> Markdown version of [/jobs/ext/1189010-it-security-compliance-manager](https://www.wearedevelopers.com/jobs/ext/1189010-it-security-compliance-manager). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security & Compliance Manager - **Company:** Fab 2 Inc - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Salary:** $140,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Software as a Service, Cyber Security, Information Leak Prevention, Identity and Access Management, Information Security Management, Information Technology Operations, Information Technology - **Published:** July 5, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=48c340b5a3fbfb06 ## About the Role * 5-7+ years of experience in IT operations, security operations, systems governance, GRC, or internal security and IT roles. * Demonstrated experience building operational processes, documentation, and playbooks from scratch in a fast-paced or rapidly growing organization. * Familiarity with export control and government-related compliance environments, particularly EAR, ITAR, NIST 800-171, CMMC, SOC 2, and/or FedRAMP. * Strong practical understanding of identity and access management, permissions auditing, SaaS governance, and endpoint/device management. * Familiarity with IAM, MDM, endpoint management, or SaaS administration platforms. * Proven ability to operate independently, break complex security problems into actionable work, and build structure in highly ambiguous environments. Nice-to-have * Experience acting as an early or foundational security/IT hire at a startup or operationally rigorous environment. * Experience supporting regulated, government-adjacent, or defense technology environments. ## Description As a Security & IT Operations lead, you will help build the security, IT, and governance foundations that support our fast-moving engineering organization as we scale across new offices, growing teams, and increasingly complex systems. Sitting at the intersection of security operations, systems governance, and IT operations, you will take broad ownership of how Atomic Semi manages access, devices, operational risk, and sensitive information. We're looking for someone who can operate as both a strategic security lead and a hands-on builder, shaping the systems, policies, and operational rigor that will support fab2 through its next stage of growth. You will know you are successful when you have built a scalable, highly secure foundation from scratch that protects our sensitive data without slowing down our engineering teams. Responsibilities * Own end-to-end change management for security and IT systems, including impact assessment, cross-site coordination, rollout execution, and stakeholder communication. * Develop and maintain foundational operational security policies, acceptable use standards, and data loss prevention strategies from the ground up. * Design and implement scalable processes around permissions management, identity access, and SaaS governance across our growing footprint of multiple locations. * Lead compliance readiness and audit preparation efforts related to critical frameworks (e.g., EAR, ITAR, NIST 800-171, CMMC, SOC 2, etc). * Take ownership of the full employee device and access lifecycle, delivering reliable, high-quality IT support and troubleshooting that keeps our teams productive and our infrastructure running smoothly. * Evaluate new software, services, and operational workflows to identify and proactively remediate security and compliance gaps before they become issues. ## Related Videos - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Beyond the Hype: Building Trustworthy and Reliable LLM Applications with Guardrails](https://www.wearedevelopers.com/videos/1594-beyond-the-hype-building-trustworthy-and-reliable-llm-applications-with-guardrails) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)