Cybersecurity Engineer - Security & Compliance

Aalo Atomics

$100K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Security, IT, Computer Science, or related field, or equivalent experience.
  • Three or more years of experience in cybersecurity, information security, or related IT role.
  • Working knowledge of core cybersecurity domains, including endpoint and network security, IAM, and vulnerability management.
  • Experience with cybersecurity technologies like EDR, SIEM, firewalls, and IAM solutions.
  • Familiarity with frameworks and standards like NIST CSF and ISO 27001.
  • Experience in documentation, risk assessments, audit support, or compliance activities.
  • Strong communication skills for technical and non-technical audiences.

Responsibilities

  • Implement, maintain, and monitor cybersecurity technologies and controls.
  • Monitor and investigate security events, supporting incident response activities.
  • Conduct vulnerability assessments and coordinate remediation with stakeholders.
  • Support the development and review of cybersecurity policies and documentation.
  • Translate compliance requirements into technical controls and measures.
  • Maintain cybersecurity documentation and compliance materials like risk registers.
  • Assist with internal and external cybersecurity assessments and audits.

Benefits

  • Health, Dental, and Vision Insurance.
  • Paid Time Off.
  • Corporate Gym Membership.
Full Job Description
About the role

The Cybersecurity Engineer is responsible for implementing, maintaining, and improving the technical and administrative controls that protect the company's systems, networks, cloud environments, applications, and data. This role combines hands-on cybersecurity engineering with support for cybersecurity governance, risk management, and compliance activities.

Reporting to the Director of Information Security, the Cybersecurity Engineer works closely with IT, engineering, business teams, and leadership to identify and address cybersecurity risks, implement safeguards, maintain security documentation, support regulatory and contractual requirements, and help ensure that the company's security controls remain effective as the organization grows.

Essential Responsibilities

  • Implement, maintain, and monitor cybersecurity technologies and controls, including endpoint protection, firewalls, email security, vulnerability management, SIEM/logging, identity and access management, and cloud security controls.
  • Monitor and investigate security events and support incident response activities, including containment, remediation, recovery, and post-incident analysis.
  • Conduct vulnerability assessments and coordinate remediation activities with internal teams, system owners, and third-party providers.
  • Support the development, implementation, and periodic review of cybersecurity policies, standards, procedures, technical baselines, and related documentation.
  • Translate cybersecurity policies, standards, and compliance requirements into practical technical and administrative controls.
  • Support the establishment and maintenance of the company's cybersecurity control framework in alignment with applicable standards and frameworks, such as NIST CSF, NIST SP 800-53, CIS Controls, ISO 27001, and CMMC.
  • Maintain cybersecurity and compliance documentation, including policies, procedures, control descriptions, system inventories, evidence, risk registers, Plans of Action and Milestones (POA&Ms), and assessment materials.
  • Assist with internal and external cybersecurity assessments, audits, customer security reviews, and regulatory or contractual compliance activities.
  • Track identified security gaps and deficiencies and work with responsible stakeholders to develop, document, and monitor corrective actions and remediation plans.
  • Support cybersecurity risk assessments for systems, applications, vendors, technologies, and business processes.
  • Support third-party and vendor cybersecurity assessments and ongoing risk management activities.
  • Help maintain recurring cybersecurity processes such as access reviews, vulnerability management, incident response, configuration management, security awareness, and other control monitoring activities.
  • Maintain cybersecurity documentation, architecture diagrams, incident response playbooks, and technical standards.
  • Support security awareness and cybersecurity training activities.
  • Remain current on emerging threats, industry standards, regulatory requirements, and cybersecurity best practices.


Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Security, Information Technology, Computer Science, or a related field; or an equivalent combination of education, training, and relevant experience.
  • Three or more years of experience in cybersecurity, information security, systems security, or a related IT or security role.
  • Working knowledge of core cybersecurity domains, including endpoint security, network security, identity and access management, vulnerability management, logging/SIEM, and cloud security.
  • Experience implementing, administering, or supporting cybersecurity technologies such as endpoint detection and response (EDR), firewalls, email security platforms, SIEM tools, IAM solutions, or cloud security controls.
  • Familiarity with cybersecurity frameworks and standards such as NIST CSF, NIST SP 800-53, CIS Controls, ISO 27001, and/or CMMC.
  • Experience supporting cybersecurity documentation, risk assessments, control implementation, audit support, or compliance activities.
  • Ability to investigate security events, assess risk, and support incident response and remediation activities.
  • Strong written and verbal communication skills, including the ability to prepare clear documentation and communicate effectively with technical and non-technical stakeholders.
  • Strong organizational skills, attention to detail, and the ability to manage multiple priorities.


Preferred Qualifications

  • Experience in a role combining cybersecurity engineering with governance, risk, and compliance responsibilities.
  • Experience supporting internal audits, external assessments, customer security reviews, or regulatory compliance initiatives.
  • Experience working in cloud environments such as AWS, Microsoft Azure, or Google Cloud Platform.
  • Experience with third-party or vendor cybersecurity risk assessments.
  • Familiarity with secure configuration standards, technical baselines, and control validation practices.
  • Experience developing cybersecurity metrics, dashboards, or management reporting.
  • Relevant professional certifications such as Security+, CISSP, CISM, CEH, GSEC, CCSP, or equivalent.
  • Experience in a regulated industry or environment with contractual cybersecurity requirements.


Physical and Work Requirements

  • Regular periods of sitting and working at a computer.
  • Ability to communicate effectively in person, by phone, and in writing.
  • Ability to review technical documentation, analyze security data, and perform work requiring close attention to detail.
  • May require occasional work outside normal business hours to support security incidents, system changes, or audit and compliance activities.
  • May require occasional travel, depending on business needs at Aalo sites.

Requirements:

  • Based in the United States
  • Willing to work on-site in Austin, TX


What We Offer:

  • Competitive salary based on technical level
  • Health, Dental, Vision Insurance
  • Paid Time Off
  • Corporate Gym Membership


Additional Information:

Direct applicants only. No recruiters or staffing agencies, please.

Similar Jobs

More Jobs at Aalo Atomics

More Information Technology Jobs

Find similar Cybersecurity Engineer - Security & Compliance jobs: