Government & regulatory compliance
• Drive CMMC Level 2 certification to completion — scoping, SSP/POA&M ownership, evidence collection, and managing the C3PAO assessment (we’re already evaluating firms like Schellman, A-LIGN, and CBIZ Pivot Point).
• Own our NIST SP 800-171 / DFARS 252.204-7012 posture and continuous compliance.
• Stand up and administer our ITAR/EAR export-control program — technical data segregation, access controls for
U.S. persons, deemed-export policies.
• Maintain AS9100 and SOC 2 alignment in coordination with quality and operations.
Security engineering & operations
• Own identity, endpoint, and network security across our stack (JumpCloud MDM, CrowdStrike EDR, Google/1Password, Cloudflare, AWS, Tailscale).
• Define and enforce CUI boundary architecture across edge (Jetson/Orin), on-prem (GPU cluster), and cloud (AWS).
• Own our Incident Response Plan and serve in the IRT; run tabletop exercises and lead real incidents.
• Vendor/third-party risk management, including ITAR/CMMC-aware external partner collaborations.
• Build the security roadmap and budget; make build-vs-buy calls decisively.
• Hire, mentor, and lead a security team (GRC, security engineering).
• Partner with engineering, IT, and leadership to make security a default, not a blocker.