Director of IT & Security
This position requires activities that are subject to US Export Control Laws and requires US Citizenship or Green Card Holder.
About the Role
As the Director of IT and Security at Paperless Parts, you'll own the intersection of corporate IT, engineering enablement, and enterprise security. Reporting directly to our CISO, you’ll have real, day-to-day proximity to the teams whose productivity and security posture you are shaping. This is a full-time position based in Boston, MA and requires on-site presence, with a hybrid schedule as needed.
Responsibilities
- Corporate IT and Infrastructure
- Own the architecture, reliability, and roadmap for our corporate IT environment
- Lead procurement, deployment, and lifecycle management of endpoint and SaaS tooling
- Design for developer experience as a first-class outcome, not an afterthought
- Drive efficiency through automation: access provisioning, onboarding/offboarding workflows, and configuration management
- Security and Compliance
- Own enterprise security controls: detection, response, access management, and data protection for our internal environment
- Manage the corporate side of our FedRAMP Moderate compliance program, including the boundary relationship between corporate IT and the product authorization boundary
- Champion compliance and configuration as code, treating policy and security controls as versioned, auditable artifacts rather than manual processes
- Lead audit readiness, vendor security reviews, and security awareness programs
- Partner with the product security team on shared risk surfaces
- Engineering Integration
- Embed meaningfully in Engineering workflows rather than operating as a separate function
- Default to ownership: operate without boundaries, pick up what falls between functions, and treat security outcomes as shared responsibility
- Serve as a credible technical peer to engineering leads on infrastructure decisions, tooling choices, and compliance tradeoffs
- AI Corporate Tooling and Enablement
- Drive adoption of our AI tooling across the company: rollout planning, communication, and ongoing evaluation of effectiveness
- Design and drive an AI literacy program: training, office hours, and internal documentation so teams beyond Engineering can use AI tools effectively and safely
- Measure and report on adoption and impact of AI tooling initiatives to leadership
- Team and Organizational Leadership
- Manage and develop an IT IC, providing mentorship and clear career growth pathways
- Build a function that scales: document playbooks, establish repeatable processes, and hire ahead of need
- Represent IT and Security in cross-functional conversations about infrastructure investment, risk tolerance, and compliance priorities
Requirements
- 8+ years in IT, security, or a combined role, with at least 3 years in a leadership position
- Demonstrated experience scaling IT and/or security at a high-growth company, ideally from startup scale through a significant expansion
- Hands-on familiarity with FedRAMP Moderate, SOC 2, or comparable compliance frameworks
- Fluency with infrastructure and configuration as code practices (e.g., policy-as-code, automated provisioning, GitOps-style change management)
- Experience managing and developing early-career IT and security professionals
- Experience driving adoption of new tooling or technology across a non-technical or mixed technical/non-technical population, including designing training or enablement programs
Mindset
- You default to finding a solution, not delivering a verdict: you dig into the underlying need, do the discovery, and work with the team to find a path that actually works
- You think in systems and anticipate second-order effects: you don't just fix what's broken, you design so it doesn't break
- You're comfortable with ambiguity and can operate with minimal process while also being the person who builds the process
- You communicate clearly with both technical and non-technical stakeholders, including engineers, executives, and auditors
- You treat security as an enabler, not a gate
- You're genuinely curious about how AI tools can make your team and the broader organization more effective, and you're energized by leading that adoption, not just advising on it
Preferred Qualifications
- Experience at a SaaS company serving regulated industries (government, defense, or manufacturing)
- Familiarity with FedRAMP Moderate authorization boundaries and the nuances of corporate vs. product scope
- Background that spans both IT operations and security engineering
- Experience specifically with AI tooling adoption or governance
Why This Role
- Real scope and authority: you'll set the direction for IT and enterprise security at a company that's growing fast and building for the long term
- Direct reporting line to the CISO with visibility to the CTO and broader leadership
- A seat inside Engineering, not alongside it: you'll be solving problems with the team, not handing down policies from the outside
- A team that's ready for this leadership and a company that's investing in it
Pay
Salary range: $190,000 - $258,000. The job posting range is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. We may ultimately pay more or less than the posted range, and the range may be modified in the future. An employee’s pay position within the salary range will be based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, skills, performance, sales or revenue-based metrics, and business or organizational needs.
Benefits
- 100% coverage of health, dental, and vision for you and your dependents
- Competitive compensation philosophy
- Unlimited PTO
- 13+ paid holidays
- Company-sponsored wellness stipend
- Pre-tax Commuter and FSA/Dependent Care FSA
- 401(k) plan
- Employee recognition program
Culture
At Paperless Parts, we value intentionality, persistence, and relationships. We live and breathe these values every day. As a fast-growing company, we’re continually improving what we’ve built while still building from the ground up.
Offices
- Boston Office
Our office is full of energy; people regularly collaborate to solve complex problems. We recognize that people work well in different environments and have intentionally designed our office to provide collaborative spaces and quiet focus areas. Our height-adjustable desks are set up with additional monitors, and employees are provided with the latest Apple technology to support productivity. Our headquarters is located in downtown Boston, MA and easily accessible to most transit routes (Red/Blue/Orange/Green Line/South Station/North Station).
- Encinitas Office
Our California office is our newest office which seats our West Coast sales team. The office has an open floor plan with several conference rooms to encourage collaboration with your colleagues in California and TVs to connect with those sitting in Boston or remotely. The office is walking distance from Downtown Encinitas, the Coaster train stop, and tons of activities on the 101.