Director of CAD & IT
Cspeed IO is a stealth start-up backed by Sutter Hill Ventures and Atreides Capital, headquartered in Palo Alto, CA. Our executive team has a demonstrated track record of building and scaling category-defining semiconductor and infrastructure businesses at companies like Broadcom, Lumentum, Tesla, Apple, Samsung, Intel, and VMware. Cspeed IO is developing next-generation optical semiconductor solutions for the AI infrastructure market, focused on enabling true “scale-up” architectures. Our mission is to replace traditional copper interconnects with advanced fiber-optic technologies that overcome the limitations of existing optics solutions and architectures.
About the Role
A build role spanning three intertwined domains: design infrastructure (the CAD, compute, and EDA environment our silicon depends on), corporate IT (identity, endpoints, connectivity, and SaaS for a five-site global company), and the security program that spans both. There is no internal IT department today — the environment is MSP-supported and the architecture is yours to define. You will operate an EDA environment representing $5–10M in annual spend, a three-zone infrastructure model (Corporate, Design/CAD, Lab/OT) governed by export-control classification. CAD and IT carry equal weight, and security is required within both: our technology is export-controlled, our customers are the most security-demanding infrastructure buyers on earth, and there is no CISO above this role. We expect aggression on AI: this role drives aggressive AI use and adoption across the company rather than waiting to be asked.
Responsibilities
- Design infrastructure & CAD: Design compute (batch scheduling, cloud burst), EDA licensing operations — license servers, utilization telemetry, denial-rate and cost-per-seat reporting; the access-controlled PDK enclave, design data management, and storage engineered for EDA workloads.
- Corporate IT: Identity as a system (single IdP, SAML/SCIM, conditional access, hardware-key MFA), the global Windows/macOS/Linux endpoint fleet under unified MDM, WAN across five sites, the SaaS portfolio and its spend, and the MSP managed against an SLA you write.
- Security across both zones: EDR on every host including Linux design machines; the outsourced security stack — SOC/MDR partner and SIEM — where you own the outcome and they own the night shift; phishing-resistant MFA; incident response end to end across time zones; segmentation between zones; customer security reviews answered unaided.
- Export-controlled environments: Operate the design zone under our Technology Control Plan: deemed-export access controls with per-nationality entitlements, logging, quarterly access reviews, and audit-ready evidence.
- AI adoption: Drive aggressive AI use across engineering and corporate workflows — pick the tools, build the guardrails that make AI safe inside an export-controlled environment, and lead by using it yourself. The job is to make yes safe, not to say no.
First-Year Outcomes
- Day 90: Asset and access inventory across five sites; EDR on every Windows and Linux host; hardware-key MFA on privileged accounts; MSP SLA rewritten.
- Day 180: Outsourced SOC/MDR live with SIEM ingesting both zones; identity on a single IdP; PDK enclave access model live; first hire started.
- Day 365: Incident response tabletop run; a hyperscaler security review passed unaided; license telemetry feeding leadership’s renewal decisions.
Requirements
- CAD: 10+ years in semiconductor design infrastructure at a fabless or IDM; ran design compute, EDA licensing operations at $5–10M scale, and PDK/design-data management; supported tape-outs under deadline.
- IT: Ran identity as a system (SAML/SCIM, conditional access, hardware keys); managed a multi-country Windows/macOS/Linux fleet; managed an MSP against an SLA they wrote; completed customer security questionnaires unaided.
- Security: Operated EDR across mixed Windows/Linux fleets; personally owned a real incident end to end; ran security through outsourced SOC/MDR and SIEM vendors and owned the detection outcome anyway; built access-controlled environments for sensitive IP.
- Across all of it: Built from near-zero at least once; an aggressive, hands-on adopter of AI in their own work; effective across Asia time zones with a small team plus vendors; translates technical risk into executive decisions; a U.S. person or eligible for required export authorizations.
What This Role Is Not
Not a caretaker role, not a single-discipline role, not the EDA contract owner, and not paper security — this role runs the controls, it does not just document them.
Preferred Qualifications
- TCP/deemed-export operating experience;
- Defender, Intune, and Entra conditional access in production;
- FreeIPA in Linux design environments;
- ISO 27001, SOC 2, or NIST 800-171 exposure.