> Markdown version of [/jobs/ext/519566-director-of-security-and-it](https://www.wearedevelopers.com/jobs/ext/519566-director-of-security-and-it). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director of Security and IT - **Company:** Aliro Quantum - **Location:** Boston, MA, United States - **Experience:** Expert - **Salary:** $160,000.0 - $200,000.0 - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Continuous Integration, Federal Information Processing Standards (FIPS), Hardware Security Module, Information Technology Operations, Runbook, Secure Coding, Software Vulnerability Management - **Published:** June 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a0dfc1bd8de3a0a0 ## About the Role Do you have experience in Security?, * Hands-on experience running both a security/GRC program and IT operations, ideally in one small-company role. * Fluency with MDM, zero-touch device provisioning, and an identity provider. * SOC 2 audit preparation experience (strongly preferred). * Working understanding of secure development practices; you can talk shop with engineers without being one. * Strong writing: policies, runbooks, questionnaire responses, audit docs. * Comfort building a function from scratch and running it at the same time. Nice to Have * Federal compliance frameworks (FedRAMP, CMMC, NIST 800-171/800-53). * Hardware security or cryptographic module validation exposure (FIPS 140-3, Common Criteria). * Certifications (CISSP, CISM, CISA, Security+) are useful, not required. * Curiosity about quantum networking and post-quantum cryptography. ## Description Aliro builds software for entanglement-based quantum networks. We are hiring our first Director of Security and IT to own two functions that operate as one: the security program and company IT. You will join with the security program already underway (GRC platform deployed, core policies drafted, strategy and roadmap created) and the IT function still to be built. You own both day to day operations, with strategic direction from our fractional CISO. What You'll Own * Security and compliance. SOC 2 evidence, policy maintenance, the security risk register, audit and pen-test coordination. * IT operations. The company device fleet end to end: procurement, provisioning, MDM, patching, helpdesk, offboarding. * Identity and access. Joiner-mover-leaver across core systems, integrated with the company identity provider. * Customer security. Security questionnaires (SIG, CAIQ, custom) and customer-facing security artifacts. * Secure development support. Coordinate with engineering on CI/CD security tooling, SBOMs, and vulnerability remediation. * Vendor and tool management. Own the security and IT toolchain and its integrations. ## Related Videos - [Quantum DevOps - Quantum Application Development](https://www.wearedevelopers.com/videos/1441-quantum-devops-quantum-application-development) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) - [Bridging AI and Nomad: a Go-based MCP Server for Cluster Control](https://www.wearedevelopers.com/videos/2063-bridging-ai-and-nomad-a-go-based-mcp-server-for-cluster-control) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms](https://www.wearedevelopers.com/magazine/635-dev-digest-188-cfp-time-the-risks-of-npm-and-ikea-algorithms)