Director of Infrastructure

AllSpice

  • Boston, Massachusetts
  • 7 days ago

    Highlights

    At AllSpice, we're building the agile development environment for hardware designers, including a Git-friendly translation layer and automated CI/CD framework for native circuit designs, think GitHub/GitLab + Copilot for electronics. Lead enterprise deployments end-to-end across our three hosting models — AllSpice Cloud, single-tenant instances, and self-hosted — including architecture reviews, SSO/OIDC integrations, and security sign-off.

    Numbers & Facts

    LocationBoston, Massachusetts

    Description

    Help define the future of hardware development by building a collaboration platform for circuit designs, enabling the next generation of smart vehicles, IoT devices, rockets, medical devices, robotics, and much more.

    At AllSpice, we're building the agile development environment for hardware designers, including a Git-friendly translation layer and automated CI/CD framework for native circuit designs, think GitHub/GitLab + Copilot for electronics.

    Read more about our latest Series A announcement here!

    As Director of Infrastructure, you will own AllSpice's infrastructure, security, and compliance programs end-to-end while building and leading a small, high-impact team. This is a hands-on leadership role: roughly 60% management and strategic work, 40% individual contribution, reporting to the CTO. With the team at 1–2 people for the next 12 months, there are no layers between you and production — you'll write the Terraform, lead the incident call, and walk an enterprise customer's CISO through our security posture, sometimes all in the same week.

    If you want executive-level ownership at a fast-growing startup — and you still love shipping infrastructure yourself — this role is for you.

    What you'll do

    This is a high-impact role that comes with significant autonomy and requires a self-driven, strategic, and collaborative builder. You will own our infrastructure, security, and compliance programs end-to-end.

    Hands-on infrastructure and scaling

    • Architect, build, and operate our production AWS environments using Terraform and infrastructure-as-code — you'll ship your own changes

    • Make the architectural calls on cloud strategy, high availability, scaling, and cost optimization as our workloads and customer base grow

    • Automate deployments, backups, and disaster recovery across AllSpice Cloud, single-tenant, and self-hosted configurations

    • Monitor and improve the performance, availability, and cost efficiency of production systems across all hosting models

    • Work closely with application developers to deploy infrastructure solutions to product problems

    Customer-facing engineering

    • Lead enterprise deployments end-to-end across our three hosting models — AllSpice Cloud, single-tenant instances, and self-hosted — including architecture reviews, SSO/OIDC integrations, and security sign-off

    • Own the process for spinning up application instances for customer evaluations — streamline it now, automate it over time

    • Serve as the primary technical point of contact for customer InfoSec questionnaires, IT security reviews, and procurement processes

    • Support self-hosted and GovCloud deployments for customers with ITAR, EAR, or CUI requirements

    • Partner with customer success and sales to turn infrastructure into a reason enterprises buy

    Security and compliance ownership

    • Own AllSpice's security posture: policies, incident response, disaster recovery, and ongoing risk assessment

    • Maintain SOC 2 compliance, penetration testing, and audit processes; evaluate additional certifications as we grow

    • Work with legal counsel on security and data-protection matters, including DPAs, breach notification obligations, and regulatory requirements

    People management and team building

    • Hire, mentor, and manage infrastructure engineers as the team grows

    • Set team goals, define processes, and establish on-call rotations — and take your own turn in the rotation, leading incident response when needed

    • Create growth paths for ICs and foster a culture of operational excellence

    Example projects

    • Automate provisioning of evaluation instances so a prospective customer can be testing AllSpice in hours, not days

    • Scale infrastructure for zero-downtime deployments across multi-region AWS accounts

    • Plan and evaluate horizontal scaling strategies for compute runtime to support growing workloads and concurrent users

    • Lead an enterprise customer through a self-hosted deployment, including architecture review, SSO integration, and security sign-off

    • Identify opportunities to reduce cloud spend while improving performance

    • Stress-test backup and disaster recovery procedures and publish runbooks

    • Drive SOC 2 Type II renewals and maintain ongoing compliance cadence

    • Coordinate tabletop exercises and incident response drills with the Security Incident Response Team

    Our stack

    • Terraform & Docker Swarm deployed to AWS for production infrastructure

    • Grafana, Loki, and Prometheus for observability

    • GitHub Actions for CI/CD

    • Playwright for e2e testing

    • Gitea application fork

      • Go [server-side]

    • PostgreSQL

    Expectations

    Our ideal candidate has:

    • 8+ years of cloud infrastructure and/or security engineering experience, with recent hands-on production work — you've written Terraform and debugged a live incident in the past year, not the past decade

    • Experience owning infrastructure at a startup or on a small team, where you built systems yourself rather than directing a platform org

    • Fluency in the operational differences between multi-tenant SaaS, single-tenant, and self-hosted deployments — and how each changes the approach to support, monitoring, and implementation

    • 2+ years of people management experience (hiring, mentoring, performance management)

    • Deep hands-on expertise with AWS services (IAM, GuardDuty, VPC, Lambda, etc.), Linux administration, and Docker

    • Demonstrated ownership of security policy, compliance programs (SOC 2, ISO 27001), and incident response

    • Confidence in front of customers — you can run an InfoSec review, present to a CISO, and guide an enterprise onboarding

    • Strong project management skills with ability to lead cross-functional initiatives from engineers to customers

    • Comfort with ambiguity and a high degree of autonomy

    • Must be a U.S. Citizen or Lawful Permanent Resident (Green Card holder)

    Relevant skills

    You don't need to check every box, but the more of these you bring, the better:

    Infrastructure and operations

    • Terraform and infrastructure-as-code at scale

    • AWS services (IAM, GuardDuty, Elasticsearch, ElastiCache, Lambda) and experience with other cloud providers (GCP, Azure)

    • Docker and Kubernetes

    • Bash and Python scripting

    • nginx and reverse-proxy services

    • PostgreSQL administration

    • Automated provisioning and orchestration of per-customer environments

    Security and compliance

    • SOC 2, ISO 27001, and other security certification frameworks

    • ITAR/EAR/CUI compliance and GovCloud deployments

    • SSO, OIDC, LDAP, and enterprise authentication

    • Vulnerability scanning, penetration testing coordination, and vendor security reviews

    Leadership

    • Hiring, mentoring, and building infrastructure teams from the ground up

    • Working with legal counsel on data protection, DPAs, and regulatory matters

    • Customer-facing technical communication (InfoSec reviews, enterprise onboarding)

    • Project management using tools such as Jira, Notion, or similar

    Benefits

    • Opportunity to make a large impact at an executive level

    • Supportive and smart colleagues

    • Flexible work

    • Competitive salary and equity

    • Health, dental, and vision benefits

    • Generous PTO

    • Home office stipend

    • Relocation package

    Similar Jobs