Security Engineer
Listed on 2026-01-25
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security, Security Manager
About Nominal
Nominal is building the software infrastructure powering the world’s most advanced hardware systems — from spacecraft and autonomous vehicles to next-generation industrial machines. Our platform ingests high-rate telemetry, validates complex autonomy software in real time, and enables engineers to iterate faster without sacrificing safety or precision. We’re a small, fast-moving team of engineers and operators who own problems end-to-end, work across disciplines, and thrive on challenges at the intersection of hardware and software.
As an early team hire dedicated to information security (Security) and governance, risk, and compliance (GRC), you’ll be responsible for working across the organization, developing and maturing various Security and GRC controls. You’ll also play a critical role in assisting Nominal to meet various authority to operate (ATO) initiatives. This may include tasks such as hardening Nominal’s software platform (both security and availability), deploying into secure environments, assisting with incident response, managing Nominal’s network, ensuring endpoint security, establishing baseline device configuration, guaranteeing technical compliance with information security standards, and more.
Over time, this role is expected to grow in scope and impact, with opportunities to take on broader ownership across security leadership, compliance programs, and potentially people or program management as Nominal scales.
🚀 About The Role
- Own the Security Posture (0 to
1):
As part of a small team, you will be responsible for building and maturing Nominal’s security and GRC posture from an early foundation. This includes designing first-generation controls, tooling, and processes that scale as Nominal serves regulated enterprise and defense customers (U.S. and non-U.S.). This role emphasizes systems thinking, architecture, and secure-by-design decisions over reactive monitoring or narrow security operations. - Detect and Respond:
Strengthen Nominalʼs operational and product security through active monitoring, threat detection, and incident response. Manage endpoint protection and logging tools (e.g., EDR, SIEM), investigate alerts, and collaborate with engineering to close gaps and prevent recurrences. - Plan and Execute:
Translate GRC requirements (e.g., CMMC, NIST 800-171, FedRAMP, NIST 800-53, Impact Level (IL) 4/5, and National Security Systems (NSS)) into concrete technical actions, architectures, and policies that meet stringent information security standards. Assist and support the maintenance of our Information Security Program. Apply technology standards to classified, air-gapped environments. - Coach Our Team:
Create and deliver approachable, relevant training to ensure all employees are equipped to maintain high technical standards for Security and Compliance. Provide guidance regarding procurement or download of secure, vetted third-party software, applications, and libraries. - Communicate the Standard:
Prepare communications for government partners, assessors, auditors, and customers that satisfactorily explain Nominalʼs technical security posture, both for our software platform and IT systems/endpoints, and inspire confidence in our secure product and business practices.
🚀 Who This Role Is (and Isn’t) For
This role is designed for a broad, product-minded security engineer who has helped build security programs in early-stage or fast-scaling technology companies.
You Will Thrive In This Role If You
- Have operated in environments where security controls, tooling, and processes were built from first principles rather than inherited.
- Enjoy owning problems end-to-end across product, infrastructure, endpoints, and compliance.
- Are comfortable balancing technical rigor with startup velocity and ambiguity.
This role is not a fit for candidates whose experience is primarily:
- Operating mature SOCs or alert-centric security environments.
- Narrowly scoped security analysis roles without broader systems ownership.
- Managed security service providers or highly siloed enterprise security teams.
We’re looking for a generalist security engineer with strong judgment and systems intuition, who has…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).