Xcimer Energy Corporation Logo

Xcimer Energy Corporation

Cybersecurity & Compliance Administrator

Posted 3 Days Ago
Be an Early Applicant
In-Office
Denver, CO, USA
140K-175K Annually
Senior level
In-Office
Denver, CO, USA
140K-175K Annually
Senior level
Manage day-to-day security operations, CMMC 2.0 Level 2 compliance, and data privacy programs. Administer Microsoft Purview and Defender, run incident response, maintain SSP/POA&M, support air-gapped security, integrate logging/SIEM, and collaborate across IT, legal, and engineering to enforce security controls and evidence collection.
The summary above was generated by AI
Xcimer Energy leverages decades of research on Inertial Fusion Energy (IFE) combined with groundbreaking new laser architecture. Our mission is to deploy fusion power plants to meet global decarbonization goals as fast as possible. Xcimer has assembled a team of leaders in tough tech, fusion science, and manufacturing with a track record of rapid execution. Supported by leading investors, Xcimer is uniquely positioned to deliver limitless, clean, fusion power to combat climate change.
 
This is a full-time, onsite role based at our headquarters in Denver, CO.
 
As Cybersecurity & Compliance Administrator, you will operate and continuously improve Xcimer’s security, compliance, and data privacy posture while the company continues to scale, and support U.S. defense‑related work. This is a hands‑on individual contributor role responsible for day‑to‑day security operations, CMMC 2.0 Level 2 compliance execution, and establishment of a defensible data privacy program appropriate for a high‑value and high‑visibility target. We are looking for our members to apply their technical expertise, problem solving skills, and dedication to quality to positively impact the future of energy!

Responsibilities

    Microsoft Purview Administration (Compliance & Data Governance)

  • Configure and manage Purview capabilities to support compliance objectives, including data classification and labeling, data loss prevention (DLP), retention and deletion policies, eDiscovery workflows, and compliance reporting.
  • Develop and maintain Purview‑derived compliance artifacts and evidence outputs to support assessments, audits, due diligence, and continuous monitoring aligned to CMMC 2.0 Level 2 and NIST SP 800‑171.
  • Define and operate data retention and deletion procedures, integrating with Purview retention controls where appropriate
  • Microsoft Defender Administration (Threat Protection & Security Operations)

  • Configure, tune, and operate Microsoft Defender security controls across identity, endpoints, email/collaboration, and cloud applications, consistent with licensing and compliance scope.
  • Monitor alerts, investigate suspicious activity, and drive remediation actions; reducing noise through continuous tuning and improvements.
  • Establish and maintain detection and response playbooks, including alert triage, escalation paths, documentation requirements, and post-incident follow-up.
  • Incident Response & Threat Prevention

  • Own and maintain the Security Incident Response Plan, including severity definitions, roles and responsibilities, evidence handling, escalation paths, and internal/external communication procedures.
  • Lead security incident response from identification through containment, eradication, recovery, and lessons learned.
  • Perform root-cause analysis and coordinate corrective actions with IT administrative staff and relevant stakeholders.
  • Proactively implement threat prevention measures: hardening, secure configuration baselines, conditional access/MFA enforcement support, and policy-driven risk reduction.
  • Maintain an incident register covering actual, attempted, and suspected security incidents (including phishing attempts), investigations performed, and outcomes.
  • Compliance Enablement (CMMC L2 / NIST Controls)

  • Maintain the System Security Plan (SSP) and Plan of Actions & Milestones (POA&M) for in‑scope systems, ensuring clear implementation statements, ownership, and evidence references.
  • Support definition and maintenance of the CUI boundary, including systems, users, endpoints, networks, and data flows.
  • Translate CMMC and NIST control requirements into concrete configurations, procedures, and ongoing monitoring activities across Microsoft 365, on‑prem infrastructure, and restricted or air‑gapped environments.
  • Collect, organize, and maintain audit‑ready evidence to support internal assessments, customer diligence, and third‑party assessments.
  • Define and maintain a centralized logging strategy (SIEM) spanning cloud and on‑prem environments, including ingestion of logs from identity systems, endpoints, email, servers, firewalls, VPNs, and IDS/IPS platforms.
  • On‑Prem & Air‑Gapped Security

  • Establish and operate secure data transfer procedures for air‑gapped and restricted environments, including removable media governance, integrity validation, malware scanning, and chain‑of‑custody documentation.
  • Partner with Network Architecture to design and maintain secure monitoring architectures for restricted and air‑gapped environments, including TAP/SPAN placement, IDS deployment, and segmentation alignment with OT/ICS security best practices
  • Security Engineering & Integrations

  • Support integrations between cloud-based services and the Microsoft security/compliance ecosystem (e.g., log sources, alerting, ticketing workflows, SSO/identity integrations).
  • Contribute to automation where appropriate (e.g., scheduled scripts, workflows, or playbook-style response actions).
  • Cross-Functional Collaboration & Communication

  • Work closely with IT and engineering teams to ensure smooth operations and secure-by-default practices.
  • Document, categorize, and prioritize security issues to ensure efficient escalation and resolution.
  • Enforce approved security, compliance, and privacy policies and contribute to ongoing policy development and improvement.
  • Collaborate with Network Architecture on secure network design, segmentation strategy, and enforcement controls including firewall policy, IDS/IPS, and Zero Trust network principles.
  • Collaborate with Network Architecture on secure network design, segmentation strategy, and enforcement controls including firewall policy, IDS/IPS, and Zero Trust network principles
  • Implement privacy impact assessments (PIAs) for new systems or processes involving personal data.
  • Partner with Legal and HR to document the company’s GDPR and CCPA applicability position, including the basis where such laws do not apply. 
  • Support inclusion of appropriate data privacy and security terms in third‑party contracts and service agreements.

Qualifications

  • Education: Bachelor’s degree (or equivalent practical experience) in information technology, cybersecurity, information systems, or a related field. 
  • Experienece: 7+ years of experience in security administration, security operations, compliance operations, or adjacent IT roles with direct security responsibility.
  • Demonstrated hands‑on experience administering Microsoft 365 security and compliance services, including Microsoft Purview and Microsoft Defender in an enterprise environment. 
  • Proven background in security incident response, investigation, and documentation in regulated or high‑risk environments. 
  • Working knowledge of system security best practices, access control, secure configuration, and audit logging. 
  • Strong written and verbal communication skills; able to translate technical security risk into clear, actionable steps and documentation. 
  • Comfortable operating as a self‑directed individual contributor in a fast‑paced and evolving environment.
  • Excellent technical and interpersonal communication skills; able to translate security risk into actionable steps.
  • Comfortable in a fast-paced, dynamic, and ambiguous environment.
  • Positive attitude, strong ownership mindset, strong professional judgement and ability to earn trust and maintain professional relationships.
  • Must be a U.S. citizen or national, U.S. permanent resident (current Green Card holder), or lawfully admitted into the U.S. as a refugee of granted asylum 

Desired

  • Direct experience implementing or operating CMMC Level 2 and/or NIST SP 800‑171 controls, including evidence collection and assessment preparation. 
  • Experience with centralized logging or SIEM platforms and detection playbook development. 
  • Experience with cloud-based service integrations (webhooks/REST APIs) and security-relevant automation.
  • Experience with security-related scripting/automation practices and languages (Python, JavaScript, Ansible, SOAR‑style workflows etc.).
  • Familiarity with hybrid cloud and on‑prem infrastructure in regulated environments, including air‑gapped networks.

Equal Employment Opportunity
Xcimer Energy is proud to be an Equal Opportunity/Affirmative Action Employer and is committed to attracting, retaining, and developing a highly qualified, diverse, and dedicated work force. Xcimer Energy hires and promotes people on the basis of their qualifications, performance, and abilities. We support the establishment and maintenance of a workplace that fosters trust, equality, and teamwork, in which all employees recognize and appreciate the diversity of individual team members. We provide all qualified applicants for employment and employees with equal opportunities for hire, promotion, and other terms and conditions of employment, regardless of their race, color, religion, gender, sexual orientation, gender identity, national origin/ethnicity, age, physical or mental disability, genetic factors, military/veteran status, or any other status or characteristic protected by federal, state, and/or local law. Xcimer Energy will consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state, and local laws. For more information on “EEO Is the Law,” please see here and here.
 
Benefits
Xcimer offers a comprehensive benefits package designed to support employee health, well-being, and long-term success. Benefits include medical, dental, and vision coverage; basic and supplemental life insurance; short- and long-term disability; paid parental leave for employees at the time of birth or adoption; and a 401(k) with a company match of up to 6%. Eligible employees also receive equity, allowing them to share in the company’s long-term success.
Xcimer operates under a flexible Paid Time Off (ATO) approach. Rather than a fixed number of vacation days, employees are trusted to take the time they need to rest and recharge while meeting the expectations of their role and team. In addition, employees receive paid sick time, 13 company-paid holidays, and an annual paid company shutdown. Benefits are available to regular employees, including part-time and fixed-term roles, as well as interns, with eligibility varying by benefit.

Similar Jobs

An Hour Ago
Remote or Hybrid
United States
50K-50K Annually
Junior
50K-50K Annually
Junior
Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Sell and manage group benefits (life, disability, dental, vision, voluntary) in the Utah market. Build broker and client relationships, develop strategic sales plans, grow renewals and new business for 2,000–4,999 life groups, coordinate cross-functionally for implementation, and track pipeline and sales activity to meet territory goals.
An Hour Ago
Remote or Hybrid
United States
42K-42K Annually
Junior
42K-42K Annually
Junior
Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Provide phone and digital customer support for insurance policy, coverage, billing, and service inquiries. Use AI-guided tools and CRM systems to resolve complex issues, validate call summaries, document interactions, escalate as needed, and contribute to process improvements. Participate in paid training and ongoing development.
Top Skills: Ai-Powered ToolsAutomated SummarizationCopilotCRMCustomer Communication SystemsGuided Decision WorkflowsKnowledge Bases
An Hour Ago
Remote or Hybrid
United States
110K-150K Annually
Expert/Leader
110K-150K Annually
Expert/Leader
Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Lead a regional financial team overseeing billing, analysis, forecasting, and reporting. Partner with Sales and Client Services, own revenue and earnings projections, drive process improvements and compliance, manage year-end reporting and key financial approvals, and build cross-functional relationships to meet customer and financial goals.

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account