Logo
job logo

Director of IT & Security

DEFCON AI, Mc Lean, VA, United States


About Defcon AI RESILIENCE IN THE FACE OF DISRUPTION. DEFCON AI is an insights company that leverages artificial intelligence, mathematical optimization, data analytics, and software engineering for resilient optimization of complex systems.

In today's dynamically changing world, DEFCON AI's technology aligns outcomes with operational goals, better decision making, and empowers customers to anticipate assess, and mitigate the impacts of disruptions.

About the Role We are seeking a

Director of IT & Security

to lead all information technology and security functions for our growing, mission driven organization supporting U.S. government, defense, and commercial clients.

This role is both

strategic and hands‑on . You will own our

security posture, compliance programs, and audit readiness

(CMMC 2.0 and SOC 2), while also ensuring that day‑to‑day IT operations run smoothly. You will serve as the owner accountable for audits, security controls, and IT risk, while partnering closely with Operations, Engineering, HR, and Finance.

This role reports directly to the Head of Ops and will help shape how our IT and security capabilities scale as the company grows.

Key Responsibilities Security, Compliance & Risk (Primary Focus)

Own CMMC 2.0 and SOC 2 end‑to‑end, including:

Control design and implementation

Evidence collection and readiness

Audit coordination and remediation

Serve as the primary point of contact for auditors, assessors, and external security partners

Maintain and evolve security policies, standards, and procedures aligned with DoD and federal requirements

Oversee access control, device security, identity management, and incident response processes

Partner with leadership to assess and manage IT and security risk across the organization

IT Leadership & Operations

Lead all IT functions supporting corporate and program needs

Own IT architecture, tooling decisions, and vendor selection

Manage relationships with MSPs, security vendors, and cloud providers

Ensure secure, reliable operation of systems supporting a distributed workforce

Plan and execute IT improvements that scale with company growth

Hands On Support & Team Enablement

Provide guidance and escalation support for IT hardware/software issues as needed

Support a culture of responsive, pragmatic IT service (without being a full‑time helpdesk)

Help mentor and support an IT Support Specialist & Cloud Infrastructure Engineer

Balance operational execution with long‑term security and compliance priorities

Required Qualifications

8+ years of progressive IT experience, including leadership responsibility

Direct ownership of at least one of the following:

CMMC 2.0 readiness or implementation

SOC 2 audits (Type I or Type II)

Experience operating in government contracting / defense / regulated environments

Strong working knowledge of:

NIST 800‑171 / NIST 800‑53

Identity and access management

Endpoint security and device management

Cloud‑based IT environments (AWS, Azure, or similar)

Ability to communicate clearly with executives, auditors, and non‑technical stakeholders

Comfortable operating in a small company where priorities shift and hands‑on work is sometimes required

Preferred Qualifications

Prior experience supporting DoD programs or federal contracts

Active or previously held security clearance (or eligibility to obtain)

Experience scaling IT/security functions from ~30–50 employees upward

Familiarity with government approved tooling and compliance platforms

Experience managing or working alongside MSPs in regulated environments

What Success Looks Like

The company is audit‑ready at all times, not scrambling

CMMC 2.0 and SOC 2 requirements are clearly owned, documented, and operationalized

Employees experience reliable, secure IT support without friction

Leadership has confidence in IT risk posture and compliance maturity

The IT function scales cleanly as the company grows

Why This Role Is Unique

You will have real ownership and authority, not just responsibility without control

You'll partner directly with the Head of Operations and leadership team

You'll shape the IT and security foundation for a mission‑focused, government‑aligned organization

This role blends security leadership, operational execution, and strategic influence

What We Offer

A fully remote, results‑based environment

Competitive salary, bonus, and equity package

100% employer paid, comprehensive health insurance including medical, dental, and vision for you and your family

Unlimited PTO, with your manager's approval

Flexible work environment where you manage your work day

14 weeks of fully‑paid parental leave

Salary Range:

$190,000‑$230,000. This represents the typical salary range for this position based on experience, skills, and other factors.

We’re an Equal Opportunity Employer: You'll receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.

Applicant Data Disclosure By submitting an application, you acknowledge that Defcon AI uses third‑party service providers to facilitate its recruitment and hiring processes. These providers include applicant tracking systems, candidate verification platforms, and fraud detection tools (collectively, “Hiring Platforms”). Your application materials, including your résumé, cover letter, work samples, responses to application questions, and any other information you submit, may be transmitted to and processed by these Hiring Platforms for the following purposes:

Managing and administering your application throughout the hiring process;

Verifying the accuracy and authenticity of application materials, including by cross‑referencing information you provide against publicly available sources and proprietary databases;

Identifying indicators of potentially fraudulent, fabricated, or materially misleading application content, including but not limited to discrepancies between submitted materials and publicly available professional profiles, geographic anomalies, and fabricated work histories.

Applications that are flagged through this process as containing indicators of fraud or material misrepresentation may be declined from further consideration. If you have questions about the status of your application or the evaluation process, please contact recruiting@defconai.com.

Defcon AI requires its Hiring Platform providers to process your information solely for the purposes described above and in accordance with applicable law. Your information will be retained only for as long as necessary to fulfill these purposes and any applicable legal obligations, after which it will be deleted in accordance with Defcon AI’s data retention policies.

For more information about how your data is used, please refer to our Privacy Policy and Applicant Privacy Notice.

#J-18808-Ljbffr