IT & Security Lead
Listed on 2026-09-23
-
IT/Tech
Cybersecurity, IT Specialist, Security Management & Operations
At Maybell Quantum, we’re redefining the future of computing. As a venture-backed quantum hardware innovator experiencing rapid growth, we build the cryogenic infrastructure that quantum computers run on — dilution refrigerators, cryogenic RF wiring, and the related systems used by quantum computing companies, national labs, and research institutions worldwide. Quantum computers will be as transformative to the next 30 years as the internet was to the last 30—and our team is creating the hardware foundation to make this revolution possible.
Position OverviewWe’re seeking a hands-on IT & Security Lead to become Maybell’s first dedicated security hire and the owner of our security program. This is a high-ownership, high-visibility role with real architectural authority: you will decide how our environment is defended, and you will also be the person who implements it.
Security at Maybell is not a paper exercise. We are roughly 100 people (and growing) with the security complexity of a much larger company—multiples countries, a manufacturing floor, cryogenic and RF test labs, GDPR obligations, and engineering systems holding export-controlled technical data. That work currently runs through the executive team. It needs an owner.
Your primary focus is cybersecurity: identity and access, endpoint and email defense, vulnerability and patch management, logging and monitoring, incident response, and the access controls that protect controlled technical data across all three sites. You will also provide day-to-day IT troubleshooting and end-user support as needed.
You’ll partner closely with Operations, Engineering, Trade Compliance, and executive leadership to protect the company’s most sensitive technical work without slowing down a manufacturing floor or a test lab.
Key Responsibilities Security Program OwnershipOwn and mature Maybell’s security baseline across all three sites: endpoint protection, patch and vulnerability management, logging, backup and recovery, and periodic access reviews.
Set the security architecture and technical standards for how our environment is built, and enforce them in practice.
Prepare and maintain the security posture documentation that customers, insurers, and investors will ask for in diligence.
Run security awareness training and phishing simulation, and build a culture where reporting is normal.
Own physical site access security — badging and access control systems, visitor and escort procedures, and restricted-area controls for labs, server rooms, and the manufacturing floor across all three sites.
Track and report on security metrics — coverage, patch latency, incident volume, and access review completion—and use them to prioritize.
Own the security configuration of Microsoft 365 and Entra l access, MFA, privileged access, and guest and external sharing governance.
Own Defender and the broader M365 security stack, plus email authentication (SPF, DKIM, DMARC) and mail hygiene.
Use Intune to enforce endpoint security policy across Windows and macOS at three sites.
Own the joiner/mover/leaver process—provisioning, access changes, and offboarding that actually completes.
Serve as first responder for phishing, account compromise, and endpoint incidents, with MSP and external IR support as needed.
Build and maintain incident response runbooks, and run tabletop exercises against them.
Own detection and logging coverage, and triage what those signals surface.
Implement and maintain access controls on export-controlled technical data. Our Trade Compliance function determines who is permitted access; you build and enforce the controls that make that real, and you provide the evidence…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).