Cybersecurity Engineer – Security & Compliance
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Cybersecurity Engineer - Security & Compliance
About Aalo Atomics
Aalo Atomics is pioneering a new era in clean energy with factory-fabricated microreactors designed to deliver affordable, scalable, and reliable nuclear power. Our mission is to make nuclear energy globally accessible, starting with the Aalo-1, a 10 MWe reactor leveraging cutting edge safety, modularity, and efficiency. Based in Austin, TX, we are rapidly growing as we work to deploy the world's first fleet of advanced microreactors.
Join us and help revolutionize energy for a sustainable future.
About the role
The Cybersecurity Engineer is responsible for implementing, maintaining, and improving the technical and administrative controls that protect the company’s systems, networks, cloud environments, applications, and data. This role combines hands-on cybersecurity engineering with support for cybersecurity governance, risk management, and compliance activities.
Reporting to the Director of Information Security, the Cybersecurity Engineer works closely with IT, engineering, business teams, and leadership to identify and address cybersecurity risks, implement safeguards, maintain security documentation, support regulatory and contractual requirements, and help ensure that the company’s security controls remain effective as the organization grows.
- Implement, maintain, and monitor cybersecurity technologies and controls, including endpoint protection, firewalls, email security, vulnerability management, SIEM/logging, identity and access management, and cloud security controls.
- Monitor and investigate security events and support incident response activities, including containment, remediation, recovery, and post-incident analysis.
- Conduct vulnerability assessments and coordinate remediation activities with internal teams, system owners, and third-party providers.
- Support the development, implementation, and periodic review of cybersecurity policies, standards, procedures, technical baselines, and related documentation.
- Translate cybersecurity policies, standards, and compliance requirements into practical technical and administrative controls.
- Support the establishment and maintenance of the company’s cybersecurity control framework in alignment with applicable standards and frameworks, such as NIST CSF, NIST SP 800-53, CIS Controls, ISO 27001, and CMMC.
- Maintain cybersecurity and compliance documentation, including policies, procedures, control descriptions, system inventories, evidence, risk registers, Plans of Action and Milestones (POA&Ms), and assessment materials.
- Assist with internal and external cybersecurity assessments, audits, customer security reviews, and regulatory or contractual compliance activities.
- Track identified security gaps and deficiencies and work with responsible stakeholders to develop, document, and monitor corrective actions and remediation plans.
- Support cybersecurity risk assessments for systems, applications, vendors, technologies, and business processes.
- Support third-party and vendor cybersecurity assessments and ongoing risk management activities.
- Help maintain recurring cybersecurity processes such as access reviews, vulnerability management, incident response, configuration management, security awareness, and other control monitoring activities.
- Maintain cybersecurity documentation, architecture diagrams, incident response playbooks, and technical standards.
- Support security awareness and cybersecurity training activities.
- Remain current on emerging threats, industry standards, regulatory requirements, and cybersecurity best practices.
Required Qualifications
- Bachelor’s degree in Cybersecurity, Information Security, Information Technology, Computer Science, or a related field; or an equivalent…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).