EU remote
Director Physical Security
About this role
About Orcrist Technologies Orcrist is building a next generation data intelligence platform using cutting-edge technologies. We're handling petabyte-scale data with sub-second queries. Our product (OIP) is a Kubernetes‑based platform delivered as B2B SaaS or as a self‑hosted/on‑prem solution, including air‑gapped deployments. The Role The Director Physical Security owns everything in security that isn't IT/cyber: people, sites, material, and processes.
The role builds and runs the group's physical and organizational security program largely from scratch, in an environment where classified work, sensitive hardware, and regulatory scrutiny are part of daily business. What You'll Do Define and own the group-wide physical security strategy across all sites and entities, scaling it with company growth. Design, implement, and operate physical access control, perimeter protection, intrusion detection, CCTV, alarm management, and visitor/contractor management.
Build and maintain the organizational security framework for classified work — protection and handling of Verschlusssachen (VS), establishment of Sicherheitsbereiche and secure storage, in line with the Geheimschutzhandbuch. Act as the operational interface to German authorities on industrial security (Geheimschutzbetreuung via BMWK) and coordinate closely with the Sicherheitsbevollmächtigte(r); take on or support the SiBe function as needed.
Manage the physical dimension of personnel security: clearance-linked access, escorting rules, badge lifecycle, and onboarding/offboarding from a security standpoint. Run crisis management, emergency response, evacuation, and business continuity planning for physical incidents. Ensure physical security across the supply chain and logistics — secure transport, storage, and handling of sensitive hardware and prototypes.
Secure company events, trade shows, and customer/site visits. Manage external security vendors (guarding, alarm/CCTV, locksmithing, security tech) including budgets and SLAs. Develop policies, run audits, drills, and training; drive a security-awareness culture across a remote-first workforce. Own the physical/organizational side of the insider-threat program, in coordination with IT Security and People & Culture. Ensure compliance with the relevant defense and regulatory frameworks (SÜG, Geheimschutzhandbuch, NATO/EU classified standards, KRITIS/BSI where applicable, ITAR/EAR physical controls).