ITAR employee requirements for defense hiring

Hiring Insights · · 16 min read
Two defense technology professionals reviewing an engineering diagram and electronics hardware in a secure workspace

What are ITAR employee requirements?

ITAR employee requirements are access requirements, not a blanket rule that every employee must be a U.S. citizen. The International Traffic in Arms Regulations control defense articles, defense services, and related technical data. A company first has to identify what is controlled, then determine who will access it and whether that access needs government authorization.

That distinction changes a search. If a founder starts with “U.S. citizens only” because the company touches defense work, the company may exclude qualified people without establishing a lawful reason. A green card holder, a U.S. national, a refugee, or an asylee may be a U.S. person under ITAR. A separate contract term or a need to access classified information may create a narrower requirement, but that is a different analysis.

I have spent nearly 16 years in technical recruiting, and cleared and defense hiring is now one of my specialties. The hardest searches are not always hard because the talent is rare. Sometimes the role was defined with three different restrictions blended into one sentence. Before I source anyone, I want the hiring team to separate export control, contract terms, classified access, and security clearance eligibility.

This article helps you have that conversation. It provides general recruiting information, not legal advice. Ask qualified export-control counsel and your empowered official to decide how ITAR applies to your company, technology, and candidates.

What does ITAR control?

ITAR controls the export and temporary import of defense articles and defense services on the U.S. Munitions List. It can also control technical data related to those articles. The current ITAR definitions in 22 CFR Part 120 define technical data to include information required for activities such as the design, development, production, operation, repair, testing, maintenance, or modification of defense articles.

An export does not always involve shipping hardware across a border. Under 22 CFR 120.50, releasing technical data to a foreign person in the United States can be a deemed export. Under 22 CFR 120.56, a release can happen through inspection, an oral or written exchange, or access information that lets a foreign person view or possess unencrypted technical data.

This is why physical location alone does not answer the hiring question. A foreign person sitting in a U.S. office may receive controlled technical data. A U.S. person working abroad may present a different set of facts. A remote employee who can open a repository, drawing, test record, or system may have access even if nobody emails a file.

The first useful question is not, “What passport does the candidate hold?” It is, “What information, systems, equipment, and conversations does this role need to access?”

Who counts as a U.S. person under ITAR?

A U.S. person under ITAR includes more people than U.S. citizens. 22 CFR 120.62 includes lawful permanent residents and protected individuals as defined by federal law. The Department of Justice explains the individual categories in its export-control hiring fact sheet.

Here is the hiring version of those definitions:

Individual statusWhat it means for this first ITAR screenWhat it does not prove
U.S. citizenIncluded as a U.S. personClearance eligibility, contract eligibility, or need-to-know
U.S. nationalIncluded as a U.S. person, including a noncitizen U.S. nationalThat every contract treats the role the same way
Lawful permanent residentA green card holder is included as a U.S. personU.S. citizenship or eligibility for a standard personnel security clearance
RefugeeA worker who has been granted refugee status is included as a U.S. personClearance eligibility or access beyond the role’s need
AsyleeA worker who has been granted asylum is included as a U.S. personClearance eligibility or access beyond the role’s need
Foreign personUnder 22 CFR 120.63, a natural person who is not a lawful permanent resident or protected individualThat the person cannot be employed or cannot do any work for the company

“Work-authorized” and “U.S. person” are not interchangeable. Someone may have permission to work in the United States but still be a foreign person for an export-control assessment. The reverse mistake also causes trouble when employers treat a green card holder as if the person falls outside the ITAR U.S.-person definition.

The DOJ also tells employers to separate the export compliance assessment from the Form I-9 process. The I-9 confirms permission to work and lets the employee choose from permitted documents. An export assessment answers a different question about access to controlled items. Combining those processes can lead an employer to request the wrong documents or treat candidates differently.

Does ITAR require U.S.-citizen-only hiring?

No. The Justice Department’s Immigrant and Employee Rights Section ITAR FAQ says that neither ITAR nor the Export Administration Regulations requires or allows an employer to limit jobs to U.S. citizens. The DOJ fact sheet says the regulations contain no employment or hiring requirements.

That answer is direct, but it is not the end of the role analysis. A company may need authorization before a foreign person can access controlled technology. A law, regulation, executive order, or government contract may require a particular citizenship status for a specific position. Classified work brings personnel security rules into the picture. The mistake is using the word “ITAR” as a substitute for identifying which requirement actually applies.

I would ask a founder to put the source next to every restriction before the role goes live:

LayerThe question to answerWho should confirm it
ITAR accessWill the person receive, inspect, discuss, or gain system access to a defense article, defense service, or controlled technical data?Empowered official, export team, and counsel
Export authorizationIf the person is a foreign person, is authorization required and available for the exact access?Empowered official and counsel, with DDTC input when needed
Contract restrictionDoes the government contract or subcontract require citizenship, location, staffing approval, or another condition for this position?Contracts team and counsel
Classified accessWill the person need access to classified information, at what level, and with what need-to-know?Facility security officer and the responsible government authority
Employment eligibilityIs the candidate authorized to work, and how will the company run Form I-9?Trained HR staff and employment counsel

If the team cannot name the layer, it is not ready to write the requirement. The same discipline improves the rest of the posting. My guide to writing a job description engineers actually read covers the technical and candidate-facing parts once the access rules are correct.

How should a defense startup assess a role before recruiting?

Assess the work and the access path before assessing candidates. The flow below is a planning tool, not an authorization decision. It shows where the recruiting team must hand the question to the people who own export, contract, and security decisions.

flowchart TD
  A[Define the role's<br/>work and access] --> B{ITAR-controlled<br/>access required?}
  B -->|No| C[Check other controls<br/>and contract terms]
  B -->|Yes| D{Is the candidate<br/>a U.S. person?}
  D -->|Yes| E[Check contract, clearance,<br/>and need-to-know]
  D -->|No| F[Counsel assesses<br/>authorization or redesign]
  C --> G[Document the approved<br/>role requirements]
  E --> G
  F -->|If approved| G
  classDef question fill:#ECFDF5,stroke:#10B981,stroke-width:1.5px,color:#065F46
  classDef action fill:#D1FAE5,stroke:#059669,stroke-width:1.5px,color:#0A2E22
  class B,D question
  class A,C,E,F,G action
A recruiting flow for identifying the real role requirement before sourcing. Legal and security owners make the final decisions.

The flow starts with classification because companies often use “ITAR role” too loosely. A business may manufacture one defense article while most of its software, finance, commercial operations, or internal tooling does not require access to that article’s controlled technical data. The company still has to check other controls and contract duties. It cannot assume that work is unrestricted just because it falls outside one ITAR access path.

The current DDTC Compliance Program Guidelines tell companies to document jurisdiction and classification decisions and track them in a central location. The guidelines also identify unauthorized access by foreign-person employees and broad access to technical data on internal networks as compliance risks. That is an operational responsibility, not a sentence to paste into every job ad.

Can a green card holder work on an ITAR-controlled project?

A lawful permanent resident is a U.S. person under 22 CFR 120.62. That means a green card holder belongs inside the normal U.S.-person candidate pool for the ITAR screen. An employer should not rewrite “U.S. person” as “U.S. citizen” and exclude lawful permanent residents without a separate, valid reason.

The role may still have requirements beyond ITAR. If the position requires access to classified information, the DCSA facility security officer FAQ says non-U.S. citizens are not eligible for a standard personnel security clearance. DCSA describes rare Limited Access Authorizations, but those are restricted government actions, not ordinary clearances and not a recruiting shortcut.

A contract may also set a requirement for a specific role. That requirement must come from the contract or another valid authority. Do not attribute it to ITAR if ITAR is not the source.

This separation matters when you compare an export-controlled engineer with a cleared engineer. My full guide to hiring cleared software engineers explains clearance levels, sponsorship, and need-to-know. The guide to how defense tech startups hire cleared engineers focuses on competing for that smaller, already-cleared pool.

Confirm the data, access, contract, location, and owner before you approve the requisition. A recruiter can test the talent market, but a recruiter cannot decide the company’s export obligations.

Use this pre-search checklist with your export, legal, contracts, security, engineering, and recruiting owners:

  1. Classify the work. Identify the article, service, software, and technical data the employee will use. Record the applicable USML category or the result of another jurisdiction review.
  2. Map real access. List repositories, drawings, test systems, facilities, meetings, tickets, logs, credentials, and devices. Include access that the person could gain, not only files the manager plans to send.
  3. Read the contract. Pull the prime contract, subcontract, statement of work, security classification guidance, and staffing clauses. Record any citizenship, location, clearance, approval, or reporting condition and its exact source.
  4. Separate classified access. Ask the facility security officer whether the position needs classified information, the required level, and a need-to-know. A clearance does not grant access to everything, and DCSA says access requires both the proper clearance and a need-to-know.
  5. Assess remote work. Identify where the person will work, where the systems and data will reside, who administers the systems, and whether foreign persons could view unencrypted technical data.
  6. Decide whether authorization is part of the plan. If a foreign person may need controlled access, have the empowered official and counsel determine whether an authorization or an applicable exemption is available. Do not promise access or a start date first.
  7. Design controls before sourcing. Define account permissions, physical areas, meeting rules, document labels, device policy, training, escalation, and audit records. Make the controls match the access decision.
  8. Write the candidate language. State the approved requirement and explain its source accurately. Keep the export assessment separate from Form I-9.
  9. Name one decision owner. Give recruiters and hiring managers one qualified contact for candidate questions. A vague group mailbox is how careful candidates get three different answers.
  10. Set a recheck point. Revisit the assessment if the design, contract, location, team, or candidate’s scope changes.

This preparation also helps when a search has been paused. Do not reopen the old requisition until the current access and contract facts are confirmed. The companion guide on restarting a startup hiring plan explains how to revalidate the whole role instead of recycling an outdated brief.

Can foreign or nearshore engineers support a defense company?

Foreign and nearshore engineers may be able to support work that does not give them access to ITAR-controlled defense articles, defense services, or technical data. Whether a particular work split is valid depends on the controlled material, the systems, the contract, other export rules, and the controls the company can enforce.

The safe planning principle is specific separation. “They will not work on the defense part” is not a control. A credible design identifies which repositories, environments, tickets, meetings, documents, facilities, and credentials are inside the boundary. It also prevents administrators, managers, and collaboration tools from giving accidental access.

For example, a company might ask counsel whether a foreign-person team can work on public website code, a commercial product with no controlled data, or an internal business system. That company would still need to confirm classification and other legal obligations. The answer cannot come from the job title or the country alone.

Remote access deserves the same care as office access. The ITAR release definition includes oral and written exchanges and access to unencrypted technical data. Screen sharing, chat, issue trackers, support logs, code comments, and broad cloud permissions can matter as much as a downloaded drawing.

I have recruited in Latin America since 2013, and I know how much engineering talent companies miss when they treat geography as a proxy for capability. That experience does not override export controls. It does make me insist on an honest work boundary before anyone says that a whole team can or cannot contribute. If you are considering a separate nearshore team, the nearshore software development hiring guide covers employment models and integration. Export counsel must still approve the defense-specific access model.

What should an ITAR job description say?

An ITAR-related job description should state the approved access requirement without inventing a citizenship rule. The DOJ recommends making clear that U.S. persons include more than U.S. citizens and warns employers not to claim that export-control regulations require U.S.-citizen-only hiring.

A company might use language like this after counsel approves it:

This position requires access to information controlled under the International Traffic in Arms Regulations. The company must determine whether each employee is a U.S. person under 22 CFR 120.62 or whether the company must obtain an export authorization. Any separate citizenship or security-clearance requirement will be stated for the specific position.

That sample is a starting point, not approved language for every employer. Counsel may change it based on the work, contract, authorization strategy, location, and local employment law.

If the role genuinely requires a clearance, say so separately. Name the level, whether active eligibility is required at application, whether the company can sponsor, the work location, and any program-specific access. Do not make candidates infer “cleared” from “ITAR.”

If the search is confidential, give the recruiter enough verified detail to screen accurately even when the company name or program cannot be shared. My guide to confidential executive and founding searches explains how to protect the search without replacing useful information with vagueness.

What is the recruiting takeaway?

Define the access requirement before you narrow the candidate pool. “ITAR” is not a complete qualification, and “U.S. citizen” is not a safe shorthand for “U.S. person.”

Good defense recruiting starts with a role that legal, export, security, contracts, and engineering owners understand the same way. That work gives candidates clear answers. It also lets a recruiter search the correct pool instead of filtering qualified people through an unsupported rule.

When the role is unusually specific, that preparation matters even more. I do my best work when a client needs precision, including software, AI and machine learning, founding, confidential, cleared, and defense searches. If you want to test whether the market matches the role you have defined, book a strategy call. Bring the approved access and contract requirements, and I will help you turn them into a focused search.

Legal note: This article provides general recruiting information. It is not legal advice, an export classification, or an authorization determination. ITAR, contract, security, immigration, and employment rules can overlap. Consult qualified export-control and employment counsel, your empowered official, your contracts team, and your facility security officer for your facts.

Sources and further reading

Frequently Asked Questions

Can a green card holder work on an ITAR-controlled project?

A green card holder is a lawful permanent resident and a U.S. person under 22 CFR 120.62. The employer must still check the contract, the work, and any classified access because those can create separate requirements.

How should an employer assess a dual citizen for an ITAR role?

Do not use dual citizenship as a shortcut for an access decision. A person who is a U.S. citizen fits the ITAR U.S.-person definition, but counsel and the empowered official must assess the actual work, contract, destinations, parties, and any separate security requirements. Dual citizenship alone also does not answer security-clearance eligibility or adjudication.

Is being a U.S. person the same as having a security clearance?

No. U.S.-person status is an export-control definition. A security clearance is a government determination about eligibility to access classified information, and DCSA also requires the proper level and a need-to-know for access.

Can a remote or nearshore engineer work for an ITAR-registered company?

Employment by an ITAR-registered company does not make every task ITAR-controlled. A foreign or nearshore engineer may be able to do properly separated work that does not provide controlled access, but qualified counsel must approve the classification, work boundary, and controls.

What ITAR language should a job description use?

Use the exact requirement that export and legal owners approve. Do not say “U.S. citizens only due to ITAR” unless a separate valid authority creates that restriction, and do not use “U.S. citizen” as a synonym for “U.S. person.”

When does a company need export authorization for an employee?

Authorization may be required when a foreign person needs access to ITAR-controlled technical data, defense articles, or defense services. The empowered official and qualified export-control counsel should determine whether authorization is required, which form applies, and whether the proposed scope can be approved before the company grants access.