Ironstead Industrial Inc. acquires precision machine shops and manufacturing businesses in aerospace/defense, maritime, and commercial sectors, and rebuilds them into modern, data-driven operations. We don't run playbooks from a spreadsheet in another state. We parachute in, work shoulder to shoulder with machine operators, and rebuild the operating system of the business from the inside. IronsteadOS, our purpose-built operating platform syncing customer design to final inspection & logistics, is the backbone of that transformation, but the platform only works if someone on the ground earns the trust to implement it.
Ironstead is seeking a Member of Technical Staff, Principal Compliance to build and scale the operational compliance system for a growing portfolio of advanced manufacturing businesses. This role sits at the intersection of Environmental Health & Safety, export control, defense cybersecurity, and operations. You will translate complex requirements into practical systems that work inside a machine shop: how people access controlled technical data, how hazardous materials are managed, how incidents are investigated, and how a newly acquired facility moves from fragmented practices to a defensible operating standard.
This is not a policy writing role where success is measured by the number of procedures published. Success means the controls actually work and production teams understand why they exist. The ideal candidate has deep expertise in at least one of EHS, export compliance, or defense cybersecurity, strong working knowledge across the others, and the judgment to know when a compliance requirement requires a hard control versus a pragmatic operational solution.
Author and deploy a unified portfolio compliance architecture, establishing standard operating procedures, audit criteria, and targeted training across EHS, ITAR/export control, and defense cybersecurity (CMMC/NIST SP 800-171).
Lead pre-acquisition compliance due diligence and post-close facility transformations, establishing clear risk ownership and actionable remediation roadmaps to rapidly baseline newly acquired shops.
Operationalize risk based compliance management, triaging vulnerabilities by real world operational exposure rather than finding counts to streamline corrective action and maintain production velocity.
Embed compliance controls and automated audit trail collection into IronsteadOS, building real time executive dashboards to monitor incidents, open risks, and corrective actions across all sites.
Codify post-integration lessons learned into scalable playbooks, continuously accelerating compliance onboarding timelines and strengthening defense readiness for subsequent acquisitions.
Architect scalable EHS architectures featuring leading indicator risk metrics, proactive hazard identification, and preventative safety protocols to eliminate incidents before they occur.
Standardize baseline shop floor safety programs, spanning lockout/tagout, machine guarding, ergonomics, chemical management, and emergency response, to establish zero-harm operating cultures across all sites.
Translate complex ITAR, EAR, and defense customer requirements into enforceable facility controls governing physical security, visitor access, technical data flows, and secure shipping.
Drive cross-site alignment and maintenance of regulatory cybersecurity frameworks, securing baseline compliance with CMMC 2.0, NIST SP 800-171, and DFARS standards.
Operationalize cybersecurity protocols directly into shop floor environments, securing CAM programming workflows, CNC machine connectivity, CMM/inspection data, and engineering workstations without compromising production velocity.
Significant experience in compliance, EHS, export controls, cybersecurity, or risk management within manufacturing, aerospace, defense, or another regulated industrial environment.
Experience with machine shop safety, industrial chemicals, environmental permitting, or controlled manufacturing environments.
Experience translating regulatory or contractual requirements into real operational controls.
Strong investigation, root cause, risk assessment, and corrective action skills.
Willingness to travel extensively (60-80%) and embed on-site at Ironstead portfolio facilities for extended periods, including some nights/weekends during critical transition windows
Familiarity with DFARS cybersecurity requirements and CUI handling.
Experience integrating compliance systems following an acquisition.
Experience implementing CMMC or NIST SP 800-171 controls in a manufacturing environment.
Relevant certifications such as CSP, CHMM, CISSP, CISM, CMMC credentials, or export compliance certifications.
Ability to work extended hours, including nights and weekends, during active deployment windows
Ability to pass any background/export-compliance screening required for defense-related client sites (ITAR-sensitive facilities)
U.S. Citizenship required due to ITAR/export control considerations
Ironstead Industrial Inc. is an equal opportunity employer. Employment decisions are based on merit, qualifications, and business needs.