Want to build security, not just maintain it?
This isn’t a role where you’ll inherit a mature security program, spend your days updating policies, or stay buried in one narrow piece of the environment.
We’re looking for an experienced security focused Systems Engineer who wants to take real ownership of security and compliance while staying hands-on with the technology behind it.
You’ll serve as a go-to security expert across the organization, partnering closely with IT leadership to strengthen the security program, advance CMMC and NIST compliance, and tackle infrastructure and systems initiatives along the way.
And yes, there’s a pretty great perk: work four 10-hour days and get a three-day weekend every week.
Why This Role Is Different
This is a newly created position, which means there’s an opportunity to put your fingerprints on the security program rather than simply stepping into someone else’s playbook.
You’ll have:
- Ownership: Help build, mature, and operationalize the security and compliance program.
- Executive visibility: Work closely with IT leadership and the CTO on security strategy, risk, and framework roadmaps.
- Hands-on technical work: Security is the priority, but you’ll still work with systems, infrastructure, identity, endpoints, networking, Microsoft 365, and cloud technologies.
- Autonomy: You’ll be trusted to own projects, make recommendations, communicate risk, and drive initiatives forward.
- Variety: Work across security, compliance, infrastructure, and systems rather than being siloed into one narrow function.
- A 4/10 schedule: Four workdays. Three-day weekends. Enough said.
What You’ll Own
Your center of gravity will be security and compliance, particularly within a government contracting environment.
You’ll:
- Drive readiness and ongoing compliance for CMMC Level 2 and NIST SP 800-171.
- Support SOC 2 and PCI DSS initiatives, including control design, evidence collection, remediation, and audit coordination.
- Take security and infrastructure projects from idea to implementation, managing timelines, stakeholders, vendors, risks, and deliverables.
- Administer and improve security technologies across endpoint protection, IAM, SIEM, MFA, email security, vulnerability management, and logging.
- Lead access reviews, security awareness efforts, phishing simulations, and incident-response tabletop exercises.
- Develop the policies, procedures, and security plans required for compliance, then make sure those controls actually work in the real world.
- Partner with leadership on security risk, vendor reviews, customer requirements, and business decisions.
- Roll up your sleeves alongside the IT team on Microsoft 365, Entra ID, servers, networking, endpoints, identity, and other infrastructure initiatives.
Who We’re Looking For
This role is a great fit for someone who started with a strong systems/infrastructure foundation and moved deeper into security, or a Security Engineer who has never lost the ability to get into the systems and solve problems.
Ideally, you bring:
- 8–12 years of progressive IT experience with meaningful depth in security and compliance.
- Hands-on experience with government contracting security frameworks, ideally NIST SP 800-171 and/or CMMC.
- Experience helping build, mature, or significantly improve a security program from the ground up, rather than simply operating within an established one.
- Knowledge of commercial frameworks such as SOC 2, PCI DSS, or ISO 27001.
- Strong systems fundamentals across Windows/Linux servers, Microsoft 365, identity and access management, networking, and endpoint management.
- Experience owning technical projects from kickoff through implementation.
- The ability to communicate just as effectively with executives and business leaders as you do with engineers and IT teammates.
- CompTIA Security+ or equivalent certification.
- Practical judgment. You understand the difference between checking a compliance box and building security controls people can realistically follow.
Even Better If You Have
- CISA, CCSP, CySA+, or CMMC CCP
- Experience supporting an organization through a CMMC assessment
- Manufacturing, defense, government contracting, or other regulated-industry experience
- Familiarity with ITAR/EAR
- AWS and/or Azure security experience
- ERP exposure