Haystack
← Back to Jobs
Other
AI

VP, Corporate Technology & CISO

Anduril IndustriesCosta Mesa🇺🇸United StatesPosted Sep 21, 2026

Why This Role Stands Out

As VP, Corporate Technology & CISO at Anduril Industries, you'll lead a high-impact security organization within a rapidly growing defense technology company, shaping the future of military capabilities. This role is ideal for an experienced leader passionate about building and scaling security programs, making it an excellent opportunity to drive significant innovation and career growth. We encourage you to apply and contribute to Anduril's vital mission.

Quick Overview

Seniority
Leader
Location
Costa Mesa, United States
Posted
7 hours ago
ComplianceComputer VisionData PrivacyDue DiligenceIntellectual PropertyOutreachRisk ManagementTalent AcquisitionZero Trust

Job Description

Anduril Industries is a defense technology company with a mission to transform U.S. and allied military capabilities with advanced technology. By bringing the expertise, technology, and business model of the 21st century’s most innovative companies to the defense industry, Anduril is changing how military systems are designed, built and sold. Anduril’s family of systems is powered by Lattice OS, an AI-powered operating system that turns thousands of data streams into a realtime, 3D command and control center. As the world enters an era of strategic competition, Anduril is committed to bringing cutting-edge autonomy, AI, computer vision, sensor fusion, and networking technology to the military in months, not years.

ABOUT THE TEAM

The Information Security team is responsible for protecting Anduril's most critical digital assets, including our networks, systems, data, and intellectual property, against the full spectrum of cyber threats, from nation-state adversaries to insider risk. As one of the fastest growing defense technology companies in the world, Information Security defends a global footprint spanning 70+ sites, securing thousands of devices and endpoints supporting more than 10,000 employees across classified and unclassified environments. Our team sits at the intersection of cybersecurity, engineering, and compliance, partnering closely with every division at Anduril to ensure our security posture scales as fast as our mission.

ABOUT THE JOB

We are looking for a Chief Information Security Officer (CISO) to build and lead a modern, engineering-driven information security organization. Reporting to the Chief Information Officer, you will own Anduril's information security posture end-to-end, spanning Information Security, Network Engineering & Infrastructure, IT, and Cyber Compliance. You will serve as a key strategic partner to our Chief Security Officer to ensure seamless defense across the cyber, physical, and human domains. This role demands a leader who can operate at the speed of a high-growth defense technology company, making pragmatic, risk-based decisions that enable rapid product delivery while ensuring uncompromising protection of our digital assets, networks, and data.

WHAT YOU'LL DO

  • Develop and Execute an Information Security Strategy: Design and implement a comprehensive strategy to protect Anduril's networks, systems, data, and intellectual property against the full spectrum of cyber threats, from nation-state adversaries to insider risk.
  • Lead a Unified Information Security Organization: Build and lead a high-performing organization spanning Information Security, Network Engineering & Infrastructure, IT, and Cyber Compliance into a cohesive function structured around business outcomes, not traditional silos.
  • Partner with the Chief Information Officer: Work as a key strategic partner to the CIO to ensure core engineering functions across InfoSec, IT, Infrastructure Engineering enable the enterprise to scale.
  • Partner with the Chief Security Officer: Work as a key strategic partner to the CSO to ensure a seamless security posture that fuses cyber, physical, and human-domain protections across the enterprise.
  • Drive Threat Detection and Response: Own the organization's ability to detect, investigate, and respond to cyber incidents and intrusions at speed, ensuring operational resilience across classified and unclassified environments.
  • Own Cyber Risk Management: Implement a dynamic risk management framework that continuously assesses and prioritizes cyber threats across all divisions, networks, and environments. Provide clear, actionable intelligence on risk exposure to executive leadership.
  • Ensure Global Cyber Compliance: Guarantee compliance with all applicable cybersecurity frameworks and US Government contractual obligations, including NIST 800-171, CMMC, ISO 27001, FedRAMP, and DoD-specific requirements. Serve as the primary senior liaison to government partners on all cybersecurity matters.
  • Build an Engineering-First Security Culture: Champion an approach to security that is deeply technical, automation-forward, and rooted in engineering principles, not checkbox compliance. Embed security into the software development lifecycle and infrastructure as a first-class concern.
  • Secure the Enterprise at Scale: Ensure the security and reliability of corporate IT, network infrastructure, and endpoint environments across a rapidly expanding global footprint of offices, manufacturing facilities, and test sites.
  • Operational Effectiveness: Drive quantifiable outcomes across the security organization through clear initiatives, metrics, and accountability.

REQUIRED QUALIFICATIONS

  • 15+ years of progressive leadership experience in information security, cybersecurity, or related technical disciplines.
  • Proven experience as a CISO or in a comparable senior cybersecurity leadership role at a technology or defense company, OR extensive experience in a senior cyber leadership role within the military or intelligence community.
  • Deep technical expertise across core information security disciplines: network security, application security, security operations, incident response, identity and access management, and cloud security.
  • Demonstrated success building, leading, and mentoring high-performing, cross-functional security and IT teams in a fast-paced environment.
  • Strong understanding of government cybersecurity frameworks and compliance requirements (NIST 800-171, CMMC, FedRAMP, FISMA, DFARS).
  • Currently possess or is eligible to obtain and maintain an active U.S. Top Secret SCI security clearance.

PREFERRED QUALIFICATIONS

  • Experience securing complex environments that span classified and unclassified networks, hardware R&D, manufacturing, and global test sites.
  • Experience in a high-growth, venture-backed technology company.
  • A pragmatic, first-principles approach to security that prioritizes risk and impact over rigid, compliance-only frameworks.
  • Hands-on technical background in software engineering, systems engineering, or infrastructure, not exclusively a governance/policy career path.
  • Experience building security programs that embed into engineering workflows (CI/CD pipeline security, infrastructure-as-code, zero trust architecture).
US Salary Range
$252,000$380,000 USD

The salary range for this role is an estimate based on a wide range of compensation factors, inclusive of base salary only. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Anduril's total compensation package. Additionally, Anduril offers top-tier benefits for full-time employees, including: 

Benefits

At Anduril, we invest in our people. Our comprehensive, competitive benefits package (available at little to no cost to employees) ensures you’re supported in health, recovery, and whatever comes next. For more information, Explore Our Benefits.

Protecting Yourself from Recruitment Scams

Anduril is committed to maintaining the integrity of our Talent acquisition process and the security of our candidates. We've observed a rise in sophisticated phishing and fraudulent schemes where individuals impersonate Anduril representatives, luring job seekers with false interviews or job offers. These scammers often attempt to extract payment or sensitive personal information.

To ensure your safety and help you navigate your job search with confidence, please keep the following critical points in mind:

  • No Financial Requests: Anduril will never solicit payment or demand personal financial details (such as banking information, credit card numbers, or social security numbers) at any stage of our hiring process. Our legitimate recruitment is entirely free for candidates.

  • Please always verify communications:
    • Direct from Anduril: If you receive an email from one of our recruiters, it will only come from an @anduril.com address.
    • Via Agency Partner: If contacted by a recruiting agency for an Anduril role, their email will clearly identify their agency. If you suspect any suspicious activity, please verify the agency's authenticity by reaching out to contact@anduril.com
  • Exercise Caution with Unsolicited Outreach: If you receive any communication that appears suspicious, contains grammatical errors, or makes unusual requests, do not engage. Always confirm the sender's email domain is @anduril.com before providing any personal information or clicking on links.

  • What to Do If You Suspect Fraud: Should you encounter any questionable or fraudulent outreach claiming to be from Anduril, please report it immediately to contact@anduril.com. Your proactive caution is invaluable in protecting your personal information and upholding the security and trustworthiness of our recruitment efforts.

Data Privacy

To view Anduril's candidate data privacy policy, please visit https://anduril.com/applicant-privacy-notice/. 

By submitting your application, you consent to Anduril Industries using a third-party service provider to conduct pre-employment risk, integrity, and due diligence screening and assessing potential risks as part of your application process. This third-party service provider provides risk-intelligence services that may include analysis of sanctions and watchlists, adverse media, public-record information, and other lawful open-source or commercial data sources. This third-party service provider does not act as a consumer reporting agency. Use of this provider helps to ensure compliance with applicable laws and protect technology, intellectual property, and organizational security.