Senior Director of Information Security
Efficient Computer is rethinking computing from the ground up to solve one of AI's biggest challenges: energy. Our Fabric architecture delivers a 10–100x improvement in energy efficiency for general-purpose computation, including AI, while supporting familiar programming languages and software frameworks—unlocking new possibilities for autonomous machines, intelligent infrastructure, wearables, and space systems. With our first processor, Electron E1, now shipping in volume and more than $97 million in Series B financing recently announced, we're accelerating customer deployments and scaling our architecture to data center performance. Join us to build the hardware and software that bring intelligence wherever it's needed and help shape the next generation of computing.
Efficient Computer is looking for its first dedicated security leader. You’ll decide what good security looks like here, and then build it. That means owning how we protect our intellectual property, how we meet the security standards our defense and government customers require, how we handle export-controlled technology, and how our engineering environment is designed and hardened.
At the start, you’ll be a team of one. Alongside the security program, you’ll own information technology end to end: devices, identity, onboarding and offboarding, and the systems that keep a fast-growing, multi-site company running. As we scale, we’ll hire a dedicated IT Manager, and you’ll help bring them on and hand off day-to-day IT operations so you can focus fully on security. If you want to build both functions from the ground up and then decide how they grow, this is that job.
This is a hands-on role. You’ll write and own policy, but you’ll also be in the consoles, the configurations, and the architecture reviews. If you’re looking for a security role run entirely through documents and meetings, this isn’t it.
You’ll sit on our Operations team, report to our Head of Legal and Compliance, and hold a standing seat in engineering architecture review.
What You’ll Do
Protect what matters most
- Design and enforce how our source code, compiler toolchain, and hardware designs are protected: classification, encryption, storage, and who can reach what.
- Own the access model across our engineering systems: repository permissions, token and credential governance, and recurring access reviews.
- Establish controls for sensitive technical data we hold under third-party confidentiality obligations.
- Build and maintain the evidence that we take reasonable measures to protect our trade secrets
Security engineering and architecture
- Secure a developer-heavy, multi-platform engineering environment where off-the-shelf tooling doesn’t always fit, and make hardening work for engineers rather than against them.
- Secure our software supply chain end to end: dependencies, build pipelines, release integrity, and the compiler itself.
- Own network and infrastructure security architecture, including build-vs-buy and in-house-vs-managed decisions.
- Work with our technology vendors and service providers as a technical peer, not a ticket queue.
- Own detection, logging, and incident response, and write the playbooks you’ll run.
Compliance
- Own and mature our NIST SP 800-171 and CMMC programs: assessments, system security plans, POA&Ms, SPRS, remediation, and audit readiness.
- Lead the security side of customer, partner, and investor diligence, including security questionnaires and government customer reviews.
- Establish policies and controls for handling sensitive and controlled information, and train employees on them.
Export control
- Own the technical implementation of our export control obligations: access segregation, U.S.-person gating for controlled technology, and deemed export analysis for system and repository access.
- Partner with Legal on classification, licensing, and restricted party screening.
AI and data governance
- Set and administer how AI tools are used against our most sensitive material: which tools are approved, how they’re provisioned, and how sensitive data stays where it belongs.
- Own AI tool spend and seat management, so budget goes where it delivers value (not every task needs a frontier model).
- Serve as the company’s data protection and privacy lead.
IT operations (to start)
- Own day-to-day IT across all offices: hardware, software, accounts, and access. No ask is too small, and you’ll build systems so the small asks stay small.
- Run onboarding and offboarding end to end: provisioning, deprovisioning, access reviews, and equipment lifecycle.
- Manage the device fleet and MDM: configuration baselines, patching, disk encryption, and endpoint security.
- Administer identity and access: SSO, MFA, automated user provisioning, and role-based access across our SaaS stack.
- Own office IT infrastructure across multiple sites: networking, Wi-Fi with certificate-based authentication, conference rooms and AV, and physical access systems where applicable.
- Manage IT vendors, licensing, and renewals, and keep spend sensible.
Strategy and scale
- Build the security and IT roadmap for where we need to be as headcount, offices, and customer requirements grow, and drive it, rather than waiting for requirements to arrive.
- Advise leadership on security and IT strategy, budget, and build-vs-buy decisions.
- Help hire our first dedicated IT Manager, hand off day-to-day operations, and lay the groundwork for a security and IT team.
What We’re Looking For
- 7+ years in information security, including time as the founding or sole security owner at a company—or as the person who built a program that didn’t exist before you arrived.
- Genuine hands-on depth. You can configure the control, not just specify it, including on developer workstations and build infrastructure that don’t look like a standard corporate fleet.
- Practical experience securing source code and developer infrastructure: source control platforms, CI/CD, secrets management, and cloud infrastructure.
- Working knowledge of NIST SP 800-171, CMMC, or a comparable federal framework—ideally having taken a company through an assessment—and the judgment to know what matters and what’s ceremony.
- Enough IT operations depth to run it well on your own for a while: MDM, identity providers and SSO, automated user lifecycle management, and multi-site networking.
- Comfort with identity and access architecture: SSO, MFA, least privilege, and access reviews at a pace that doesn’t exhaust people.
- A service mindset paired with strategic judgment. You take pride in fast, friendly support and in knowing which problems to solve permanently.
- Clear written communication. You document what you build, and you can explain a security decision to an engineer who disagrees with it—and change your mind when they’re right.
- Willingness to travel roughly 25% of the time between our offices.
- Due to the nature of our work and applicable export control regulations, this position requires U.S. person status (U.S. citizen or lawful permanent resident).
Nice to Have
- Experience with export-controlled technical data (EAR or ITAR), CUI, or a facility clearance process.
- Semiconductor, hardware, or EDA environments—or any setting where the engineering toolchain drove the security design.
- Experience supporting federal or defense customer security requirements.
- Security certifications (e.g., CISSP, GIAC, CMMC CCP or CCA). Useful signal, not a substitute for hands-on depth.
- Scripting and automation (e.g., Python, Bash, infrastructure as code).
- Experience rolling out or governing AI tools in a company setting.
We offer a competitive base salary for this role, generally ranging from $180,000 to $230,000, plus a 10% annual bonus, meaningful equity, and comprehensive benefits. Final compensation will depend on experience, level, and location, with flexibility for the right candidate.
Why Join Efficient?
Build what's next. At Efficient, you'll tackle big challenges with room to take ownership and make an impact. We back you with competitive pay, equity, a 401(k) match, company-paid benefits, paid parental leave, and flexibility—plus opportunities to grow your skills and career as we scale.
Required Skills
Required Languages
🇬🇧 English