> Markdown version of [/jobs/ext/1409588-lead-security-it-engineer](https://www.wearedevelopers.com/jobs/ext/1409588-lead-security-it-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security & IT Engineer - **Company:** Anodize, LLC - **Location:** San Francisco, CA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Apple Mac Systems, Systems Engineering, Software as a Service, Cloud Computing, Linux, Network Security, Network Segmentation, Zero Trust Network Access, Software Engineering, Infrastructure as Code (IaC), Amazon Virtual Private Cloud (VPC), Information Technology, Devsecops - **Published:** July 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=318ec25a00f5d6b4 ## About the Role * 6+ years of experience spanning Infrastructure Security, DevSecOps, or Systems Engineering, ideally in fast-paced startup or high-growth tech environments. * IaC & Automation First: Strong scripting or software development skills and hands-on experience using Infrastructure as Code (IaC) to build and manage security and IT infrastructure programmatically. * Enterprise Identity & Zero Trust: Experience architecting enterprise Identity Providers, strict least-privilege access controls, and Zero Trust network architectures. * Cloud & Network Security: Proven track record securing public cloud environments, with expertise in network segmentation, VPC isolation, egress control, and robust encryption standards. * Fleet Management & Endpoint Security: Hands-on experience administering multi-OS environments (macOS, Linux, Windows) using modern MDM and EDR solutions to enforce security without sacrificing engineering velocity., * Experience securing cloud-based silicon design (EDA) environments, high-performance computing (HPC) workloads, or high-value third-party IP during chip development cycles. * Familiarity with enterprise device enrollment standards and hardware-level security concepts. ## Description We're a well-funded, stealth startup building a new end-to-end personal computing platform. As our Lead Security & IT Engineer, your responsibility is to build a high-performance, automated, and seamless corporate environment. You will have complete ownership of both our internal security posture and corporate infrastructure, across our custom silicon design environment, internal infrastructure, and employee endpoints. Your goal is to keep us secure by default through automation, code, and zero-trust principles, rather than manual policies and ticket queues. Additionally, you will have the opportunity to act as an internal security consultant for our product team, helping them design our products to be manageable by modern enterprise IT organizations., * Automate Corporate IT: Treat IT like an engineering discipline. Build and scale our identity provider, SaaS toolchain, and lifecycle workflows through zero-touch automation. No manual ticket queues. * Secure Silicon & Vendor IP Infra: Design and enforce network isolation and strict access controls for our cloud-based silicon design environment. Protect highly confidential, encrypted third-party IP during the design and tape-out phases. * Secure the Fleet: Build and secure our internal fleet (Windows/macOS/Linux) using light-touch, high-efficacy tools that keep our company secure without killing battery life. * Consult on Product MDM: Act as a technical advisor to our product team. Help them build native, secure enterprise management and MDM enrollment features into our commercial device, drawing from your hands-on experience as an IT customer. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data)