Director Information Technology Security positions focus on delivering results in their domain. This page aggregates open Director Information Technology Security roles and what employers typically expect.
Paperless Parts is a SaaS startup helping manufacturers quote faster and win more work. From rockets to medical devices, we power the parts that move the world forward. *This position requires activities that are subject to US Export Control Laws and require US Citizenship or Green Card Holder.* **Summary** As the Director of IT and Security at Paperless Parts you'll own the intersection of corporate IT, engineering enablement, and enterprise security. Reporting directly to our CISO, you’ll have real, day-to-day proximity to the teams whose productivity and security posture you are shaping. This is a full-time position based in Boston, MA and requires on-site presence, with a hybrid schedule as needed. **## What You'll Own** \*\*Corporate IT and Infrastructure\*\* - Own the architecture, reliability, and roadmap for our corporate IT environment - Lead procurement, deployment, and lifecycle management of endpoint and SaaS tooling - Design for developer experience as a first-class outcome, not an afterthought - Drive efficiency through automation: access provisioning, onboarding/offboarding workflows, and configuration management \*\*Security and Compliance\*\* - Own enterprise security controls: detection, response, access management, and data protection for our internal environment - Manage the corporate side of our FedRAMP Moderate compliance program, including the boundary relationship between corporate IT and the product authorization boundary - Champion compliance and configuration as code, treating policy and security controls as versioned, auditable artifacts rather than manual processes - Lead audit readiness, vendor security reviews, and security awareness programs - Partner with the product security team on shared risk surfaces \*\*Engineering Integration\*\* - Embed meaningfully in Engineering workflows rather than operating as a separate function - Default to ownership: operate without boundaries, pick up what falls between functions, and treat security outcomes as shared responsibility - Serve as a credible technical peer to engineering leads on infrastructure decisions, tooling choices, and compliance tradeoffs \*\*AI Corporate Tooling and Enablement\*\* - Drive adoption of our AI tooling across the company: rollout planning, communication, and ongoing evaluation of effectiveness - Design and drive an AI literacy program: training, office hours, and internal documentation so teams beyond Engineering can use AI tools effectively and safely - Measure and report on adoption and impact of AI tooling initiatives to leadership \*\*Team and Organizational Leadership\*\* - Manage and develop an IT IC, providing mentorship and clear career growth pathways - Build a function that scales: document playbooks, establish repeatable processes, and hire ahead of need - Represent IT and Security in cross-functional conversations about infrastructure investment, risk tolerance, and compliance priorities **## What We're Looking For** \*\*Experience\*\* - 8+ years in IT, security, or a combined role, with at least 3 years in a leadership position - Demonstrated experience scaling IT and/or security at a high-growth company, ideally from startup scale through a significant expansion - Hands-on familiarity with FedRAMP Moderate, SOC 2, or comparable compliance frameworks - Fluency with infrastructure and configuration as code practices (e.g., policy-as-code, automated provisioning, GitOps-style change management) - Experience managing and developing early-career IT and security professionals - Experience driving adoption of new tooling or technology across a non-technical or mixed technical/non-technical population, including designing training or enablement programs This is a pivotal hire. We're expanding our IT leadership role to encompass enterprise security, and we're looking for a leader with the technical depth and strategic instincts to grow with that scope. -- **## The Role and Mindset** As Director of IT & Security, you'll ow…