SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Code Metal is the leader in automated software engineering using AI with formal verification. The company works with defense and government customers (U.S. Air Force, L3Harris, RTX, Toshiba) to modernize legacy code, optimize performance, and move prototypes to production with provably correct code and auditable proof. Founded in 2023 with offices in Boston and San Francisco, Code Metal is backed by Accel, Salesforce Ventures, B Capital, and others.
You will lead, mature, and scale Code Metal's security program as the company grows. This is a senior leadership role owning security strategy and technical direction across products, offerings, infrastructure, corporate systems, and development environments. You will work closely with engineering, IT, legal, compliance, the FSO, and company leadership to ensure security posture meets the needs of defense, government, and enterprise customers.
Key responsibilities include:
- Own and evolve Code Metal's cybersecurity strategy, priorities, and roadmap
- Lead security across products, infrastructure, corporate systems, and development environments
- Partner with engineering teams to establish practical security architecture, standards, and controls
- Oversee core security operations: identity and access management, vulnerability management, monitoring, and incident response
- Lead product security and ensure security is integrated throughout the software development lifecycle
- Own security aspects of regulatory, compliance, and customer requirements
- Partner with FSO and technical teams on cybersecurity requirements for CUI and classified environments
- Translate regulatory, contractual, and customer security requirements (CMMC, DFARS/NIST 800-171, customer flowdowns) into technical controls
- Represent Code Metal's security posture with leadership, customers, government partners, auditors, and external stakeholders
- Lead and develop the security organization and its capabilities as Code Metal grows
This role requires someone technically strong, comfortable making risk-based decisions, and able to operate effectively with engineers, executives, customers, and government partners.
REQUIREMENTS:
- 10+ years of cybersecurity and compliance experience with meaningful security leadership responsibility
- Broad technical depth across product, cloud, infrastructure, and enterprise security
- Experience owning or significantly maturing security programs within highly technical organizations
- Strong understanding of security architecture, risk management, security operations, privacy, compliance requirements, and incident response
- Experience working closely with engineering organizations and influencing technical decisions
- Strong judgment and ability to communicate security risks and priorities to technical and non-technical audiences
- U.S. citizenship and ability to obtain and maintain a U.S. government security clearance
NICE TO HAVES:
- Experience supporting defense, government, or other highly regulated customers
- Experience with CUI, classified systems, SCIFs, or other high-assurance environments
- Experience moving into new markets and jurisdictions and understanding compliance requirements for new regions
- Familiarity with NIST 800-171, CMMC, SOC 2, ISO 27001, GDPR, or EU AI frameworks
- Experience securing modern cloud-native and AI-enabled products
- Active U.S. government security clearance