> Markdown version of [/jobs/ext/3568963-it-security-expert](https://www.wearedevelopers.com/jobs/ext/3568963-it-security-expert). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT & Security Expert - **Company:** Great Sky - **Location:** Palo Alto, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $150,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Artificial Intelligence, Amazon Web Services, Apple Mac Systems, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, Linux, Disaster Recovery, Identity and Access Management, Virtual Private Networks (VPN), Python (Programming Language), Key Management, Network Security, Network Segmentation, Zero Trust Network Access, Security Information and Event Management, Data Logging, Google Cloud, Amazon Virtual Private Cloud (VPC), Bare Metal, Cloudflare, Slurm, Hardware Infrastructure, Terraform, SentinelOne Expertise - **Published:** October 3, 2026 - **Apply:** https://www.builtincolorado.com/job/it-security-expert/11491472?handler=ApplyRedirect ## About the Role * 5-8 years of IT and security experience, with direct experience building from scratch at a small technical company - not just running a mature setup * Strong identity and access management experience: SSO, MFA, role-based access, directory services * Secure networking experience: VPN, zero-trust, identity-gated SSH, device management, endpoint security * Cloud security across at least one major provider (AWS, GCP, or Azure): IAM, network segmentation, controlled ingress/egress * Fluent across macOS, Linux, and Windows * Infrastructure-as-code mindset - builds things documented and self-serve * Scripting and automation depth (Python, Bash, Terraform, or similar) * Experience working directly with engineering, operations, and leadership to understand business needs and translate them into reliable, usable, documented systems that make the team's lives easier Nice to Have * Hands-on experience with CMMC, NIST 800-171, or CUI environments * Export control awareness (deemed exports, access segregation for non-US persons) * Experience with EDR/MDR tooling (CrowdStrike Falcon, SentinelOne, or similar) * Experience with on-site rack-mounted server hardware and bare-metal Linux * Centralized logging, SIEM, and incident response experience * Familiarity with Microsoft GCC High or government cloud environments * SOC 2 experience ## Description We're looking for a hands-on IT & Security Expert to own our technology infrastructure from the ground up. You'll be our first dedicated IT hire - which means you'll do the work, shape how we do it, and build the systems and practices that will carry us through our next phase of growth. You'll report to the CTO. You'll work directly with the team rather than in a silo, and the job is to make people's lives easier, not to gatekeep. This is an IC role today with room to grow in scope and seniority as we scale. This is a full-time role based in Palo Alto, CA or Boulder, CO, with travel as well as flexibility for some remote work. What You'll Do IT Operations & Infrastructure * Own and manage our full IT stack (computers, software, network, firewall, and office infrastructure across macOS, Linux, and Windows environments) * Stand up a secure VPN; deploy MDM (device management and policy enforcement) and endpoint security (currently CrowdStrike Falcon) across the full device fleet; build toward zero-trust architecture, asset inventory, centralized logging, and SIEM * Manage hardware procurement, asset tracking, onboarding/offboarding, software license management, IT budget * Manage IT and security vendor relationships - decide what to manage internally vs. outsource, evaluate new tools before they touch our systems, and hold vendors accountable to commitments * Support on-site rack-mounted server hardware and bare-metal Linux as we productize * Own our AI usage and safety policies by defining practical protocols and policies that balance productivity with IP protection Identity, Access & Secrets Management * Stand up an identity platform (Active Directory, Entra ID) with SSO, MFA, and role-based access; connect our internal web infrastructure's login to it * Implement secrets management (Vault, 1Password Teams, SSM) with key rotation and no credentials sitting in repos * Implement a zero-trust mesh or VPN (Tailscale, WireGuard, Cloudflare Access) with identity-gated SSH * Own cloud security across AWS, GCP, and SLURM - IAM, VPC/network segmentation, controlled ingress/egress * Maintain encrypted backups; build toward secure external access to our hardware as we productize Compliance & Security * Lead and own all compliance roadmaps and certification efforts (e.g., CMMC Level 2, SOC 2) - oversee buildouts, ongoing compliance, documentation of policies and procedures, and coordination with external assessors and managed providers * Build toward a real security program: zero-trust architecture, asset inventory, centralized logging and SIEM, monitoring, and identity governance * Own incident response, disaster recovery, and business continuity planning * Maintain awareness of export control rules given our deep tech work and government contracts ## Related Videos - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Running Secure Life Science Research at Scale using Hybrid GPU HPC and Kubernetes 🧬](https://www.wearedevelopers.com/videos/100355-running-secure-life-science-research-at-scale-using-hybrid-gpu-hpc-and-kubernetes) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)