Director of Information Security

Efficient Computer•Austin, TX
•$180,000 - $230,000•Hybrid

About The Position

Efficient Computer is seeking its first dedicated security leader to establish and own the company's security program. This role involves protecting intellectual property, meeting defense and government customer security standards, handling export-controlled technology, and hardening the engineering environment. Initially, this position will be a team of one, also responsible for end-to-end information technology operations, including devices, identity, onboarding/offboarding, and supporting a fast-growing, multi-site company. As the company scales, a dedicated IT Manager will be hired, allowing the Director to focus solely on security. This is a hands-on role requiring direct involvement in policy creation, console management, configuration, and architecture reviews.

Requirements

  • 7+ years in information security, including experience as the founding or sole security owner at a company or building a program from scratch.
  • Genuine hands-on depth, capable of configuring controls directly, including on non-standard developer workstations and build infrastructure.
  • Practical experience securing source code and developer infrastructure: source control platforms, CI/CD, secrets management, and cloud infrastructure.
  • Working knowledge of NIST SP 800-171, CMMC, or a comparable federal framework, with experience taking a company through an assessment.
  • Sufficient IT operations depth to manage independently for a period: MDM, identity providers and SSO, automated user lifecycle management, and multi-site networking.
  • Comfort with identity and access architecture: SSO, MFA, least privilege, and access reviews.
  • Clear written communication skills for documentation and explaining security decisions.
  • Willingness to travel approximately 25% of the time between offices.
  • U.S. person status (U.S. citizen or lawful permanent resident) due to export control regulations.

Nice To Haves

  • Experience with export-controlled technical data (EAR or ITAR), CUI, or a facility clearance process.
  • Experience in semiconductor, hardware, or EDA environments, or settings where the engineering toolchain drove security design.
  • Experience supporting federal or defense customer security requirements.
  • Security certifications (e.g., CISSP, GIAC, CMMC CCP or CCA).
  • Scripting and automation skills (e.g., Python, Bash, infrastructure as code).
  • Experience rolling out or governing AI tools in a company setting.

Responsibilities

  • Design and enforce protection for source code, compiler toolchain, and hardware designs, including classification, encryption, storage, and access controls.
  • Own the access model for engineering systems, including repository permissions, token and credential governance, and access reviews.
  • Establish controls for sensitive technical data under third-party confidentiality obligations.
  • Build and maintain evidence of reasonable measures to protect trade secrets.
  • Secure a developer-heavy, multi-platform engineering environment, making hardening work for engineers.
  • Secure the software supply chain end-to-end, including dependencies, build pipelines, release integrity, and the compiler.
  • Own network and infrastructure security architecture, including build-vs-buy and in-house-vs-managed decisions.
  • Work with technology vendors and service providers as a technical peer.
  • Own detection, logging, and incident response, and develop response playbooks.
  • Own and mature NIST SP 800-171 and CMMC programs, including assessments, system security plans, POA&Ms, SPRS, remediation, and audit readiness.
  • Lead the security aspects of customer, partner, and investor diligence, including security questionnaires and government customer reviews.
  • Establish policies and controls for handling sensitive and controlled information, and train employees.
  • Own the technical implementation of export control obligations, including access segregation, U.S.-person gating, and deemed export analysis.
  • Partner with Legal on classification, licensing, and restricted party screening.
  • Set and administer policies for AI tool usage against sensitive material, including approved tools, provisioning, and data protection.
  • Own AI tool spend and seat management.
  • Serve as the company’s data protection and privacy lead.
  • Own day-to-day IT across all offices: hardware, software, accounts, and access.
  • Run onboarding and offboarding processes end-to-end.
  • Manage the device fleet and MDM, including configuration baselines, patching, disk encryption, and endpoint security.
  • Administer identity and access, including SSO, MFA, automated user provisioning, and role-based access across the SaaS stack.
  • Own office IT infrastructure across multiple sites, including networking, Wi-Fi, conference rooms, AV, and physical access systems.
  • Manage IT vendors, licensing, and renewals.
  • Build and drive the security and IT roadmap based on company growth and customer requirements.
  • Advise leadership on security and IT strategy, budget, and build-vs-buy decisions.
  • Help hire the first dedicated IT Manager, hand off day-to-day operations, and lay the groundwork for a security and IT team.

Benefits

  • Competitive base salary
  • 10% annual bonus
  • Meaningful equity
  • Comprehensive benefits
  • 401(k) match
  • Company-paid benefits
  • Paid parental leave
  • Flexibility
  • Opportunities to grow skills and career
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service