Head of Security

Foundry Robotics
San Francisco, CA

Who this role is best for

Aimed at mid-level security professionals with hands-on experience in national security compliance and startup environments, who can architect and implement security frameworks across edge, on-prem, and cloud infrastructures in San Francisco.

Best fit for

  • Candidates with experience in CMMC Level 2 certification and export control compliance for national security-critical hardware
    — “Drive CMMC Level 2 certification to completion — scoping, SSP/POA&M ownership, evidence collection
  • Individuals who have built or scaled security functions in fast-growing companies, especially with identity and network security expertise
    — “Experience building or scaling a security function at a startup or fast-growing company
  • Professionals who can operate with high autonomy and align security with manufacturing and robotics domains
    — “Comfort operating with high autonomy and ambiguity in a ~30-person startup

Things to consider

  • U.S. person status is a mandatory requirement due to ITAR-controlled work
    — “U.S. person status (required for ITAR-controlled work)
  • The role demands full-time in-person presence in San Francisco, with no remote flexibility implied
    — “This role is 100% in-person at our office in the mission, SF

How to stand out

  • Highlight end-to-end experience with CMMC Level 2 and NIST SP 800-171 compliance in your resume and interview responses
    — “Proven track record taking an organization through CMMC Level 2 or NIST SP 800-171 assessment, ideally end to end
  • Emphasize your ability to architect and implement identity, endpoint, and network security solutions
    — “Strong security engineering foundation: identity, endpoint, network, and cloud (AWS) security, you can architect and, early on, implement
  • Showcase your background in building security programs from the ground up, especially in startup environments
    — “Build the security roadmap and budget; make build-vs-buy calls decisively
  • Demonstrate familiarity with national security facility requirements and export control frameworks
    — “Understanding of national security facility requirements
  • Position yourself as a leader who can integrate security into engineering and operations workflows seamlessly
    — “Partner with engineering, IT, and leadership to make security a default, not a blocker
Pace · Fast PacedCollaboration · HighAutonomy · HighDecision Impact · CompanyLevel · Lead

Derived from job-description analysis by Serendipath's career intelligence engine.

What success looks like

  • successful security audits
  • incident-free operations
  • compliance with regulations
Typical background
experience in security engineeringbackground in national security

Skills & requirements

Required

Security ComplianceIncident ResponseVendor Risk ManagementIdentity And Access ManagementCloud Security

Preferred

SOC 2 ComplianceAs9100 Certification

Stack & domain

Security ComplianceCmmcNist Sp 800-171Dfars 252.204-7012LeadershipProblem-solvingTeamworkCommunicationSecurityComplianceManufacturing

About the role

Original posting from Foundry Robotics via Ashby

ABOUT US

Foundry Robotics is building an AI-native robotics manufacturing company focused on deploying advanced assembly and production capability for leading robotics companies and national-security-critical hardware. Basically, we're building robots that build robots.

We are reimagining manufacturing through advanced robotics. Our mission is to rebuild the American manufacturing industry as an AI-first, assembly-focused, dual-use contract manufacturer. We aim to empower manufacturers with intelligent, efficient, and adaptable robotic systems that redefine productivity and quality. As a founding member of our engineering team, you will have a direct and significant impact on our product, culture, and ultimate success. This role is 100% in-person at our office in the mission, SF.

THE ROLE

We're hiring our first Head of Security to own the full security and compliance program end to end, from achieving CMMC Level 2 certification ahead of our November 2026 deadline, to building and leading the security function as we grow. You'll be the accountable owner for how Foundry protects Controlled Unclassified Information (CUI), export-controlled technical data, and customer IP across our edge, on-prem, and cloud infrastructure. This is a builder role. You'll set strategy, do hands-on work in the early days, and hire a team behind you.

KEY RESPONSIBILITIES

Government & regulatory compliance

  • Drive CMMC Level 2 certification to completion — scoping, SSP/POA&M ownership, evidence collection, and managing the C3PAO assessment (we're already evaluating firms like Schellman, A-LIGN, and CBIZ Pivot Point).
  • Own our NIST SP 800-171 / DFARS 252.204-7012 posture and continuous compliance.
  • Stand up and administer our ITAR/EAR export-control program — technical data segregation, access controls for

U.S. persons, deemed-export policies.

  • Maintain AS9100 and SOC 2 alignment in coordination with quality and operations.

Security engineering & operations

  • Own identity, endpoint, and network security across our stack (JumpCloud MDM, CrowdStrike EDR, Google/1Password, Cloudflare, AWS, Tailscale).
  • Define and enforce CUI boundary architecture across edge (Jetson/Orin), on-prem (GPU cluster), and cloud (AWS).
  • Own our Incident Response Plan and serve in the IRT; run tabletop exercises and lead real incidents.
  • Vendor/third-party risk management, including ITAR/CMMC-aware external partner collaborations.

Team & program building

  • Build the security roadmap and budget; make build-vs-buy calls decisively.
  • Hire, mentor, and lead a security team (GRC, security engineering).
  • Partner with engineering, IT, and leadership to make security a default, not a blocker.

WHAT WE'RE LOOKING FOR

  • Understanding of national security facility requirements.
  • Previous/current Experience as a Facility Security Officer.
  • Proven track record taking an organization through CMMC Level 2 or NIST SP 800-171 assessment ,ideally end to end, at least once.
  • Deep, hands-on knowledge of DFARS, CUI handling, and ITAR/EAR export controls.
  • Strong security engineering foundation: identity, endpoint, network, and cloud (AWS) security, you can architect and, early on, implement.
  • Experience building or scaling a security function at a startup or fast-growing company.
  • U.S. person status (required for ITAR-controlled work).
  • Comfort operating with high autonomy and ambiguity in a ~30-person startup.

NICE TO HAVE

  • SOC 2 and AS9100 experience.
  • Manufacturing, defense, aerospace, or hardware-adjacent background.
  • Familiarity with securing edge/robotics or ML/GPU infrastructure.
  • Relevant certifications (CISSP, CISM, CCP/CCA, etc.).

WHY JOIN US?

This is one of the only places where world-class manufacturing operators, mechanical engineers, robotics researchers, and software engineers sit in the same room, building production systems together.

We are committed to being deeply embedded in the U.S. industrial base. Our focus is simple: build adaptive robotic assembly systems that make American manufacturing scalable, resilient, and competitive again.

The base salary range for this full-time position in the location of San Francisco is:

$150,000 to $250,000 USD

Compensation packages at Foundry Robotics for eligible roles include base salary, equity, and benefits. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position, determined by work location and additional factors, including job-related skills, experience, interview performance, and relevant education or training. Foundry Robotics employees in eligible roles are also granted equity based compensation, subject to Board of Director approval. You'll also receive benefits including, but not limited to: Comprehensive health, dental and vision coverage, and generous PTO.

Source: Foundry Robotics careers (Ashby)

Similar roles