Careers · Remote · Asheville, NC preferred

Director of Cybersecurity

Build and lead CRI’s cybersecurity program end to end — strategy, architecture, governance, and hands-on operations.

About CRI

The Civilization Research Institute (CRI) is a research center focused on understanding and mitigating catastrophic and existential risk. Our mission is to create and disseminate actionable knowledge and wisdom that is essential for navigating the metacrisis, and to undertake research into viable future forms for global civilization. Our work spans technology, governance, ecological tipping points, financial systems, civilization theory, and societal sense‑making. The work requires analytical rigor, systems thinking, and cross‑disciplinary fluency. We operate in a high‑trust, low‑ego environment where clarity, integrity, and long‑term thinking are essential.

If you’d like a quick overview of our work, this video with our Executive Director, Daniel Schmachtenberger, is a good place to start.

About the Role

The Director of Cybersecurity will establish and lead the organization’s cybersecurity program, cyber threat model, including threats from frontier model attacks and exploits, and security roadmap. This is a hands-on leadership role responsible for cybersecurity strategy, governance, architecture, risk management, and technical operations. During the build-out of the function, the Director will directly implement and operate security controls, lead incident response, and establish policies, protocols, and standard operating procedures (SOPs) to protect CRI’s networks, systems, data, communications, and people.

Location & Reporting

  • Our preference is for this to be a full-time, on-site role based out of Asheville, NC. We will also consider strong candidates who would work remotely with the ability to travel to Asheville as needed.
  • The role will report to the Chief Technology Officer.

What You’ll Own

Cybersecurity Strategy, Governance, and Program Leadership

  • Own CRI’s cybersecurity posture, cyber threat model, security strategy, and security roadmap, in alignment with the organization’s broader security strategy.
  • Establish cybersecurity governance, risk metrics, decision rights, and regular reporting on material cyber threats, vulnerabilities, incidents, and mitigation priorities.
  • Build the cybersecurity function, including staffing, tooling, vendor relationships, operating cadence, and the appropriate division of work between internal team members and external specialists.

Security Architecture and Technical Controls

  • Establish pragmatic security architecture principles and standards for networks, endpoints, identity and access, secure communications, cloud/SaaS platforms, sensitive data, LLM services, and related security tooling.
  • During the initial build-out, directly review, select, configure, and operate hardware/software security controls, including password managers, VPNs, secure communications channels, secure document-sharing systems, monitoring, and endpoint/network protections.
  • Ensure security policies, standards, and threat-model assumptions are translated into practical technical controls, configurations, and operating procedures.

Threat Monitoring, Detection, Incident Response, and Recovery

  • Maintain active monitoring of network traffic, system logs, security alerts, public sources, and relevant threat intelligence for indicators of cyber threats.
  • Use and monitor frontier agentic cyber capabilities to harden configurations, improve detection and analysis, and adjust to rapidly changing threats from agentic coding models and AI-enabled attacks.
  • Lead vulnerability assessments, penetration testing, incident investigations, containment, remediation, and recovery activities to mitigate security threats and minimize downtime.
  • Establish and maintain technical disaster recovery controls and incident response procedures, and regularly exercise and improve them.

Security Policies, Protocols, and SOPs

  • Review, refine, document, implement, and enforce cybersecurity protocols across information, operations, cyber, network, and personnel security where they intersect with technology.
  • Define and implement cybersecurity policies and SOPs, including access controls, security classifications, data protection protocols, incident response plans, escalation procedures, third-party access, and security of off-premises devices.
  • Develop and implement LLM and AI use protocols to mitigate risks including sensitive-data leakage, access violations, insecure tool permissions, and agentic coding accidents; establish requirements for approved services, data handling, and access.
  • Conduct security and compliance assessments and prepare appropriate documentation for review.

Third-Party and Vendor Risk

  • Establish cybersecurity requirements for vendors, contractors, SaaS platforms, and other third parties; conduct or oversee due diligence and prioritize mitigation of material vendor risks.
  • Evaluate and manage key cybersecurity vendor relationships, including penetration testers, incident-response firms, threat-intelligence providers, and security tooling vendors.

Security Awareness and Training

  • Set the cybersecurity awareness program and ensure team members understand the cyber risk landscape, mitigation strategies, and practical security measures needed in day-to-day work, including secure LLM and agent use.
  • Partner with the Training Unit to create training materials and practical guidance, and assist with secure configurations and higher-risk workflows as needed.

Research and Continuous Improvement

  • Evaluate security technologies and providers across VPNs, firewalls, secure Wi-Fi, secure communications, endpoint and network protections, LLM services, and related systems.
  • Stay current with the latest cyber threats, vulnerabilities, security trends, frontier model capabilities, AI-enabled attack techniques, and emerging defensive uses of LLMs and agents.
  • Establish security metrics, feedback loops, periodic assessments, and exercises to continuously improve CRI’s cybersecurity posture.

Technology and Headquarters Security

  • Oversee secure configuration of headquarters technology infrastructure and hardware, including routers, modems, extenders, Starlinks, battery backup systems, hard drives, printers, USBs, and related equipment.
  • Set and maintain protocols for connecting to Wi-Fi networks and printers, use of cameras and microphones, sharing addresses, visitor technology access, and related day-to-day cybersecurity practices.
  • Oversee quarterly security housekeeping matters, including bug sweeps, penetration tests, and other technical assessments, and ensure successful remediation of findings.

Qualifications

  • Demonstrated experience leading a cybersecurity program or function, including cyber threat modeling, security strategy, governance, risk management, and technical operations.
  • Strong hands-on ability to implement and troubleshoot security controls across networks, endpoints, identity and access, secure communications, cloud/SaaS environments, and sensitive data.
  • Expert in network security protocols and architectures, threat modeling, and risk assessment methodologies.
  • Ability to personally lead and participate in technical incident investigation, triage, containment, remediation, and recovery, including analysis of logs and other technical evidence.
  • Practical experience with vulnerability management and penetration testing, including interpreting findings, prioritizing remediation, and validating corrective actions.
  • Ability to evaluate, select, configure, and initially administer security tools and services rather than relying exclusively on engineering staff or outside vendors.
  • Up-to-date on novel cyber threats from LLMs and frontier models and the use of LLMs/agents in cyber defense; practical understanding of controls needed for safe organizational use of LLM services and agentic systems.
  • Strong understanding of software architecture and technologies, with the ability to translate policies and security requirements into concrete configurations, controls, workflows, and SOPs.
  • Strong judgment and communication skills, with the ability to explain material cyber risks, tradeoffs, and recommendations clearly to senior leaders and non-technical colleagues.
  • Experience building and scaling a security department or cybersecurity function from the ground up, including organizational design, hiring, budgeting, policies, protocols, SOPs, tooling, and vendor management.
  • Experience establishing active threat monitoring, protective intelligence, incident response, and deterrence capabilities in a high-security environment.
  • Depth in one or more technical domains such as incident response and forensics, malware analysis and reverse engineering, penetration testing, threat intelligence, or security automation.
  • Experience securing AI/ML systems, LLM-enabled applications, agentic workflows, or other model-integrated systems beyond standard end-user LLM services.
  • Past military experience in cybersecurity or broader security operations is ideal; startup experience or experience within fast-moving technology companies is highly desirable.
  • Certifications such as Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), or other relevant security certifications are a plus.

What We Offer

  • Mission‑Driven Culture – Work alongside collaborative, values‑aligned colleagues tackling some of humanity’s most complex challenges.
  • Health & Wellness Support – Access to wellness resources designed to support your physical and mental well‑being.
  • Professional Growth & Development – Employees receive mentorship from senior leaders and the opportunity to take on meaningful projects that support continuous learning and career advancement.
  • Competitive Compensation – The starting compensation is competitive and will depend on a variety of factors that include experience, education, training, certification, and location. We do not currently cap salary ranges because we value team members growing in their roles over time.
  • Flexible Benefits – Full-time employees are offered flexible benefits to support the personal health, wellness, and finances of our team members.

Apply

Ready to join us? Submit your application using the button below.

Apply Here (opens in a new tab)