ironquill.tech/board

$ cat jobs/director-of-it-security-paperless-parts-90236048a81d.json

Director of IT & Security

Paperless Parts·Worldwide·Boston, MA·mid
Apply on greenhouse → Get AI match score →
Paperless Parts is a SaaS startup helping manufacturers quote faster and win more work. From rockets to medical devices, we power the parts that move the world forward. This position requires activities that are subject to US Export Control Laws and require US Citizenship or Green Card Holder. Summary As the Director of IT and Security at Paperless Parts you'll own the intersection of corporate IT, engineering enablement, and enterprise security. Reporting directly to our CISO, you’ll have real, day-to-day proximity to the teams whose productivity and security posture you are shaping. This is a full-time position based in Boston, MA and requires on-site presence, with a hybrid schedule as needed. ## What You'll Own **Corporate IT and Infrastructure** - Own the architecture, reliability, and roadmap for our corporate IT environment - Lead procurement, deployment, and lifecycle management of endpoint and SaaS tooling - Design for developer experience as a first-class outcome, not an afterthought - Drive efficiency through automation: access provisioning, onboarding/offboarding workflows, and configuration management **Security and Compliance** - Own enterprise security controls: detection, response, access management, and data protection for our internal environment - Manage the corporate side of our FedRAMP Moderate compliance program, including the boundary relationship between corporate IT and the product authorization boundary - Champion compliance and configuration as code, treating policy and security controls as versioned, auditable artifacts rather than manual processes - Lead audit readiness, vendor security reviews, and security awareness programs - Partner with the product security team on shared risk surfaces **Engineering Integration** - Embed meaningfully in Engineering workflows rather than operating as a separate function - Default to ownership: operate without boundaries, pick up what falls between functions, and treat security outcomes as shared resp