About this role
The Nuclear Company is the fastest growing AI tech-enabled startup in the nuclear and energy space, pioneering a fleet-scale approach to building the next generation of nuclear reactors. Through our design-once, build-many model, we're accelerating the deployment of safe, reliable, and affordable nuclear energy.
We operate with an AI-first mindset. Every employee is expected to leverage AI, technology, and the Nuclear Operating System (NOS) as integral components of their role to improve the quality, speed, and impact of their work. We expect every team member to continuously identify opportunities to automate workflows, enhance decision-making, improve processes, and contribute to the ongoing evolution of NOS as a strategic operating capability that enables The Nuclear Company to scale with excellence.
We hire people who are driven by purpose, thrive in ambiguity, and are energized by building what has never been built before. Our team combines intellectual curiosity with high agency, embraces candid feedback and continuous learning, and holds themselves and others to exceptional standards. Our values— Transparency, Responsibility, Unity, Scrappy, and Tenacity —guide how we hire, collaborate, and make decisions every day. They are not words on a wall; they are the standard by which we operate. TRUST is the foundation of our safety culture, fostering intellectual honesty, accountability, and open communication, while our values challenge every team member to execute with urgency, humility, resilience, and an unwavering commitment to our mission.
About the role
The Director, Cloud & Security Engineering owns cloud and security engineering across Microsoft Azure and AWS, along with network and security architecture, identity, threat detection and incident response, and vulnerability management, and produces the technical evidence needed for audits and customer security reviews. The role also owns the business-facing side of IT: demand intake and prioritization, and rolling roadmaps with priority functions so requests don’t drop or get routed around IT. This role works closely with the Director of IT Operations and Infrastructure. This is a hands-on director role — leading a small senior team while staying technical enough to serve as an escalation point, with the team growing based on company needs.
Responsibilities
Cloud & Security Engineering Strategy
- Own cloud engineering across Microsoft Azure and AWS and set network and security architecture standards, including threat modeling and solution-level requirements
- Own build-vs-buy decisions, vendor and contract relationships for network and security platforms, and the domain’s operating budget
Identity, Detection & Response
- Direct identity security: privileged access, MFA, conditional access, and non-human identities
- Lead threat detection and incident response — playbooks, tabletop exercises, post-incident review — and report security posture and risk to leadership
Vulnerability & Compliance
- Drive vulnerability management and remediation to closure against defined SLAs
- Produce the technical evidence needed for audits and customer security reviews
Email, SaaS & AI Security
- Direct email and collaboration security: anti-phishing and BEC controls, DMARC/SPF/DKIM enforcement
- Govern SaaS security posture — OAuth and third-party app access, shadow-SaaS discovery, vendor security review — and set enablement-first guardrails for AI tools
Business Engagement
- Own intake and prioritization of business demand through a single documented process
- Maintain rolling roadmaps with priority functions (starting with NOS and Legal) and feed those priorities into annual planning and budget
- Coordinate supported functions’ cloud usage with engineering platform owners
People Leadership
- Lead and develop the engineering team, serve as a hands-on escalation backup, and grow the team based on company needs
Experience
- 10+ years in security and/or network engineering, including 4+ years leading technical staff or programs
- Cloud engineering and security depth across Microsoft Azure and AWS
- Deep identity security experience: privileged access management, MFA, conditional access, and non-human identities
- Experience building or maturing incident response (playbooks, tabletops) and owning vulnerability management with remediation SLAs
- Hands-on familiarity with the enterprise stack — SSE/zero-trust access (e.g., Zscaler), next-generation firewalls (e.g., FortiGate), EDR, SIEM, MDM — deep enough to direct the work and back up the team
- Fluency with compliance frameworks (NIST 800-53, CMMC, or equivalent) and producing audit-ready technical evidence
- Demonstrated experience partnering directly with business functions and managing demand against real capacity
- Strong communication skills; translates security risk for leadership and IT plans for the business
Preferred Experience
- Experience in regulated industries (nuclear, defense, energy, or federal); familiarity with 10 CFR 73.54 and NRC cybersecurity requirements
- Relevant certifications: CISSP, CISM, CCSP, or equivalent
- Experience transitioning outsourced or contractor-run security functions in-house
- Experience securing AI tooling, large language models, or agentic workflows
Benefits
- Competitive compensation packages
- 401k with company match
- Medical, dental, vision plans
- Generous vacation policy, plus holidays
Estimated Starting Salary Range
The estimated starting salary range for this role is $198,000 - $228,000 annually less applicable withholdings and deductions, paid on a bi-weekly basis. The actual salary offered may vary based on relevant factors as determined in the Company’s discretion, which may include experience, qualifications, tenure, skill set, availability of qualified candidates, geographic location, certifications held, and other criteria deemed pertinent to the particular role.
EEO Statement
The Nuclear Company is an equal opportunity employer committed to fostering an environment of inclusion in the workplace. We provide equal employment opportunities to all qualified applicants and employees without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic. We prohibit discrimination in all aspects of employment, including hiring, promotion, demotion, transfer, compensation, and termination.
Export Control
Certain positions at The Nuclear Company may involve access to information and technology subject to export controls under U.S. law. Compliance with these export controls may result in The Nuclear Company limiting its consideration of certain applicants.
Recruiting Fraud Alert
Your safety is our priority. We want to ensure your job search stays secure. Please note that the team at The Nuclear Company only communicates through official @thenuclearcompany.com email addresses. We will never ask for payments or sensitive financial information at any stage of our recruitment process. For your peace of mind, please verify all openings and submit your applications directly through our official careers page (https://www.thenuclearcompany.com/careers).
