Director of Security and IT

Aliro Quantum
Boston, MA, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$160,000.0 - $200,000.0
Working hours
Regular working hours
Job source

Tech stack

CompTIA Security+ Continuous Integration Federal Information Processing Standards (FIPS) Hardware Security Module Information Technology Operations Runbook Secure Coding Software Vulnerability Management

Job description

Aliro builds software for entanglement-based quantum networks. We are hiring our first Director of Security and IT to own two functions that operate as one: the security program and company IT.

You will join with the security program already underway (GRC platform deployed, core policies drafted, strategy and roadmap created) and the IT function still to be built. You own both day to day operations, with strategic direction from our fractional CISO.

What You’ll Own

  • Security and compliance. SOC 2 evidence, policy maintenance, the security risk register, audit and pen-test coordination.
  • IT operations. The company device fleet end to end: procurement, provisioning, MDM, patching, helpdesk, offboarding.
  • Identity and access. Joiner-mover-leaver across core systems, integrated with the company identity provider.
  • Customer security. Security questionnaires (SIG, CAIQ, custom) and customer-facing security artifacts.
  • Secure development support. Coordinate with engineering on CI/CD security tooling, SBOMs, and vulnerability remediation.
  • Vendor and tool management. Own the security and IT toolchain and its integrations.

Requirements

Do you have experience in Security?, * Hands-on experience running both a security/GRC program and IT operations, ideally in one small-company role.

  • Fluency with MDM, zero-touch device provisioning, and an identity provider.
  • SOC 2 audit preparation experience (strongly preferred).
  • Working understanding of secure development practices; you can talk shop with engineers without being one.
  • Strong writing: policies, runbooks, questionnaire responses, audit docs.
  • Comfort building a function from scratch and running it at the same time.

Nice to Have

  • Federal compliance frameworks (FedRAMP, CMMC, NIST 800-171/800-53).
  • Hardware security or cryptographic module validation exposure (FIPS 140-3, Common Criteria).
  • Certifications (CISSP, CISM, CISA, Security+) are useful, not required.
  • Curiosity about quantum networking and post-quantum cryptography.

Benefits & conditions

1284 Soldiers Field Road, Brighton, MA 02135 Hybrid work $160,000 - $200,000 a year - Full-time, Pulled from the full job description

  • Health insurance
  • Dental insurance
  • Flexible schedule

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · World Congress 2021

4:50 min

Addressing quantum enterprise pilots, LLM training, and security

John Fletcher John Fletcher +1 · World Congress 2026 Europe

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · World Congress 2026 Europe

Videos

See all

Related articles

See all