1st10 · 5 hours ago
Infrastructure Architect
1st10 is a specialized search firm that builds engineering teams for the top startups on the planet, and they are seeking an Infrastructure Architect for a startup in the aerospace sector. The role involves owning the IT architecture and technology stack, leading a small IT function, and ensuring the team operates efficiently and securely as they scale.
Computer Software
Responsibilities
Own the IT roadmap: Build and deliver a 12–18‑month plan across identity/SSO, endpoint management, networks, collaboration, backups/DR, logging/observability, access governance, and internal/off‑the‑shelf tooling
Engineering enablement: Engage with teams, decompose needs, and architect pragmatic, secure solutions that reduce friction and improve developer/design velocity
End‑user productivity: Define endpoint strategy (e.g., COPE), zero‑touch provisioning, and a modern productivity stack that balances speed with security/compliance
Cloud & data architecture: Evaluate and implement the right cloud path for regulated workloads (e.g., AWS GovCloud (US), Azure Government, or GCP Assured Workloads). Define IAM, key management, logging, and data lifecycle
Compliance readiness: Map and operationalize controls for NIST SP 800‑171 Rev. 3 and CMMC 2.0 (policies, technical controls, vendor risk, and audit evidence). Incorporate network segmentation, zero‑trust access, and secure remote work
Continuity & risk: Establish RTO/RPO, implement and test backups and disaster recovery, and maintain incident response runbooks with regular tabletop exercises
Vendors & budget: Own IT vendor selection, SLAs, renewals, and spend; rationalize tooling and forecast costs
Leadership: Coach the Help Desk Specialist; set SLAs, build a documentation/automation culture, and publish simple metrics (availability, device compliance, onboarding time, ticket SLAs)
Qualification
Required
8–12+ years in IT infrastructure/architecture with deep hands‑on in identity, endpoints, networks, and SaaS; proven scaling in startup and/or hardware‑lab environments
Experience planning and operating secure cloud for regulated workloads (e.g., GovCloud/Azure Gov/GCP Assured Workloads or equivalent controls)
Comfort turning NIST 800‑171 requirements into practical controls; familiarity with CMMC 2.0; bonus for SOC 2 or NIST CSF experience
Representative toolkit: Okta or Entra ID; Jamf/Intune/FleetDM; CrowdStrike/SentinelOne; M365; Jira/Freshservice; modern VPN
Export controls: Some parts of the job may require access to export‑controlled technical data; eligibility as a U.S. person may be required depending on scope
Preferred
Bonus points: Prior ITAR/EAR environment
SF or Denver preferred; remote (US) considered with periodic travel
Benefits
Comprehensive medical, dental, and vision insurance, including Flexible Spending Accounts (FSA)
401(k) program and transparent stock option plan
Self-managed and flexible time-off policy, including PTO, paid holidays, and sick time
Flexible work environment
Company-funded perks, including weekly team lunches and lots of great swag