IT & Security Manager ○ Boulder

Posted yesterday

great skyBoulder (CO)

SENIORITY

Manager

Apply

About the role

About Us: Great Sky is a technology startup based with a mission to rebuild AI from first principles. We are pursuing neuroscience-inspired hardware and algorithms that overcome the greatest challenges in scaling AI systems.
Job Overview: We're looking for a hands‑on IT & Security Expert to own our technology infrastructure from the ground up. You'll be our first dedicated IT hire — which means you'll do the work, shape how we do it, and build the systems and practices that will carry us through our next phase of growth. You'll report to the CTO. You'll work directly with the team rather than in a silo, and the job is to make people's lives easier, not to gatekeep. This is an IC role today with room to grow in scope and seniority as we scale. This is a full‑time role based in Palo Alto, CA or Boulder, CO, with travel as well as flexibility for some remote work.
What You’ll Do: IT Operations & Infrastructure Own and manage our full IT stack (computers, software, network, firewall, and office infrastructure across macOS, Linux, and Windows environments) Stand up a secure VPN; deploy MDM (device management and policy enforcement) and endpoint security (currently CrowdStrike Falcon) across the full device fleet; build toward zero‑trust architecture, asset inventory, centralized logging, and SIEMManage hardware procurement, asset tracking, onboarding/offboarding, software license management, IT budget Manage IT and security vendor relationships — decide what to manage internally vs. outsource, evaluate new tools before they touch our systems, and hold vendors accountable to commitments Support on‑site rack‑mounted server hardware and bare‑metal Linux as we productize Own our AI usage and safety policies by defining practical protocols and policies that balance productivity with IP protection Identity, Access & Secrets Management Stand up an identity platform (Active Directory, Entra ID) with SSO, MFA, and role‑based access; connect our internal web infrastructure's login to itImplement secrets management (Vault, 1Password Teams, SSM) with key rotation and no credentials sitting in repos Implement a zero‑trust mesh or VPN (Tailscale, WireGuard, Cloudflare Access) with identity‑gated SSHOwn cloud security across AWS, GCP, and SLURM — IAM, VPC/network segmentation, controlled ingress/egress Maintain encrypted backups; build toward secure external access to our hardware as we productize Compliance & Security Lead and own all compliance roadmaps and certification efforts (e.g., CMMC Level 2, SOC 2) — oversee buildouts, ongoing compliance, documentation of policies and procedures, and coordination with external assessors and managed providers Build toward a real security program: zero‑trust architecture, asset inventory, centralized logging and SIEM, monitoring, and identity governance Own incident response, disaster recovery, and business continuity planning Maintain awareness of export control rules given our deep tech work and government contracts
Qualifications:
  • 5-8 years of IT and security experience, with direct experience building from scratch at a small technical company — not just running a mature setup
  • Strong identity and access management experience: SSO, MFA, role‑based access, directory services
  • Secure networking experience: VPN, zero‑trust, identity‑gated SSH, device management, endpoint security
  • Cloud security across at least one major provider (AWS, GCP, or Azure): IAM, network segmentation, controlled ingress/egress
  • Fluent across macOS, Linux, and Windows
  • Infrastructure‑as‑code mindset — builds things documented and self‑serve
  • Scripting and automation depth (Python, Bash, Terraform, or similar)
  • Experience working directly with engineering, operations, and leadership to understand business needs and translate them into reliable, usable, documented systems that make the team’s lives easier
Nice to Have:
  • Hands‑on experience with CMMC, NIST 800‑171, or CUI environments
  • Export control awareness (deemed exports, access segregation for non‑US persons)
  • Experience with EDR/MDR tooling (CrowdStrike Falcon, SentinelOne, or similar)
  • Experience with on‑site rack‑mounted server hardware and bare‑metal Linux
  • Centralized logging, SIEM, and incident response experience
  • Familiarity with Microsoft GCC High or government cloud environmentsSOC 2 experience
Benefits and Perks:
  • Meaningful equity ownership in an early‑stage deep tech company
  • Employer‑matched 401(k)
  • Health, dental, vision, and life insurance
  • Flexible PTOSupport for ongoing learning, conference attendance, and skill development
  • Our culture is onsite by default (we're founded by scientists who are used to working in the lab), with flexibility for hybrid arrangements. For the right person and role, we're open to filling roles remotely

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this