Careers · Remote · Asheville, NC preferred

Cybersecurity Engineer

Design, implement, and continuously improve the technical controls that protect CRI’s networks, systems, and data from cyber threats.

About CRI

The Civilization Research Institute (CRI) is a research center focused on understanding and mitigating catastrophic and existential risk. Our mission is to create and disseminate actionable knowledge and wisdom that is essential for navigating the metacrisis, and to undertake basic research into viable future forms for global civilization. Our work spans technology, governance, ecological tipping points, financial systems, civilization theory, and sense‑making. We operate in a high‑trust, low‑ego environment where clarity, integrity, and long‑term thinking are essential.

If you’d like a quick overview of our work, this video with our Executive Director, Daniel Schmachtenberger, is a good place to start.

About the Role

The Cybersecurity Engineer will design, implement, operate, and continuously improve the technical controls protecting the organization’s networks, systems, endpoints, communications, LLM/AI services, and data from cyber threats. Working closely with the CTO and cybersecurity leadership, this role emphasizes hands-on security engineering, threat intelligence, vulnerability assessments, monitoring and detection, incident response, secure configuration, and security automation, including the practical use of LLMs/agents in cyber defense and protection against AI-enabled and agentic threats.

Location & Reporting

  • Our preference is for this to be a full-time, on-site role based out of Asheville, NC. We will also consider strong candidates who would work remotely with the ability to travel to Asheville as needed.
  • The role will report to the Chief Technology Officer.

What You’ll Own

Hardware/Software Selection and Configuration

  • Working closely with the CTO and cybersecurity leadership, manage hardware/software security review and configuration, ensuring all devices and systems have appropriate security settings.
  • Manage password managers, VPNs, secure communications channels, secure document-sharing systems, identity and access configurations, LLM services, and related security tooling.
  • Implement appropriate access controls, logging, data-handling settings, and technical safeguards for approved LLM/AI services, coding agents, and other model-enabled tools.

Threat Monitoring, Detection, and Recovery

  • Monitor network traffic, system logs, security alerts, and relevant threat intelligence for signs of suspicious activity or anomalies that could indicate potential threats.
  • Use LLMs, agents, and emerging agentic cyber capabilities for security analysis, triage, automation, and hardening with appropriate safeguards, human validation, and secure handling of sensitive information.
  • Detect, investigate, and mitigate attacks and suspicious activity as early as possible, including threats enabled by automated or agentic attack techniques.
  • Conduct regular vulnerability assessments, coordinate or perform penetration testing, and carry out incident response activities to mitigate potential security threats and minimize downtime.
  • Implement, maintain, and test technical recovery controls in accordance with disaster recovery and business continuity plans.

Security Controls and Policy Implementation

  • Review, refine, and implement technical controls required by current security protocols across information, operational, cyber, network, and personnel security.
  • Translate security policies and standards into practical configurations, including access controls, security classifications, data protection protocols, secure document-sharing procedures, and security of off-premises devices.
  • Implement LLM and AI use protocols through technical controls for approved services, data handling, access, logging, tool permissions, secrets management, and agentic coding workflows.
  • Maintain clear technical documentation and support compliance or security assessments by preparing evidence and documentation for review.

Security Awareness and Training

  • Support online and communications operational security for websites, public interfaces, bank and other accounts, and other systems that require secure configuration.
  • Train other team members on secure configurations, practical security measures, and safe use of LLM/AI services and agentic tools.
  • Partner with the Training Unit and cybersecurity leadership to contribute technical content to training materials so individuals across the organization and network understand the risk landscape, mitigation strategies, and practical security measures needed.

Digital Threat Monitoring and External Attack Surface Protection

  • Monitor and help protect CRI’s external digital presence from technical threats, including phishing, account compromise, malicious domains, impersonation, IP exposure, credential leakage, and related attack vectors.
  • Track online threats against CRI team members and close allied individuals in our network, in addition to hacking or phishing attempts; proactively respond to and protect against technical attacks. This may require configuring existing technology or building in-house analytics tools for related tracking purposes.
  • Assist with technical aspects of online reputation and threat response; others will manage outreach, content, communications, and legal responses.

Research and Continuous Improvement

  • Evaluate and recommend providers of VPNs, firewalls, secure Wi-Fi configurations, transcription services, alternative communication systems, LLM/AI services, security automation tools, VoIP, and related services based on technical requirements.
  • Establish the appropriate security and functionality configurations for selected software and hardware and maintain those configurations over time.
  • Build or improve scripts, automations, and analytics that increase the speed and quality of security monitoring, investigation, configuration validation, and response.
  • Stay current with the latest cyber threats, vulnerabilities, security trends, frontier model capabilities, LLM/agent security risks, and emerging defensive techniques.

Specific Responsibilities Related to Headquarters

  • Acquire and set up physical infrastructure and hardware: home security systems, routers, modems, extenders, Starlinks, battery backup systems, hard drives, computer monitors, printers, USBs, etc.
  • Set protocols for connecting to Wi-Fi networks and printers, turning cameras and microphones on and off, sharing addresses, etc.
  • Oversee quarterly housekeeping matters: bug sweeps, penetration tests, etc. This entails conducting due diligence on potential vendors/contractors, deciding which contractors to use for such services, communicating and collaborating with them, and ensuring the success of their work.

Qualifications

  • A degree in computer science, IT, systems engineering, or related qualification.
  • 4 years of work experience with incident detection, incident response, and forensics.
  • Experience with Firewalls (functionality and maintenance), Office 365 Security, VSX, and Endpoint Security.
  • Proficiency in Python, C++, Java, Ruby, Node, Go, and/or PowerShell.
  • Ability to work under pressure in a fast-paced environment.
  • Strong attention to detail with an analytical mind and outstanding problem-solving skills.
  • Great awareness of cybersecurity trends and hacking techniques.

What We Offer

  • Mission‑Driven Culture – Work alongside collaborative, values‑aligned colleagues tackling some of humanity’s most complex challenges.
  • Health & Wellness Support – Access to wellness resources designed to support your physical and mental well‑being.
  • Professional Growth & Development – Employees receive mentorship from senior leaders and the opportunity to take on meaningful projects that support continuous learning and career advancement.
  • Competitive Compensation – The starting compensation is competitive and will depend on a variety of factors that include experience, education, training, certification, and location. We do not currently cap salary ranges because we value team members growing in their roles over time.
  • Flexible Benefits – Full-time employees are offered flexible benefits to support the personal health, wellness, and finances of our team members.

Apply

Ready to join us? Submit your application using the button below.

Apply Here (opens in a new tab)