26 days ago
Austin, TX, USA or Sunnyvale, CA, USAStaff+
Base Salary
$180k - $235k/yr
Responsibilities
- Deploy zero-trust network access, secure cloud perimeters, and infrastructure access controls across cloud, lab, and office environments.
- Protect engineering compute, CAD/EDA tools, and proprietary chip design repositories from exfiltration and unauthorized access.
- Implement IAM, PAM, RBAC, MFA, and automated access review processes.
- Design and operate vulnerability management, asset scanning, remediation tracking, SIEM/EDR, intrusion detection, and continuous logging programs.
- Own incident response runbooks, act as primary incident commander, conduct forensic analysis, and lead root-cause post-mortems.
- Lead customer and investor security discussions, vendor risk assessments, and responses to security questionnaires and technical due diligence.
- Own security policies, compliance documentation, data classification, network segmentation, disaster recovery, and the SOC 2 Type II program.
- Collaborate with legal and engineering teams on secure data handling, export controls, and access controls.
- Build and eventually hire and develop a small security function.
Requirements
- 8+ years of experience in security engineering, infrastructure security, or cybersecurity leadership, including primary security ownership at a company with fewer than 200 people.
- Hands-on ownership of a SIEM/EDR stack from end to end.
- Demonstrated IAM/PAM architecture experience with a modern identity provider such as Okta or equivalent.
- Direct experience leading at least one SOC 2 Type II audit cycle and delivering evidence to auditors.
- Experience conducting vendor security assessments and responding to customer or prospect security questionnaires and technical due diligence.
- Working knowledge of ITAR/EAR export control frameworks as applied to technical data and access control.
- Working proficiency in at least one major public cloud, ideally Azure.
- Ability to operate without an existing team and interest in hiring and developing a security function.
- Willingness to work across Sunnyvale and Austin as needed.
- Preferred qualifications include CISSP, CISM, CCSP, or OSCP certification; experience with Vanta, Drata, or similar GRC automation platforms; and experience securing semiconductor EDA/CAD workflows, Linux compute clusters, or physical R&D labs.
Benefits
- 100% coverage of base health plan premiums for employees and dependents, plus HSA contributions.
- Unlimited paid time off.
- 401(k) matching and stock option opportunities.
- Dental, vision, life, hospital, critical illness, and accident insurance.
- Personalized benefit-plan options with cash-back alternatives.
- Full-time onsite work in Austin, Texas, or Sunnyvale, California, with travel or work across both locations as needed.
