> Markdown version of [/jobs/ext/3432390-it-security-lead](https://www.wearedevelopers.com/jobs/ext/3432390-it-security-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT & Security Lead - **Company:** MAYBELL QUANTUM INDUSTRIES, INC. - **Location:** Denver, CO, United States - **Experience:** Expert - **Salary:** $150,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Computer-Aided Design, Microsoft Windows, Microsoft Azure, Backup Devices, Software as a Service, Cyber Security, Computer Engineering, Continuous Integration, SolidWorks (CAD), Domainkeys Identified Mail, Domain-Based Message Authentication Reporting and Conformance (DMARC), Github, Information Technology Operations, Key Management, Network Segmentation, Anti-Phishing, Technical Data Management Systems, Software Vulnerability Management, Windchill, Data Logging, Data Processing, Software Security, Gitlab, Microsoft InTune, Sender Policy Framework (SPF), Patch Management - **Published:** September 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a9d6a015358d3ae7 ## About the Role * 8+ years in IT or security with progressive ownership; you've been the senior or sole technical decision-maker for an environment. * Practical security ownership-you've run patching, access reviews, and at least one real incident end to end. * Deep, current Microsoft 365 and Entra ID security expertise: conditional access, Intune, and Defender in production, not in a lab. * Experience supporting a physical operating environment-manufacturing, labs, or hardware engineering. A background exclusively in software companies is unlikely to prepare you for this. * Willingness to handle IT troubleshooting and end-user support when it's needed, without letting it crowd out the security program. * Comfort being the person who says no to local admin, unmanaged devices, and shadow SaaS-including to senior people. * Exposure to regulated data handling-export controls, ITAR/EAR, CMMC, GDPR, or similar-is a strong plus. * Multi-site or international support experience, ideally including Europe, is a strong plus. * Experience managing an MSP relationship rather than being managed by one is a strong plus. * Network segmentation for OT or lab environments, and CAD/PLM platform experience (SolidWorks PDM, Windchill, or comparable), are strong pluses. * Application and source code security experience - repository access controls, secrets management tooling, and securing CI/CD pipelines (GitHub/GitLab, Azure DevOps, or comparable) - is a strong plus. * Familiarity with physical security and site access controls - badging and access control systems, visitor management, and restricted-area procedures - is a strong plus. * Relevant certifications (CISSP, CISM, SC-200, AZ-500, or comparable) are welcome but not required. * Comfort operating with autonomy and ambiguity in a fast-moving, resource-constrained environment. * Demonstrated desire to own and build-not just execute someone else's playbook. ## Description We're seeking a hands-on IT & Security Lead to become Maybell's first dedicated security hire and the owner of our security program. This is a high-ownership, high-visibility role with real architectural authority: you will decide how our environment is defended, and you will also be the person who implements it. Security at Maybell is not a paper exercise. We are roughly 100 people (and growing) with the security complexity of a much larger company-multiples countries, a manufacturing floor, cryogenic and RF test labs, GDPR obligations, and engineering systems holding export-controlled technical data. That work currently runs through the executive team. It needs an owner. Your primary focus is cybersecurity: identity and access, endpoint and email defense, vulnerability and patch management, logging and monitoring, incident response, and the access controls that protect controlled technical data across all three sites. You will also provide day-to-day IT troubleshooting and end-user support as needed. You'll partner closely with Operations, Engineering, Trade Compliance, and executive leadership to protect the company's most sensitive technical work without slowing down a manufacturing floor or a test lab. Key Responsibilities Security Program Ownership * Own and mature Maybell's security baseline across all three sites: endpoint protection, patch and vulnerability management, logging, backup and recovery, and periodic access reviews. * Set the security architecture and technical standards for how our environment is built, and enforce them in practice. * Prepare and maintain the security posture documentation that customers, insurers, and investors will ask for in diligence. * Run security awareness training and phishing simulation, and build a culture where reporting is normal. * Own physical site access security - badging and access control systems, visitor and escort procedures, and restricted-area controls for labs, server rooms, and the manufacturing floor across all three sites. * Track and report on security metrics - coverage, patch latency, incident volume, and access review completion-and use them to prioritize. Identity and Access Security * Own the security configuration of Microsoft 365 and Entra ID: conditional access, MFA, privileged access, and guest and external sharing governance. * Own Defender and the broader M365 security stack, plus email authentication (SPF, DKIM, DMARC) and mail hygiene. * Use Intune to enforce endpoint security policy across Windows and macOS at three sites. * Own the joiner/mover/leaver process-provisioning, access changes, and offboarding that actually completes. Security Operations and Incident Response * Serve as first responder for phishing, account compromise, and endpoint incidents, with MSP and external IR support as needed. * Build and maintain incident response runbooks, and run tabletop exercises against them. * Own detection and logging coverage, and triage what those signals surface. Controlled Technical Data * Implement and maintain access controls on export-controlled technical data. Our Trade Compliance function determines who is permitted access; you build and enforce the controls that make that real, and you provide the evidence that they worked. * Support access reviews, egress visibility, and offboarding hygiene on controlled data. This is a meaningful part of the role, not a footnote. * Maintain the experience and certification requirements for personnel who handle export-controlled technical data - confirm that training, certification, and authorization prerequisites are satisfied before access is granted, re-verify on role change, and keep the supporting records. * Classification of controlled technical data belongs to Trade Compliance; implementation and enforcement belong to you. That separation is deliberate. Engineering, Manufacturing, and Lab Systems * Secure CAD, PLM, and engineering file infrastructure-in scope for this role, not left to engineering. * Own source code security - repository access and branch protections, secrets management so credentials never live in code, and CI/CD pipeline security including build integrity, dependency risk, and artifact signing. * Design and maintain network segmentation for lab and test instrumentation that cannot be patched or managed conventionally. * Address manufacturing IT risk: shop floor systems, ERP endpoints, and the practical realities of instrument PCs running vendor software with long support tails. * Hold a standing working relationship with Operations and Engineering leadership on manufacturing and lab systems. Those functions are partners with real operational stakes, not just internal customers. IT Operations and Support * Provide day-to-day IT troubleshooting and end-user support as needed. This is a secondary responsibility-real, but not the focus of the role. * Support all global locations, including network, procurement, and local vendor coordination. * Own IT vendor and license management-MSP, SaaS portfolio, hardware procurement, and renewals * Push routine support and administration to automation, self-service, and our MSP wherever it can go, so security work stays the priority. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [GitLab CI pipelines for a whole company](https://www.wearedevelopers.com/videos/143-gitlab-ci-pipelines-for-a-whole-company) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)