audits, risk management, and GRC teams.

🔥 18 hours ago

Johnson & Johnson

10,000+ employees

🏥 Healthcare

💊 Pharmaceuticals

🧬 Biotechnology

Cybersecurity director leading Johnson & Johnson’s post-close security strategy for acquisitions, divestitures, and integrations. Governing risk, compliance, technical execution, and enterprise security transformation.

🔥 18 hours ago

Johnson & Johnson

10,000+ employees

🏥 Healthcare

💊 Pharmaceuticals

🧬 Biotechnology

Cybersecurity Director leading Johnson & Johnson’s pre-close security strategy for acquisitions, divestitures, and strategic transactions. Governing due diligence, transaction risk, and integration or separation readiness.