Compound Eye is hiring a hands-on Cybersecurity & IT Engineer to help protect engineering operations end to end, from identity and endpoint security to network access and production email/DNS. This hybrid role is based in Redwood City, CA and is designed for an engineer who wants meaningful ownership on a small team, supported by clear practices built on NIST 800-171 and practical guidance for a CMMC 2.0 Level 2 environment (without requiring compliance ownership or certifications).
In addition to a salary range of USD 150,000 - 185,000 per year, you’ll be eligible for Strong Incentive Stock Options (ISO) along with medical, dental, and vision coverage, employer-paid disability and life insurance, and a 401(k) with employer match after 6 months. The team also offers an annual home office stipend, flexible PTO plus 8 holidays and a 2 week winter break, paid family leave, and quarterly on-sites in San Francisco.
Responsibilities
- Build internal security standards grounded in NIST 800-171, including hardening guides, onboarding/offboarding, access reviews, and incident response runbooks
- Run recurring audits for access, logs, and configuration, and maintain evidence supporting a compliance contractor
- Own identity and access across Entra ID, Intune, Microsoft 365 (including Defender, Purview, and GCC High), plus Google Workspace
- Own email authentication and DNS for a production domain, including SPF, DKIM, DMARC, and MTA-STS, and manage zones/certificates via Cloudflare
- Secure engineer and lab access using Cloudflare Tunnel / Zero Trust Mesh, VPN jump hosts, and SSH certificate authorities
- Manage the device fleet across Windows, macOS, Linux, Android, and iOS, and support physical network controls including firewalls, switches, VLANs, and lab isolation
- Define guardrails for AI tooling such as Claude Code and other agentic workflows
- Keep documentation current, manage vendor relationships within budget, and handle hardware logistics from the Redwood City office (shipping, returns, and spare equipment storage)
Requirements
- 5+ years in IT, systems administration, or security engineering, including experience owning broad-scope responsibilities on a small team
- Hands-on administration experience with both Microsoft 365 and Google Workspace
- Strong Linux administration skills, along with working competence in Windows and macOS
- Hands-on networking experience with firewalls, VPNs, managed switches, VLANs, and routing
- Practical experience with zero-trust or overlay networking such as Cloudflare Tunnel, WireGuard, Tailscale, or similar
- Ownership experience for DNS and email authentication for production domains
- Familiarity with NIST 800-171 and CMMC 2.0 sufficient to avoid creating compliance debt; no certification required
- A track record of writing security practices engineers adopt
- Comfort working independently while partnering with engineering teams without close oversight
Work Environment
- Primarily hybrid from the Redwood City, CA office: typically 1–3 days per week on-site, with more days during build-outs and during quarterly company on-sites
- Less than 10% domestic travel; occasional and infrequent
- Ability to lift and carry equipment up to 40 lbs, with occasional on-site physical work (for example, cabling and racking). Reasonable accommodations are available upon request
Equal Opportunity / ITAR: This position requires access to technology controlled under the International Traffic in Arms Regulations (ITAR). Applicants must be a U.S. person as defined under ITAR (U.S. citizen, lawful permanent resident, asylee, or refugee) or qualify for a license exception.