Nooks (nooks.works) Logo

Nooks (nooks.works)

Cybersecurity Engineer

Reposted Yesterday
Easy Apply
Remote
Hiring Remotely in USA
145K-175K Annually
Senior level
Easy Apply
Remote
Hiring Remotely in USA
145K-175K Annually
Senior level
The Cybersecurity Engineer will manage compliance with NIST SP 800-171 standards, conduct self-assessments, oversee Google Workspace security, and prepare for audits. This role requires technical expertise in cybersecurity and collaboration with leadership and technical teams.
The summary above was generated by AI

ABOUT NOOKS

Are you seeking an exciting and unique opportunity to grow and support our national security? As a startup, we are offering a limited-time opportunity to be an equity owner in a pioneering new industry. Nooks is pioneering Classified Infrastructure-as-a-Service (CIaaS) to provide government and industry partners with the fastest, most efficient access to classified infrastructure. We are building a nationwide network of accredited classified spaces and systems, ensuring that the best technologies equip our nation’s warfighters. At Nooks, we value innovation, collaboration, and a service-first mindset.

ABOUT THE ROLE: 

The Cybersecurity Engineer is a pivotal role dedicated to securing Nooks' unclassified networks and ensuring strict adherence to NIST SP 800-171 standards. While our classified infrastructure is vital, protecting our Controlled Unclassified Information (CUI) is equally critical to our mission and partner trust. 

This position requires a "player-coach" mindset—someone who can manage the compliance program but also has the technical ability to conduct deep-dive self-assessments and internal audits. You will own the security posture of our unclassified environment, specifically within our Google Workspace architecture. This role is ideal for a technical compliance professional who understands how to translate NIST controls into practical configurations within a modern, cloud-native collaborative environment. 

KEY RESPONSIBILITIES: 

  • NIST 800-171 Governance: Serve as the primary owner for the unclassified environment's compliance posture. Manage and maintain the System Security Plan (SSP) to ensure accurate reflection of implemented controls against NIST SP 800-171 and CMMC Level 2 requirements. 
  • Self-Assessments & Auditing: Independently plan and execute comprehensive self-assessments of the unclassified network. Act as an internal auditor to validate control effectiveness, generate SPRS scores, and identify gaps prior to third-party assessments. 
  • Google Workspace Security: Architect and monitor security configurations within the network. Ensure Data Loss Prevention (DLP), access controls, and mobile device management (MDM) settings meet CUI protection requirements. 
  • Remediation Management: Track findings and vulnerabilities; develop and manage Plans of Action & Milestones (POA&Ms) to drive timely remediation of security gaps. ● Audit Readiness: Lead the preparation for C3PAO assessments. Compile evidence artifacts, interview technical staff, and ensure the environment is "audit-ready" at all times. 
  • Vendor & Supply Chain: Evaluate the compliance posture of third-party tools and

vendors integrated into the unclassified environment to ensure no breakage in the chain of trust. 

  • Software Vetting & Compliance: Serve as the primary cybersecurity point of contact for evaluating new enterprise software introductions. Assess compliance requirements and ensure all tools meet network-specific security standards and organizational policies. 

REQUIRED QUALIFICATIONS: 

  • Citizenship: You must be a US Citizen (Compliance requirement for accessing CUI/ITAR data). 
  • Experience: A minimum of 5-8 years of experience in Cybersecurity, with at least 3 years focused specifically on NIST SP 800-171 compliance and implementation. ● Google Workspace Expertise: Demonstrated experience configuring and securing Google Workspace (formerly G-Suite) in a regulated environment. You must understand how to apply compliance controls to Drive, Gmail, and endpoint management. ● Assessment Skills: Proven ability to conduct technical self-assessments. You must be comfortable acting as an auditor, testing controls, and gathering evidence without supervision. 
  • Framework Knowledge: Deep understanding of DFARS 252.204-7012/7019/7020, NIST SP 800-171, and CMMC Level 2 assessment guides. 
  • Certifications: Active DoD 8570/8140 IAM Level II or III certification (e.g., CISSP, CISM, CASP+, or CAP). 
  • Communication: Strong ability to explain technical requirements to non-technical leadership and document controls clearly for external auditors. 
  • CMMC Ecosystem: Status as a CMMC Certified Professional (CCP) or Registered Practitioner (RP). 
  • Google Certifications: Google Professional Cloud Security Engineer or Professional Google Workspace Administrator. 

PREFERRED QUALIFICATIONS: 

  • Clearance: While this role focuses on the unclassified environment, an active Secret or Top Secret clearance is a plus. 
  • Audit Experience: Experience functioning as a formal security control assessor (SCA) or QSA. 

COMPENSATION: 

  • base salary (Per Level) 
  • Yearly Bonus Structure + Equity Ownership in company 
  • Medical, Dental and Vision benefits 
  • 401k Employer Contribution Plan 
  • Flexible PTO Policy 

LOCATION: 

  • Remote (Must reside in the US)

TRAVEL: 

  • This role requires approximately 10-20% travel for on-site assessments or team strategy meetings. 

ELIGIBILITY: 

● You must be a US Citizen.

Salary Range for all departments

Salary Range
$145,000$175,000 USD

Top Skills

Cmmc Level 2
Dfars
Google Workspace
Nist Sp 800-171

Similar Jobs

11 Days Ago
Easy Apply
Remote
USA
Easy Apply
85K-100K Annually
Mid level
85K-100K Annually
Mid level
Business Intelligence • Consulting
The Security Engineer will protect client IT environments from cyber threats, responding to incidents, implementing security solutions, and educating clients. Responsibilities include threat analysis and security tool management, requiring strong technical skills and client interaction.
Top Skills: Application SecurityDns SecurityEdrEmail SecurityFirewallsIds/IpsMfaMicrosoft 365SIEMVulnerability Scanning Tools
15 Days Ago
Remote or Hybrid
4 Locations
176K-221K Annually
Mid level
176K-221K Annually
Mid level
Fintech • Machine Learning • Payments • Software • Financial Services
Responsible for security architecture, design, and configuration of HP NonStop systems, collaborating with vendors and teams, and ensuring compliance with security policies and regulatory requirements.
Top Skills: CyberarkHp Nonstop SystemsServicenowSplunk
20 Days Ago
Easy Apply
Remote
USA
Easy Apply
150K-150K Annually
Senior level
150K-150K Annually
Senior level
Manufacturing • Renewable Energy
Lead and manage cybersecurity activities and protections, assessing security vulnerabilities, developing policies, and collaborating with cross-functional teams to ensure compliance and security posture.
Top Skills: CryptographyCspmDlpEdrEmail SecurityEmbedded SecurityIso27001Network SecurityNistPen TestsPythonRustSecure Bill Of MaterialsSoc2Threat ModelingVulnerability AssessmentsXdrZtna

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account