Celebrating 30 Years of Idealist! Discover where we’ve been, and where we’re going.
Nonprofit
Published 4 days ago

Cybersecurity Engineer

Hybrid, Work must be performed in or near Asheville, NC
Apply


  • Details

    Job Type:
    Full Time
    Start Date:
    September 7, 2026
    Experience Level:
    Mid-level
    Cause Areas:
    Environment & Sustainability, Policy, Research & Social Science, Science & Technology, Transparency & Oversight

    Description

    About Us

    The Civilization Research Institute (CRI) is a research center focused on understanding and mitigating catastrophic and existential risk. Our mission is to create and disseminate actionable knowledge and wisdom that is essential for navigating the metacrisis, and to undertake basic research into viable future forms for global civilization.

    Our work spans technology, governance, ecological tipping points, financial systems, civilization theory, and sense-making. We operate in a high‑trust, low‑ego environment where clarity, integrity, and long‑term thinking are essential.

    If you’d like a quick overview of our work, this video with our Executive Director, Daniel Schmachtenberger, is a good place to start.

    About the Role

    The Cybersecurity Engineer will oversee all matters concerning security to protect the organization’s networks, systems, and data from cyber threats. This role emphasizes proactive measures, including threat intelligence, vulnerability assessments, and incident response, to safeguard digital assets against cyberattacks, as well as reactive measures as needed to mitigate any potential breaches

    Location and Reporting Relationship

    • This is a full-time, on-site role based out of Asheville, NC. We may also consider strong candidates who would work remotely with the ability to travel to HQ as needed
    • The role will report to the Chief Technology Officer.

    What You’ll Own

    • Hardware/Software Selection and Configuration
      • Working closely with the CTO, responsible for hardware/software security review and configuration, ensuring all devices have appropriate security settings.
      • Manage all Password managers, VPNs, secure comms channels, secure document sharing systems, etc.
    • Threat Monitoring, Detection, and Recovery
      • Monitor network traffic, system logs, and security alerts for signs of suspicious activity or anomalies that could indicate potential threats.
      • Detect and mitigate attacks before they occur.
      • Conduct regular vulnerability assessments, penetration testing, and incident response activities to mitigate potential security threats and minimize downtime.
      • Establish and maintain disaster recovery plans to ensure the rapid recovery of operations in the event of unforeseen disruptions or disasters.
    • Security Policy Development
      • Review, refine, and implement current security protocols (info, ops, cyber, network, personnel).
      • Define and implement IT security policies, including access controls, security classifications, data protection protocols, and incident response plans.
      • Establish procedures for information storage, access privileges, document sharing protocols, and security of off-prem devices.
      • Conduct compliance audits and prepare proper documentation for review.
    • Security Awareness and Training
      • Responsible for online and communications op sec. for all websites and public interfaces related to our org, bank, and other accounts.
      • Develop security classification designations for documents, projects, and departments.
      • Train other team members on processes for organized upkeep.
      • Partner with the Training Unit to create training materials needed to ensure all individuals in the organization and network understand the risk landscape, mitigation strategies, and practical security measures needed; assist with security configurations.
    • Online Reputation Management
      • Manage and protect CRI’s online presence and reputation (IP address security, uploading memos, videos, troubleshooting, etc.).
      • In addition to any hacking or phishing attempts; proactively respond and protect against such attacks. This may require configuring existing tech or building in-house analytics tools for related tracking purposes.
      • Assist with technical aspects of online reputation management; others will manage outreach, content, and legal responses.
    • Research and Continuous Improvement
      • Recommend the best providers of VPNs, firewalls, secure wifi configurations, transcription services, alternative communication systems (Signal, iMessage, Slack, Zoom, Gmail, proprietary in-house end-to-end encryption platform, etc.), VoIP, etc.
      • Establish the right security and functionality configurations for all aforementioned software and hardware to be used.
      • Determine which online security services to use (MalwareBytes, Norton, DeleteMe, etc.) and manage those relationships.
      • Stay current with the latest cyber threats, vulnerabilities, and security trends.
    • Specific Responsibilities related to Headquarters
      • Acquire and set up physical infrastructure and hardware: home security systems, routers, modems, extenders, Starlinks, battery backup systems, hard drives, computer monitors, printers, USBs, etc.
      • Set protocols for connecting to wifi networks and printers, turning cameras and microphones on and off, sharing addresses, etc.
      • Oversee quarterly housekeeping matters: bug sweeps, penetration tests, etc. This entails conducting due diligence on potential vendors/contractors, deciding which contractors to use for such services, communicating and collaborating with them, and ensuring the success of their work.

    Qualifications

    • A degree in computer science, IT, systems engineering, or related qualification.
    • 4 years of work experience with incident detection, incident response, and forensics.
    • Experience with Firewalls (functionality and maintenance), Office 365 Security, VSX, and Endpoint Security.
    • Proficiency in Python, C++, Java, Ruby, Node, Go, and/or Power Shell.
    • Ability to work under pressure in a fast-paced environment.
    • Strong attention to detail with an analytical mind and outstanding problem-solving skills.
    • Great awareness of cybersecurity trends and hacking techniques.

    Benefits

    What We Offer

    • Mission‑Driven Culture Work alongside collaborative, values‑aligned colleagues tackling some of humanity’s most complex challenges.
    • Health & Wellness Support - Access to wellness resources designed to support your physical and mental well‑being.
    • Professional Growth & Development Employees receive mentorship from senior leaders and the opportunity to take on meaningful projects that support continuous learning and career advancement.
    • Competitive Compensation The starting compensation is competitive and will depend on a variety of factors that include experience, education, training, certification, and location. We do not currently cap salary ranges because we value team members growing in their roles over time.
    • Flexible Benefits - Full-time employees are offered flexible benefits to support the personal health, wellness, and finances of our team members.

    Location

    Hybrid
    Work must be performed in or near Asheville, NC
    Associated Location
    Asheville, NC, USA

    Apply to This Job

    All fields are required
    Resume must be uploaded in PDF format
    Choose a file or drag it here
    No file chosen (maximum size: 10 MB)
    I acknowledge that use of the Idealist Applicant Tracking System is subject to Idealist's Privacy Policy and Terms of Service.
    Illustration

    Take the Next Step in Your Career

    Match with social-impact hiring managers, explore the latest job opportunities, and get notified when new opportunities meet your search criteria.