Location: Austin, TX or Sunnyvale, CA. Full-time onsite position.
Reports To: SVP of Engineering
FLSA Status: Exempt
Position OverviewWe are seeking an experienced Security Lead to design, build, and defend Neurophos's core cloud, network, and system infrastructure against external threats. In this role, you will own the architectural integrity of our security posture, implement zero-trust network boundaries, manage vulnerability and threat detection programs, and serve as the face of Neurophos's security posture. You will balance deep technical execution with strategic governance to ensure our infrastructure withstands scrutiny from sophisticated adversaries and Tier-1 commercial customers.
This is a lead role by design. You are the senior-most security voice in the company from day one and the intended future owner of the security function and its team.
Key ResponsibilitiesInfrastructure & Perimeter Defense
- Deploy zero-trust network access, secure cloud perimeters, and infrastructure access controls across cloud and physical lab/office environments. Experience with Azure is a major plus.
- Safeguard high-value engineering compute environments, CAD/EDA tools, and proprietary chip design repositories against external exfiltration and unauthorized access.
- Implement robust Identity & Access Management policies, fine-grained Role-Based Access Control, Multi-Factor Authentication, and automated access review cycles.
Threat Detection, Vulnerability Management & Incident Response
- Design and execute end-to-end vulnerability management processes, covering continuous asset scanning, prioritization, and coordinated remediation tracking with engineering teams.
- Build, maintain, and test the incident response runbook; serve as the primary incident commander during security events, conducting forensic analysis and root-cause post-mortems.
- Establish SIEM/EDR tooling, intrusion detection, and continuous logging across endpoints, servers, and cloud infrastructure to detect unauthorized access attempts in real time.
Customer & Vendor Security Assurance
- Lead technical defense discussions and security assessments with customers and investors.
- Conduct vendor risk management assessments for third-party SaaS and infrastructure tools entering the company's software stack.
Governance, Risk & Compliance (GRC)
- Own the security compliance library, authoring and enforcing acceptable use, data classification, network segmentation, and disaster recovery policies.
- Support our SOC 2 Type II certification program (utilizing platforms such as Vanta or Drata) in coordination with engineering, General Counsel, and external auditors.
- Collaborate with the General Counsel to establish secure data handling, export control safeguards, and access controls.
Working RelationshipsYou own the infrastructure and information security programs, security posture, relevant policy, threat detection, incident command, and the compliance program. The Lead IT Engineer owns infrastructure itself, engineering compute, and MSP delivery. The two roles are peers reporting to the SVP of Engineering.
Qualifications- 8+ years in security engineering, infrastructure security, or cybersecurity leadership, including experience as the primary security owner at a company under 200 people.
- Hands-on ownership of a SIEM/EDR stack end-to-end.
- Demonstrated ownership of IAM/PAM architecture in a modern IdP (Okta or equivalent).
- Direct experience leading at least one SOC 2 Type II audit cycle, including auditor-facing evidence delivery.
- Direct experience running vendor security assessments and responding to customer/prospect security questionnaires or technical due diligence.
- Working knowledge of export control frameworks (ITAR/EAR) as applied to technical data and access control.
- Working proficiency in at least one major public cloud, ideally Azure.
- Comfortable operating without an existing team, plus interest in hiring and developing a small security function over time.
- Willingness to work across Sunnyvale and Austin as needed.
Preferred Skills- CISSP, CISM, CCSP, or OSCP
- GRC automation platform experience (Vanta, Drata, or similar)
- Experience securing semiconductor EDA/CAD workflows, Linux compute clusters, or physical R&D lab environments.