Cybersecurity & IT Engineer

Compound Eye

$150K — $185K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in IT, systems administration, or security engineering experience in small teams.
  • Hands-on knowledge of Microsoft 365 and Google Workspace administration.
  • Strong Linux skills alongside proficiency in Windows and macOS.
  • Networking experience with firewalls, VPNs, switches, VLANs, and routing.
  • Practical background in zero-trust networking models (e.g. Cloudflare Tunnel).
  • Experienced in managing DNS and email authentication for domains.
  • Familiarity with NIST 800-171 and CMMC for compliance practices.

Responsibilities

  • Develop internal security standards based on NIST 800-171.
  • Conduct regular audits of access, logs, and configurations.
  • Manage identity and endpoints across multiple platforms.
  • Oversee email authentication and DNS configurations.
  • Secure remote engineer access via various secure channels.
  • Administer the device fleet and physical network systems.
  • Establish guidelines for AI tooling within engineering.
  • Keep documentation updated and maintain vendor budgets.

Benefits

  • Strong Incentive Stock Options (ISO) provided.
  • Comprehensive medical, dental, and vision plans.
  • Annual stipend for home office expenses.
  • Employer-paid long-term and short-term disability insurance.
  • 401(k) matching after 6 months of employment.
  • Flexible paid time off and generous holiday schedule.
  • Paid family leave offered.
  • Regular company on-site events in San Francisco.
Full Job Description
The Role

We're hiring a Cybersecurity & IT Engineer to report directly to the VP of Engineering. You will own the identity, endpoint, network, and security practice that supports our engineering team. You'll inherit a working stack with room to improve it.

This is a hands-on generalist role, not a ticket-queue role and not a compliance-paperwork role. You'll sit in engineering standups, find where access, identity, or network friction is slowing the team down, and have the autonomy to fix it. On a given week, you might harden conditional access policies in Entra, audit third-party OAuth grants in Google Workspace, get a remote engineer a working path to a Jetson AGX sitting on a lab VLAN, fix a DMARC alignment failure, and write the internal standard that keeps all three from breaking again.

A large part of the job is enabling engineers to build securely rather than telling them not to. Our engineers connect distributed equipment over Cloudflare tunnels and mesh VPN overlays, run agentic tooling like Claude Code against real codebases, and stand up their own lab environments. You'll define what safety looks like, make the safe path the easy path, and make it work for a mostly-remote team.

You won't own CMMC compliance and you are not expected to hold a certification yourself. But we're a CMMC 2.0 Level 2 environment, so every configuration decision you make needs to be NIST 800-171 aware. You'll be the person the contractor comes to for evidence and implementation detail. You'll partner with our DevOps Engineer, who owns AWS workloads, GPU compute, and the developer toolchain.

Key Responsibilities
  • Build our internal security standard on top of NIST 800-171: Hardening guides, onboarding/offboarding, access reviews, incident response runbooks
  • Run recurring access, logs, and configuration audits, and maintain evidence for our compliance contractor.
  • Own identity across Entra ID, Intune, Microsoft 365 (Defender, Purview, GCC High), and Google Workspace.
  • Own email authentication and DNS (SPF, DKIM, DMARC, MTA-STS) and manage zones/certificates across Cloudflare.
  • Secure engineer and lab access via Cloudflare Tunnel/Zero Trust Mesh, VPN jump hosts, and SSH certificate authorities.
  • Manage the device fleet (Windows, macOS, Linux, Android, iOS) and the physical network (firewalls, switches, VLANs, lab isolation).
  • Define AI tooling guardrails for Claude Code and other agentic workflows.
  • Keep documentation current and manage vendor relationships within budget.
  • Manage hardware logistics from our Redwood City office, including shipping, returns, and spare equipment storage.


To Thrive in This Role, You Have
  • 5+ years in IT, systems administration, or security engineering, including time owning broad scope on a small team.
  • Hands-on administration of both Microsoft 365 and Google Workspace.
  • Strong Linux administration, plus working competence with Windows and macOS.
  • Hands-on networking experience with firewalls, VPNs, managed switches, VLANs, routing.
  • Practical experience with zero-trust/overlay networking (Cloudflare Tunnel, WireGuard, Tailscale, or similar).
  • Ownership of DNS and email authentication for a production domain.
  • Familiarity with NIST 800-171 and CMMC 2.0 sufficient to avoid creating compliance debt. No certification required.
  • A track record of writing security practices that engineers actually adopt.
  • Comfortable working independently and partnering with engineering teams without close oversight.


Work Environment
  • Primarily hybrid from our Redwood City, CA office: typically 1-3 days per week on-site, with more days during build-outs and quarterly company on-sites.
  • Less than 10% domestic travel, occasional and infrequent.
  • Able to lift and carry equipment up to 40 lbs and do occasional on-site physical work (cabling, racking); reasonable accommodations available upon request.


Compensation & Benefits
  • Base salary: $150k-185k, depending on experience.
  • Strong Incentive Stock Options (ISO)
  • Medical, dental, and vision insurance
  • Annual home office stipend
  • Employer-paid long-term disability, short-term disability, and life insurance
  • 401(k) with employer match after 6 months
  • Flexible PTO and 8 holidays + 2 week winter break
  • Paid family leave
  • Quarterly onsites in San Francisco


Similar Jobs

More Jobs at Compound Eye

More Information Technology Jobs

Find similar Cybersecurity & IT Engineer jobs: