Information Systems Security Manager (ISSM)

1 month ago
Full-time
Senior
Cybersecurity
Oklo

Oklo

Oklo Inc. designs and deploys advanced fission power plants for clean, reliable, and affordable energy, utilizing innovative technology with inherent safety and nuclear waste as fuel.

Electric Utilities
51-250

Description

  • Serve as the primary authority for Oklo’s information systems security posture.
  • Implement, maintain, and continuously improve security controls aligned with NIST 800-53 and NIST 800-171.
  • Embed security requirements into system design, configuration, and operations across on-premises and cloud environments.
  • Assess, remediate, and maintain secure system configurations using baselines such as DISA STIGs and CIS Benchmarks.
  • Partner with IT and engineering teams on secure architectures, access controls, encryption, and monitoring.
  • Oversee security monitoring, logging, and alerting to detect and respond to security events.
  • Lead incident response activities, including investigation, containment, remediation, and post-incident reviews.
  • Coordinate vulnerability management, including scanning, remediation tracking, validation, and patching.
  • Own security compliance execution for standards and contract requirements such as SOX, NIST, and CMMC.
  • Build and maintain System Security Plans, policies, procedures, and other supporting security artifacts.
  • Conduct system risk assessments and support internal and external audits and assessments.
  • Enforce controls for export-controlled data, including access restrictions, segmentation, and secure handling.
  • Develop and enforce information security policies, standards, and procedures.
  • Communicate security risks, decisions, and requirements to technical and non-technical stakeholders.

Requirements

  • 6+ years of experience in information security or cybersecurity, including 3+ years in a system security, security engineering, or compliance-focused role.
  • Proven experience applying, remediating, and maintaining compliance with DISA STIGs and CIS Benchmarks.
  • Operational experience securing and maintaining Linux, macOS, and Windows environments, with Linux as the primary operating system.
  • Experience implementing or operating security controls under NIST frameworks.
  • Experience using automated or semi-automated compliance tools such as SCAP, OpenSCAP, compliance-as-code, or equivalent.
  • Prior experience supporting federally regulated environments, including DOE, NRC, DoD, or similar regulatory bodies.
  • Active certification meeting DoD 8570 / DoD 8140 baseline requirements, such as CISSP, CISM, CASP+, GSLC, or Security+.
  • Must be considered a U.S. Person under 8 U.S.C. 1324b(a)(3).
  • Strong working knowledge of NIST 800-53, NIST 800-171, and risk-based security control implementation.
  • Hands-on experience in Linux, macOS, and Windows hardening, configuration, and troubleshooting.
  • Ability to translate regulatory requirements into practical operational security controls.
  • Proven experience leading incident response and vulnerability remediation efforts.
  • Excellent written and verbal communication skills, with strong documentation ability.
  • Strong organizational and time-management skills in a fast-paced, startup environment.
  • Passion for clean energy and advanced fission is preferred.

Benefits

  • Salary of $115,000 to $125,000.
  • Equity.
  • Competitive pay.
  • 401(k).
  • Health insurance.
  • FSA.
  • Flexible time off.
  • Flexible work hours.
  • Remote work with periodic travel to headquarters in Santa Clara, CA, including in-person onboarding for the first two weeks.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Lead Security Engineer, Enterprise Security

Klaviyo 1K-5K IT Services

Klaviyo is hiring a Lead Security Engineer to secure its corporate systems and platforms across SaaS, identity, endpoints, Zero Trust networking, and perimeter defenses in a hands-on technical leadership role.

AWS Azure Cloudflare CrowdStrike GCP OAuth OpenID Connect Secrets Management Terraform Vercel
1 hour, 4 minutes ago

Principal Security Engineer, Privy

Stripe 5K-10K Diversified Financial Services

Privy is hiring a Principal Security Engineer to define and operate security programs for its fintech and crypto infrastructure products, with a focus on protecting sensitive systems and reducing risk across the company.

AWS Blockchain CI/CD Encryption Go Java JavaScript Microservices Network Security OAuth OpenID Connect Penetration Testing Python Ruby Rust Secrets Management TypeScript
1 hour, 9 minutes ago

Staff Security Engineer

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is hiring a Security Engineer to secure its OT and ICS environments and help design foundational defenses for advanced defense technology and factory systems.

Go Linux Python Rust
4 hours, 47 minutes ago

Senior Purple Operations Engineer

Sporty Group 51-250 Media

Sporty is hiring a Purple Operations Engineer to improve the quality and reliability of security detections across its security monitoring environment and turn threat findings into actionable defensive controls.

Azure Bash Cloudflare Confluence GitHub GitLab JIRA Kubernetes Lucene PowerShell Python SIEM SOC
5 hours, 21 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers