Head of Security

Foundry RoboticsSan Francisco, CA
Onsite

About The Position

Foundry Robotics is building an AI-native robotics manufacturing company focused on deploying advanced assembly and production capability for leading robotics companies and national-security-critical hardware. We are reimagining manufacturing through advanced robotics. Our mission is to rebuild the American manufacturing industry as an AI-first, assembly-focused, dual-use contract manufacturer. We aim to empower manufacturers with intelligent, efficient, and adaptable robotic systems that redefine productivity and quality. As a founding member of our engineering team, you will have a direct and significant impact on our product, culture, and ultimate success. This role is 100% in-person at our office in the mission, SF.

Requirements

  • Understanding of national security facility requirements.
  • Previous/current Experience as a Facility Security Officer.
  • Proven track record taking an organization through CMMC Level 2 or NIST SP 800-171 assessment, ideally end to end, at least once.
  • Deep, hands-on knowledge of DFARS, CUI handling, and ITAR/EAR export controls.
  • Strong security engineering foundation: identity, endpoint, network, and cloud (AWS) security, you can architect and, early on, implement.
  • Experience building or scaling a security function at a startup or fast-growing company.
  • U.S. person status (required for ITAR-controlled work).
  • Comfort operating with high autonomy and ambiguity in a ~30-person startup.

Nice To Haves

  • SOC 2 and AS9100 experience.
  • Manufacturing, defense, aerospace, or hardware-adjacent background.
  • Familiarity with securing edge/robotics or ML/GPU infrastructure.
  • Relevant certifications (CISSP, CISM, CCP/CCA, etc.).

Responsibilities

  • Drive CMMC Level 2 certification to completion — scoping, SSP/POA&M ownership, evidence collection, and managing the C3PAO assessment.
  • Own our NIST SP 800-171 / DFARS 252.204-7012 posture and continuous compliance.
  • Stand up and administer our ITAR/EAR export-control program — technical data segregation, access controls for U.S. persons, deemed-export policies.
  • Maintain AS9100 and SOC 2 alignment in coordination with quality and operations.
  • Own identity, endpoint, and network security across our stack (JumpCloud MDM, CrowdStrike EDR, Google/1Password, Cloudflare, AWS, Tailscale).
  • Define and enforce CUI boundary architecture across edge (Jetson/Orin), on-prem (GPU cluster), and cloud (AWS).
  • Own our Incident Response Plan and serve in the IRT; run tabletop exercises and lead real incidents.
  • Vendor/third-party risk management, including ITAR/CMMC-aware external partner collaborations.
  • Build the security roadmap and budget; make build-vs-buy calls decisively.
  • Hire, mentor, and lead a security team (GRC, security engineering).
  • Partner with engineering, IT, and leadership to make security a default, not a blocker.

Benefits

  • Comprehensive health, dental and vision coverage
  • generous PTO
  • equity
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service