Talent.com
Security & Compliance Engineer
Security & Compliance EngineerNominal • New York, NY, United States
Security & Compliance Engineer

Security & Compliance Engineer

Nominal • New York, NY, United States
1 day ago
Job type
  • Permanent
Job description

About Nominal

Nominal is building the software infrastructure powering the world's most advanced hardware systems - from spacecraft and autonomous vehicles to next-generation industrial machines. Our platform ingests high-rate telemetry, validates complex autonomy software in real time, and enables engineers to iterate faster without sacrificing safety or precision. We're a small, fast-moving team of engineers and operators who own problems end-to-end, work across disciplines, and thrive on challenges at the intersection of hardware and software.

As an early team hire dedicated to information security (Security) and governance, risk, and compliance (GRC), you'll be responsible for working across the organization, developing and maturing various Security and GRC controls. You'll also play a critical role in assisting Nominal to meet various authority to operate (ATO) initiatives. This may include tasks such as hardening Nominal's software platform (both security and availability), deploying into secure environments, assisting with incident response, managing Nominal's network, ensuring endpoint security, establishing baseline device configuration, guaranteeing technical compliance with information security standards, and more.

About the role

  • Own the Posture : Technical excellence in product hardening and information security is table-stakes for Nominal's success due to our product and industry. You'll need to internalize this and fully own it in a first-class way. Set Nominal up for success in serving large DoD and enterprise customers in a secure manner.
  • Detect and Respond : Strengthen Nominal's operational and product security through active monitoring, threat detection, and incident response. Manage endpoint protection and logging tools (e.g., EDR, SIEM), investigate alerts, and collaborate with engineering to close gaps and prevent recurrences.
  • Plan and Execute : Translate GRC requirements (e.g., CMMC, NIST 800-171, FedRAMP, NIST 800-53, Impact Level (IL) 4 / 5, and National Security Systems (NSS)) to propose and lead a rollout of technical actions and policies that meet stringent information security standards. Assist and support the maintenance of our Information Security Program. Apply technology standards to classified, air-gapped environments.
  • Coach Our Team : Create and deliver approachable, relevant training to ensure all employees are equipped to maintain high technical standards for Security and Compliance. Provide guidance regarding procurement or download of secure, vetted third-party software, applications, and libraries.
  • Communicate the Standard : Prepare communications for government partners, assessors, auditors, and customers that satisfactorily explain Nominal's technical security posture, both for our software platform and IT systems / endpoints, and inspire confidence in our secure product and business practices.

We're looking for someone with

  • 4+ years of experience working as a Security Engineer / Security Analyst.
  • Hands-on expertise in endpoint protection, event monitoring and logging (EDR & SIEM).Incident handlining experience including incident preparation, detection, analysis, containment & eradication, and post-mortem.
  • Strong understanding of system administration, including network setup (VPN, SSIDs, firewalls), software & hardware allowlisting / blocklisting, encryption & secure protocols, identity and access management controls.
  • Familiarity with cloud environments such as AWS GovCloud, Microsoft Azure, Microsoft Government Community Cloud (GCC).Experience implementing and maintaining compliance frameworks such as CMMC, NIST 800-171, FedRAMP, NIST 800-53, DoD Impact Levels (IL4 / 5), National Security Systems (NSS), SOC2, and ISO 27001 / 27002.
  • Experience with federal contracting and data protection requirements, whether in government or industry settings.
  • Experience conducting risk assessments, vulnerability management, and security control testing to proactively identify and remediate issues and areas of improvement.
  • General knowledge of DevSecOps and infrastructure concepts, with the ability to effectively collaborate with engineering teams on planning, integrations, and implementation of security and compliance requirements.
  • Strong organizational & writing skills, and attention to detail, commensurate to build out policy, procedure, plan, and standards documentation for customer, government, and auditor audiences.
  • Strong project management, collaboration, and relational skills to work with cross-functional stakeholders across Nominal to ensure ongoing delivery of our Security and GRC posture.
  • Benefits

  • 100% coverage of medical, dental, and vision insurance
  • Unlimited PTO and sick leave
  • Free lunch, snacks, and coffee
  • Professional development stipend
  • Annual company retreat
  • $140,000 - $170,000 a year

    This job description is written to capture a range of experience levels from 4 years to 10+ years, which is why you'll see a wide band listed. Your actual base salary will be determined on a case-by-case basis and may vary based on a range of considerations, including job-related knowledge and skills, education, prior experience, and other business needs. The listed salary range represents an estimate for base compensation only. Base salary is just one part of the total rewards package. Eligible employees may also receive highly competitive equity grants in the form of stock options, allowing you to share in the company's long-term success.

    To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State.

    Please note that Nominal is unable to sponsor employment visas (H-1B, F-1 OPT, etc.) for this position. Applicants must be authorized to work in the U.S. without the need for visa sponsorship now or in the future. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin.

    We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

    Create a job alert for this search

    Security Engineer • New York, NY, United States

    Related jobs
    Senior Security Engineer - Offensive Security

    Senior Security Engineer - Offensive Security

    PLAID • New York, NY, United States
    Full-time
    We believe that the way people interact with their finances will drastically improve in the next few years.We're dedicated to empowering this transformation by building the tools and experiences th...Show more
    Last updated: 3 days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Insight Global • New York, NY, United States
    Full-time
    Insight Global is seeking a Senior Security Engineer to join one of our investment management clients.This individual will serve as a key member of the Information Technology team, reporting direct...Show more
    Last updated: 3 days ago • Promoted
    Staff Security Engineer, Infrastructure Security, IAM Products

    Staff Security Engineer, Infrastructure Security, IAM Products

    CoreWeave • Livingston, NJ, United States
    Permanent
    CoreWeave is The Essential Cloud for AI™.Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence....Show more
    Last updated: 3 days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Kensho • New York, NY, United States
    Full-time
    Kensho is S&P Global's hub for AI innovation and transformation.With expertise in machine learning, natural language processing, and data discovery, we develop and deploy novel solutions to innovat...Show more
    Last updated: 3 days ago • Promoted
    Security Engineer (Detection and Response)

    Security Engineer (Detection and Response)

    Alchemy • New York, NY, United States
    Full-time
    The Alchemy Platform is a world class developer platform designed to make building on the blockchain easy.We've built leading infrastructure in the space, powering over$105billion in transactions f...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer, Application Security

    Security Engineer, Application Security

    Rogo • New York, NY, United States
    Full-time
    Finance is the engine of the global economy.It decides which ideas get built, which companies rise, and how resources are allocated. Yet it runs on slow tools and outdated technology.Our mission is ...Show more
    Last updated: 14 days ago • Promoted
    IT & Security Engineer

    IT & Security Engineer

    Norm AI, Inc • New York, NY, United States
    Full-time
    Norm Ai, the leading Legal & Compliance AI company, has a client base with a combined $30 trillion in assets under management. By turning legal code into AI code, Norm enables enterprises to move fa...Show more
    Last updated: 12 days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Recruitics Careers • New York, NY, United States
    Full-time
    Recruitics is a data-centric recruitment marketing agency that makes it easy for the world's leading brands to attract and hire great talent. We revolutionized recruitment advertising in 2012 with t...Show more
    Last updated: 3 days ago • Promoted
    Application Security Engineer

    Application Security Engineer

    MoveWorks, Inc. • New York, NY, United States
    Full-time
    Are you interested in being part of Application Security efforts at Moveworks? Do you enjoy collaborating closely with engineers to develop secure solutions from the ground up and ensure they remai...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer, Systems Integrity

    Security Engineer, Systems Integrity

    Menlo Ventures • New York, NY, United States
    Full-time
    Anthropic’s mission is to create reliable, interpretable, and steerable AI systems.We want AI to be safe and beneficial for our users and for society as a whole. Our team is a quickly growing group ...Show more
    Last updated: 7 days ago • Promoted
    Security Engineer

    Security Engineer

    Zoom Corporation • New York, NY, United States
    Full-time
    The Security Engineer is responsible for security design and reviews across our products and services, with a specific focus on Platform services and core infrastructure components.The ideal candid...Show more
    Last updated: 1 day ago • Promoted
    Security Engineer

    Security Engineer

    META • New York, NY, United States
    Full-time
    Cross-Meta Security's mission is to protect the company, our community, and their data while empowering safe innovation.To achieve this, we are building a small team of Senior Individual Contributo...Show more
    Last updated: 30+ days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    Recruitics • New York, NY, United States
    Full-time
    Recruitics is a data-centric recruitment marketing agency that makes it easy for the world's leading brands to attract and hire great talent. We revolutionized recruitment advertising in 2012 with t...Show more
    Last updated: 2 days ago • Promoted
    Senior Security Engineer | Enterprise Security

    Senior Security Engineer | Enterprise Security

    RAMP • New York, NY, United States
    Full-time
    At Ramp, we're rethinking how modern finance teams function in the age of AI.We believe AI isn't just the next big wave.It's the new foundation for how business gets done.We're investing in that fu...Show more
    Last updated: 3 days ago • Promoted
    Senior / Staff Enterprise Security Engineer

    Senior / Staff Enterprise Security Engineer

    Abridge Al, Inc • New York, NY, United States
    Full-time
    Abridge was founded in 2018 with the mission of powering deeper understanding in healthcare.Our AI-powered platform was purpose-built for medical conversations, improving clinical documentation eff...Show more
    Last updated: 14 days ago • Promoted
    Senior Application Security Engineer

    Senior Application Security Engineer

    Datadog • New York, NY, United States
    Full-time
    As a Senior Security Engineer within Platform Security at Datadog, you will play a vital role in securing our infrastructure for agentic applications. This role will be critical in establishing and ...Show more
    Last updated: 17 hours ago • Promoted • New!
    Senior Lead Security Engineer

    Senior Lead Security Engineer

    JPMorgan Chase Bank, N.A. • Jersey City, NJ, United States
    Full-time
    Join a team at the forefront of securing the future of connected devices and smart environments within a world-renowned company. As a Senior Lead Security Engineer at JPMorgan Chase within the Cyber...Show more
    Last updated: 2 days ago • Promoted
    Lead Application Security Engineer

    Lead Application Security Engineer

    Point72 • New York, NY, United States
    Full-time
    Lead Application Security Engineer.We are seeking a highly skilled and experienced Lead Application Security Engineer to join our Global Information Security team. You will play a critical role in i...Show more
    Last updated: 22 days ago • Promoted