DEFCON AI seeks a Director of IT & Security to lead all information technology and security functions for its growing, mission-driven organization. This role is both strategic and hands-on, requiring ownership of security posture, compliance programs, and audit readiness. The ideal candidate will have 8+ years of progressive IT experience, including leadership responsibility.
Key Highlights
Key Responsibilities
Technical Skills Required
Benefits & Perks
Nice to Have
Job Description
About Defcon Ai
RESILIENCE IN THE FACE OF DISRUPTION. DEFCON AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.
In today's dynamically changing world, DEFCON AI's technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.
About the Role
We are seeking a Director of IT & Security to lead all information technology and security functions for our growing, mission driven organization supporting U.S. government, defense, and commercial clients.
This role is both strategic and hands-on. You will own our security posture, compliance programs, and audit readiness (CMMC 2.0 and SOC 2), while also ensuring that day-to-day IT operations run smoothly. You will serve as the owner accountable for audits, security controls, and IT risk, while partnering closely with Operations, Engineering, HR, and Finance.
This role reports directly to the Head of Ops and will help shape how our IT and security capabilities scale as the company grows.
Key Responsibilities
Security, Compliance & Risk (Primary Focus)
- Own CMMC 2.0 and SOC 2 end-to-end, including:
- Control design and implementation
- Evidence collection and readiness
- Audit coordination and remediation
- Serve as the primary point of contact for auditors, assessors, and external security partners
- Maintain and evolve security policies, standards, and procedures aligned with DoD and federal requirements
- Oversee access control, device security, identity management, and incident response processes
- Partner with leadership to assess and manage IT and security risk across the organization
- Lead all IT functions supporting corporate and program needs
- Own IT architecture, tooling decisions, and vendor selection
- Manage relationships with MSPs, security vendors, and cloud providers
- Ensure secure, reliable operation of systems supporting a distributed workforce
- Plan and execute IT improvements that scale with company growth
- Provide guidance and escalation support for IT hardware/software issues as needed
- Support a culture of responsive, pragmatic IT service (without being a fulltime helpdesk)
- Help mentor and support an IT Support Speciaist & Cloud Infrastructure Engineer
- Balance operational execution with long term security and compliance priorities
Interested in remote work opportunities in Cyber Security? Discover Cyber Security Remote Jobs featuring exclusive positions from top companies that offer flexible work arrangements.
- 8+ years of progressive IT experience, including leadership responsibility
- Direct ownership of at least one of the following:
- CMMC 2.0 readiness or implementation
- SOC 2 audits (Type I or Type II)
- Experience operating in government contracting / defense / regulated environments
- Strong working knowledge of:
- NIST 800171 / NIST 80053
- Identity and access management
- Endpoint security and device management
- Cloudbased IT environments (AWS, Azure, or similar)
- Ability to communicate clearly with executives, auditors, and nontechnical stakeholders
- Comfortable operating in a small company where priorities shift and handson work is sometimes required
- Prior experience supporting DoD programs or federal contracts
- Active or previously held security clearance (or eligibility to obtain)
- Experience scaling IT/security functions from ~30–50 employees upward
- Familiarity with government approved tooling and compliance platforms
- Experience managing or working alongside MSPs in regulated environments
- The company is audit ready at all times, not scrambling
- CMMC 2.0 and SOC 2 requirements are clearly owned, documented, and operationalized
- Employees experience reliable, secure IT support without friction
- Leadership has confidence in IT risk posture and compliance maturity
- The IT function scales cleanly as the company grows
Browse our curated collection of remote jobs across all categories and industries, featuring positions from top companies worldwide.
- You will have real ownership and authority, not just responsibility without control
- You'll partner directly with the Head of Operations and leadership team
- You'll shape the IT and security foundation for a missionfocused, governmentaligned organization
- This role blends security leadership, operational execution, and strategic influence
- A fully remote, results-based environment
- Competitive salary, bonus, and equity package
- 100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family
- Unlimited PTO, with your manager's approval
- Flexible work environment where you manage your work day
- 14 weeks of fully-paid parental leave
We're an Equal Opportunity Employer: You'll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.
Applicant Data Disclosure
By submitting an application, you acknowledge that Defcon AI uses third-party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, "Hiring Platforms"). Your application materials, including your résumé, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:
- Managing and administering your application throughout the hiring process;
- Verifying the accuracy and authenticity of application materials, including by cross-referencing information you provide against publicly available sources and proprietary databases;
- Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.
Defcon AI requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Defcon AI's data retention policies.
For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice.
Similar Jobs
Explore other opportunities that match your interests
Huntress
Cybersecurity Network Engineer
Banner Health
Senior Security Engineer - Agentic AI Security