Information Systems Security Manager (ISSM)

1 week, 4 days ago
Full-time
Senior
Cybersecurity
Oklo

Oklo

Oklo Inc. designs and deploys advanced fission power plants for clean, reliable, and affordable energy, utilizing innovative technology with inherent safety and nuclear waste as fuel.

Electric Utilities
51-250

Description

  • Serve as the primary authority for Oklo’s information systems security posture.
  • Implement, maintain, and continuously improve security controls aligned with NIST 800-53 and NIST 800-171.
  • Embed security requirements into system design, configuration, and operations across on-premises and cloud environments.
  • Assess, remediate, and maintain secure system configurations using baselines such as DISA STIGs and CIS Benchmarks.
  • Partner with IT and engineering teams on secure architectures, access controls, encryption, and monitoring.
  • Oversee security monitoring, logging, and alerting to detect and respond to security events.
  • Lead incident response activities, including investigation, containment, remediation, and post-incident reviews.
  • Coordinate vulnerability management, including scanning, remediation tracking, validation, and patching.
  • Own security compliance execution for standards and contract requirements such as SOX, NIST, and CMMC.
  • Build and maintain System Security Plans, policies, procedures, and other supporting security artifacts.
  • Conduct system risk assessments and support internal and external audits and assessments.
  • Enforce controls for export-controlled data, including access restrictions, segmentation, and secure handling.
  • Develop and enforce information security policies, standards, and procedures.
  • Communicate security risks, decisions, and requirements to technical and non-technical stakeholders.

Requirements

  • 6+ years of experience in information security or cybersecurity, including 3+ years in a system security, security engineering, or compliance-focused role.
  • Proven experience applying, remediating, and maintaining compliance with DISA STIGs and CIS Benchmarks.
  • Operational experience securing and maintaining Linux, macOS, and Windows environments, with Linux as the primary operating system.
  • Experience implementing or operating security controls under NIST frameworks.
  • Experience using automated or semi-automated compliance tools such as SCAP, OpenSCAP, compliance-as-code, or equivalent.
  • Prior experience supporting federally regulated environments, including DOE, NRC, DoD, or similar regulatory bodies.
  • Active certification meeting DoD 8570 / DoD 8140 baseline requirements, such as CISSP, CISM, CASP+, GSLC, or Security+.
  • Must be considered a U.S. Person under 8 U.S.C. 1324b(a)(3).
  • Strong working knowledge of NIST 800-53, NIST 800-171, and risk-based security control implementation.
  • Hands-on experience in Linux, macOS, and Windows hardening, configuration, and troubleshooting.
  • Ability to translate regulatory requirements into practical operational security controls.
  • Proven experience leading incident response and vulnerability remediation efforts.
  • Excellent written and verbal communication skills, with strong documentation ability.
  • Strong organizational and time-management skills in a fast-paced, startup environment.
  • Passion for clean energy and advanced fission is preferred.

Benefits

  • Salary of $115,000 to $125,000.
  • Equity.
  • Competitive pay.
  • 401(k).
  • Health insurance.
  • FSA.
  • Flexible time off.
  • Flexible work hours.
  • Remote work with periodic travel to headquarters in Santa Clara, CA, including in-person onboarding for the first two weeks.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Engineer

SymSoft Solutions Web Design, Development, and System Integration

Symsoft Solutions is hiring a remote six-month contract professional to support state and local government web, application, and data services work with prior State of California experience.

46 minutes ago

Director of Security/GRC

Censys 51-250 IT Services

Censys is hiring a Director of Security & GRC to lead corporate security, risk, and compliance programs for a remote U.S. team supporting internet intelligence operations.

AWS Azure Cybersecurity GCP SIEM
3 hours, 49 minutes ago

Senior Information Security Specialist

Rush Street Interactive 251-1K Hotels, Restaurants & Leisure

Rush Street Interactive is hiring a Senior Information Security Specialist to support the protection of its online gaming platforms, infrastructure, and data through technical security leadership across multiple domains.

SIEM SOC
4 hours, 28 minutes ago

DevSecOps Engineer (TypeScript & Agentic AI)

Arize AI 51-250 IT Services

Arize AI is hiring a remote IT Support Specialist to support Mac-only endpoints, cloud systems, and compliance operations for a distributed team.

Confluence GitHub JIRA TypeScript
5 hours, 39 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers